Traefik

Serving a static site securely with static-web-server

Hardening a Hugo site behind Traefik with static-web-server: read-only rootfs, dropped capabilities, a non-root UID, and security headers

A Hugo build is a folder of files. Nothing executes, nothing talks to a database, nothing parses user input. The interesting attack surface isn’t the content — it’s the server you put in front of it, and for years that meant an nginx image carrying a config language, a module system, and a package manager I never used.

This blog now runs on static-web-server instead. Here’s the compose file that serves it, and what each hardening line actually buys.

Docker docker security traefik