diff --git a/helm/values.yaml b/helm/values.yaml index 81419ed0..7f936681 100644 --- a/helm/values.yaml +++ b/helm/values.yaml @@ -26,22 +26,54 @@ ingress: annotations: kubernetes.io/tls-acme: "true" nginx.ingress.kubernetes.io/configuration-snippet: | - more_set_headers "Content-Security-Policy: - default-src 'self'; - script-src 'self' 'unsafe-inline' 'unsafe-eval' https://js.intercomcdn.com https://www.googletagmanager.com https://cdn.jsdelivr.net https://widget.intercom.io https://s3.tradingview.com; - style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; - style-src-elem 'self' 'unsafe-inline' https://fonts.googleapis.com; - connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://nexus-websocket-a.intercom.io https://api-iam.intercom.io https://api.bako.global/socket.io wss://api.bako.global/socket.io https://testnet.fuel.network https://mainnet.fuel.network https://relay.walletconnect.org wss://relay.walletconnect.org https://hermes.pyth.network https://indexer.hyperindex.xyz wss://indexer.hyperindex.xyz https://app.sentio.xyz https://api.web3modal.org wss://relay.walletconnect.com https://api.bako.global https://unleash.v12.trade wss://nexus-websocket-a.intercom.io https://spark-candles.v12.trade wss://api.bako.global/socket.io https://api-js.mixpanel.com; - img-src 'self' data:; - font-src 'self' https://fonts.gstatic.com data:; - frame-src 'self' https://widgetbot.io https://intercom.io https://widget.intercom.io https://verify.walletconnect.com https://e.widgetbot.io https://s.tradingview.com blob:; - media-src 'self'; - manifest-src 'self'; - worker-src 'self'; - child-src 'self'; - block-all-mixed-content; - upgrade-insecure-requests;"; - + more_set_headers "Content-Security-Policy: + default-src 'self'; + child-src 'self'; + connect-src 'self' + https://api-iam.intercom.io + https://api.bako.global + https://api.bako.global/socket.io + https://api-js.mixpanel.com + https://api.web3modal.org + https://app.sentio.xyz + https://hermes.pyth.network + https://indexer.hyperindex.xyz + https://mainnet.fuel.network + https://nexus-websocket-a.intercom.io + https://region1.google-analytics.com + https://relay.walletconnect.org + https://spark-candles.v12.trade + https://testnet.fuel.network + https://unleash.v12.trade + https://www.google-analytics.com + wss://api.bako.global/socket.io + wss://indexer.hyperindex.xyz + wss://nexus-websocket-a.intercom.io + wss://relay.walletconnect.com + wss://relay.walletconnect.org; + font-src 'self' https://fonts.gstatic.com data:; + frame-src 'self' + https://e.widgetbot.io + https://intercom.io + https://s.tradingview.com + https://verify.walletconnect.com + https://widget.intercom.io + https://widgetbot.io + blob:; + img-src 'self' data:; + manifest-src 'self'; + media-src 'self'; + script-src 'self' 'unsafe-inline' 'unsafe-eval' + https://cdn.jsdelivr.net + https://js.intercomcdn.com + https://s3.tradingview.com + https://widget.intercom.io + https://www.googletagmanager.com; + style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; + upgrade-insecure-requests; + worker-src 'self'; + block-all-mixed-content;"; + resources: requests: cpu: 1