Seguridad
nginx ingress — hardening global
| Parámetro | Valor |
|---|---|
| TLS mínimo | 1.2 |
| TLS máximo | 1.3 |
| HTTP → HTTPS | Redirect 308 permanente |
| HSTS | max-age=31536000; includeSubDomains; preload |
| X-Frame-Options | SAMEORIGIN |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Server tokens | Off |
| OCSP stapling | Habilitado |
| SSL Labs | A+ ✅ |
Manifest: $DEIBUZZ_HOME/k3s/manifests/ingress-nginx/security-headers.yaml
Protección por servicio
| Servicio | Protección |
|---|---|
auth.deibuzz.es |
Credenciales Authentik |
vault.deibuzz.es |
Token OpenBao + unseal manual |
jellyfin.deibuzz.es |
Cuentas Jellyfin |
fotos.deibuzz.es |
Cuentas Immich |
wiki.deibuzz.es |
Cuentas Wiki.js |
torrent.deibuzz.es |
Cuentas qBittorrent |
files.deibuzz.es |
Usuario/contraseña Filebrowser |
mail.deibuzz.es |
Cuentas Stalwart |
HSTS Preload
Enviado a la preload list de Chrome/Firefox el 2026-08-11. Estado: pendiente aprobación.
Una vez aprobado, los navegadores forzarán HTTPS para *.deibuzz.es incluso antes de la primera visita.