ServerName pdnsadmin.example.com ServerAdmin hostmaster@example.com Redirect / https://pdnsadmin.example.com/ ErrorLog ${APACHE_LOG_DIR}/pdnsadmin.example.com-error.log LogLevel warn CustomLog ${APACHE_LOG_DIR}/pdnsadmin.example.com-access.log combined ServerName pdnsadmin.example.com ServerAdmin hostmaster@example.com DocumentRoot /opt/python/powerdns-admin/app/powerdnsadmin/ AllowOverride None Require all granted ProxyPass "/static/" "!" ProxyPass "/favicon.ico" "!" ProxyPass "/.well-known/" "!" ProxyPass "/" "unix:/run/uwsgi_powerdns-admin/service.sock|uwsgi://powerdns-admin/" ErrorLog ${APACHE_LOG_DIR}/pdnsadmin.example.com-error.log LogLevel warn CustomLog ${APACHE_LOG_DIR}/pdnsadmin.example.com-access.log combined SSLEngine on SSLCertificateFile /etc/dehydrated/certs/example.com/fullchain.pem SSLCertificateKeyFile /etc/dehydrated/certs/example.com/privkey.pem # enable HSTS Header always set Strict-Transport-Security "max-age=15768000" # allow frames, needed for settings page Header always set X-Frame-Options SAMEORIGIN # Content Security Policy (https://content-security-policy.com/) Header set Content-Security-Policy: "default-src 'self' *.example.com 'unsafe-inline' 'unsafe-eval'"