Skip to content
MDView as Markdown

Fastly

Fastly can add a CSP header to responses at the edge in VCL, which makes it a practical route for any origin you cannot easily change - a legacy application, a managed platform, or a stack where a deployment to add one header is more trouble than it is worth.

What Fastly gives you

  • The add statement, which appends a response header without removing existing headers of the same name.
  • header.set, for setting a header by name when you want replace rather than append semantics.
  • Header manipulation in vcl_deliver, so the policy applies to what leaves the edge regardless of what the origin sent.
  • A published solutions example for adding modern web security headers to all responses.

Sending reports to Report URI

Set the header in vcl_deliver. Your URL comes from the Setup page:

sub vcl_deliver {
  set resp.http.Content-Security-Policy-Report-Only =
    "default-src 'none'; form-action 'none'; frame-ancestors 'none'; report-uri https://abc123.report-uri.com/r/d/csp/reportOnly";
}

That is the same starting policy we recommend for the CSP Wizard, and report-only blocks nothing.

Things to watch for

  • add and set are not interchangeable here. add appends, so if the origin already sends a CSP you end up with two headers and the browser enforces both - the effective policy is the intersection. Use set if you intend to replace.
  • Check what the origin sends before adding anything at the edge. A policy that looks wrong at the browser is often two policies that are each individually fine.
  • VCL cannot generate a per-request nonce for the page body, because it does not rewrite the HTML. Allowlist and hash-based policies work at the edge; nonce-based policies belong in the application - see our Frameworks guides.

Official documentation

Fastly - Enable modern web security headers to all responses

Start Monitoring with Report URI

Already using us for CSP? Find your report-uri value on Setup, or view your CSP reports.

New to Report URI? Create an account and grab your report-uri value from the Setup page. Prefer a guided setup? The CSP Wizard builds a policy from your reports automatically once you're signed in.

Start your free trial