We would like to enable HSTS (HTTP Strict Transport Security) headers for our Portal GUI. I see headers can be injected using NGINX_PROXY_ADD_HEADER however this does not seem to affect the Portal. How can this be achieved?
Kong Gateway: Enabling HSTS headers for Portal
How do I enable HSTS headers for the Kong Dev Portal GUI?
NGINX_PROXY_ADD_HEADER does not apply to the Portal GUI. Instead, add a custom Nginx template with an add_header Strict-Transport-Security ...; directive inside the Portal’s location / block. Note that the Dev Portal is deprecated on Kong Gateway (Enterprise), and on a standard Enterprise license the Portal GUI listener returns a 404 regardless of this header configuration.
Problem
Solution
To accomplish this a custom nginx template will be needed. Specifically, this (and other headers) will need to be added to the Portal location block as seen below.
The location block has been shortened for readability.
location / {
root portal;
default_type text/html;
...
add_header Strict-Transport-Security 'max-age=320000; includeSubDomains;';
}The results can be seen when accessing your portal, in the example below the GUI is running on port 48003.
Note: The Dev Portal is deprecated on Kong Gateway (Enterprise). On a standard Enterprise license the Portal GUI listener returns
404 {"message":"Not Found"}even withKONG_PORTAL=onexplicitly set, because Portal is now gated behind a separate license entitlement that ordinary Enterprise licenses do not carry. Thelocation /block above is still the correct place to add the header for anyone whose license does unlock the Portal, but on a standard license there is no served Portal GUI to add the header to.