diff --git a/helm/values.yaml b/helm/values.yaml index 5e3995f1..d63a09e8 100644 --- a/helm/values.yaml +++ b/helm/values.yaml @@ -8,7 +8,7 @@ image: service: type: ClusterIP - port: 3000 + port: 80 autoscaling: enabled: true @@ -26,8 +26,10 @@ ingress: annotations: kubernetes.io/tls-acme: "true" nginx.ingress.kubernetes.io/custom-headers: spark-frontend/ingress-nginx-custom-headers + headers: | + Content-Security-Policy: default-src 'self'; child-src 'self'; connect-src 'self' https://api-iam.intercom.io https://api.bako.global https://api.bako.global/socket.io https://api-js.mixpanel.com https://api.web3modal.org https://app.sentio.xyz https://hermes.pyth.network https://indexer.hyperindex.xyz https://mainnet.fuel.network https://nexus-websocket-a.intercom.io https://region1.google-analytics.com https://relay.walletconnect.org https://spark-candles.v12.trade https://testnet.fuel.network https://unleash.v12.trade https://www.google-analytics.com wss://api.bako.global/socket.io wss://indexer.hyperindex.xyz wss://nexus-websocket-a.intercom.io wss://relay.walletconnect.com wss://relay.walletconnect.org; font-src 'self' https://fonts.gstatic.com data:; frame-src 'self' https://e.widgetbot.io https://intercom.io https://s.tradingview.com https://verify.walletconnect.com https://widget.intercom.io https://widgetbot.io blob:; img-src 'self' data:; manifest-src 'self'; media-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://js.intercomcdn.com https://s3.tradingview.com https://widget.intercom.io https://www.googletagmanager.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; upgrade-insecure-requests; worker-src 'self'; block-all-mixed-content; resources: requests: - cpu: 100m + cpu: 1 memory: 512Mi