Skip to content

harden nginx security and document Cloudflare setup in Phase A#32

Merged
Buffden merged 1 commit into
mainfrom
ci-cd/setup-pipeline-for-deployment
Mar 27, 2026
Merged

harden nginx security and document Cloudflare setup in Phase A#32
Buffden merged 1 commit into
mainfrom
ci-cd/setup-pipeline-for-deployment

Conversation

@Buffden

@Buffden Buffden commented Mar 27, 2026

Copy link
Copy Markdown
Owner

nginx: add malicious bot/scanner user-agent blocking, real IP resolution via CF-Connecting-IP to fix broken per-client rate limiting behind ALB, strip conflicting Spring Security 6 headers with proxy_hide_header, add short URL enumeration protection on redirect endpoint, and connection limits with slow-read timeouts.

docs: integrate Cloudflare free plan setup as Step 12 in Phase A — covers DNS record migration, nameserver switch at Namecheap, SSL mode, rate limit rule, and rollback procedure.

nginx: add malicious bot/scanner user-agent blocking, real IP resolution
via CF-Connecting-IP to fix broken per-client rate limiting behind ALB,
strip conflicting Spring Security 6 headers with proxy_hide_header, add
short URL enumeration protection on redirect endpoint, and connection
limits with slow-read timeouts.

docs: integrate Cloudflare free plan setup as Step 12 in Phase A —
covers DNS record migration, nameserver switch at Namecheap, SSL mode,
rate limit rule, and rollback procedure.
@Buffden Buffden merged commit 1c485de into main Mar 27, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant