* 🛡️ feat: Configurable Baseline HTTP Security Headers Adds helmet's CSP-independent headers (HSTS, X-Frame-Options, X-Content-Type-Options, COOP, CORP, Referrer-Policy) on every response, with contentSecurityPolicy explicitly disabled. Every header that can break a deployment is configurable, so there is no allow-list to go stale the way #7377's hardcoded CSP directives did. HSTS includeSubDomains defaults off rather than matching helmet's on-by-default: it would otherwise pin every sibling subdomain to HTTPS for a year in every visitor's browser, and undoing that requires serving max-age=0 from each affected host. * 🛡️ feat: Nonce-Based Content Security Policy for the SPA Shell Adds an opt-in, per-response nonce CSP on the HTML response, resolved once at startup so each request only mints a nonce and concatenates the header. Report-only by default, since that is the rollout step #7377 skipped. Rebase and correctness pass over #13226: - Styles carry no nonce. A nonce in style-src makes browsers ignore 'unsafe-inline', which would have blocked the <style> element the theme script injects at runtime, plus every style third-party components inject. - frame-ancestors 'self' is now a default rather than opt-in, so enabling CSP actually covers the clickjacking half of #7110. - CSP_SCRIPT_SRC_EXTRA now drops 'strict-dynamic', which would otherwise make browsers ignore the very hosts the operator configured. - Nonce stamping runs after the query-devtools bootstrap injection so that injected script is covered too. * fix: replace frame-ancestors instead of merging it Merging the configured value into the default turned a deliberate CSP_FRAME_ANCESTORS='none' into `frame-ancestors 'self' 'none'`, which browsers resolve back to 'self'. Also bail out if the serialized policy somehow lacks the nonce slot rather than emitting a header the shell cannot match. * fix: address Codex review findings on the CSP defaults All five were real against LibreChat's actual runtime: - CSP_REPORT_ONLY now only enforces on an explicit false/off/0/no. A typo or `1` previously fell through isEnabled() to enforcing, turning a config slip into a blocked SPA. Shares the parse helper with headers.ts via a new security/env.ts. - Module preloads are stamped. A production client/dist/index.html carries 32 parser-inserted `<link rel="modulepreload">` tags, which 'strict-dynamic' does not cover and 'self' cannot rescue. - Stale nonce attributes are replaced rather than preserved; only the current response's nonce is authorized. - worker-src allows data:, which Monaco's default CDN loader needs to bootstrap its workers (there is no loader.config() in the client). - script-src allows 'wasm-unsafe-eval' for the HEIC upload path, which compiles WebAssembly through heic-to. Narrower than 'unsafe-eval'. Verified against the real built shell: 4 scripts and all 32 preloads nonced, stylesheets/icons/manifest and <style> untouched. * fix: address second Codex round on CSP rollout controls - SECURITY_HEADERS=false now disables CSP too. It is documented as the global kill switch, and an operator reaching for it to recover a shell broken by an enforcing policy must not be left with that policy on. - The SPA shell is forced to `no-store` while CSP is enabled, ignoring INDEX_CACHE_CONTROL/INDEX_PRAGMA/INDEX_EXPIRES and warning when they are set. A cacheable shell pins one nonce across page loads and users, which is the whole thing a nonce policy defends against. - Added CSP_ALLOW_WASM and CSP_ALLOW_DATA_WORKERS. The previous commit's .env.example claimed CSP_ADDITIONAL_DIRECTIVES could drop 'wasm-unsafe-eval' and data:, but merging only ever appends sources, so the documented hardening step was impossible. These toggles make it real. |
||
|---|---|---|
| .. | ||
| examples | ||
| templates | ||
| tests | ||
| .helmignore | ||
| Chart.yaml | ||
| DNS_CONFIGURATION.md | ||
| readme.md | ||
| values.yaml | ||
LibreChat Helm Chart
This Librechat Helm Chart provides an easy, light weight template to deploy LibreChat on Kubernetes
Variables
In this Chart, LibreChat will only work with environment Variables. You can Specify Vars and Secret using an existing Secret (This can be generated by creating an Env File and converting it to a Kubernetes Secret --from-env-file)
Setup
- Generate Variables
Generate unique values for
CREDS_KEY,JWT_SECRET,JWT_REFRESH_SECRET, andMEILI_MASTER_KEYusingopenssl rand -hex 32, andCREDS_IVusingopenssl rand -hex 16. Store them in the existing Kubernetes Secret so every replica uses the same values. place them in a secret like this (If you want to change the secret name, remember to change it in your helm values):
apiVersion: v1
kind: Secret
metadata:
name: librechat-credentials-env
namespace: <librechat-chart-namespace>
type: Opaque
stringData:
CREDS_KEY: <generated value>
CREDS_IV: <generated value>
JWT_SECRET: <generated value>
JWT_REFRESH_SECRET: <generated value>
MEILI_MASTER_KEY: <generated value>
- Add Credentials to the Secret Dependant of the Model you want to use, create Credentials in your provider and add them to the Secret:
apiVersion: v1
kind: Secret
. . . .
OPENAI_API_KEY: <your secret value>
-
Apply the Secret to the Cluster
-
Fill out values.yaml and apply the Chart to the Cluster
Admin Panel SSO
Set librechat.adminPanelUrl to the admin panel base URL used for OAuth/SSO
redirect, whether the admin panel is deployed on a separate origin
or on the same origin under an admin subpath.
It may include a path, but it should not
end with a trailing / because LibreChat appends /auth/... callback paths.
librechat:
adminPanelUrl: https://admin.example.com/admin
This renders ADMIN_PANEL_URL for LibreChat's admin OAuth flow. For OpenID SSO,
also register this LibreChat callback URL with your identity provider:
https://<librechat-domain>/api/admin/oauth/openid/callback
Generation protocol rollout
Redis-backed generation streams use protocol v1 by default during the first rollout of a v2-capable image. This keeps a rolling deployment compatible with replicas that still run the previous Redis queue, checkpoint, and recovery scripts.
After every LibreChat replica is on the v2-capable image and all active
generations owned by the old image have drained, set
librechat.configEnv.GENERATION_PROTOCOL_VERSION="2" in a second rollout.
Keep the new image in place until v2 generations have drained; an older image
cannot safely operate on their Redis state. In-memory generation streams do not
share state across replicas and negotiate v2 without this cutover.
Langfuse Fanout
The chart can optionally deploy a Langfuse fanout gateway with an internal OpenTelemetry Collector sidecar. The gateway handles Langfuse media fanout and proxies traces to the collector; the collector forwards tenant-scoped Langfuse traces to both a central Langfuse project and the tenant Langfuse project. It is disabled by default.
When enabled, the chart also sets LANGFUSE_FANOUT_ENABLED and
LANGFUSE_FANOUT_COLLECTOR_URL for the LibreChat app unless those values are
already provided in librechat.configEnv.
Set librechat.configEnv.LANGFUSE_FANOUT_TENANT_EXPORT_DISABLED=true to keep
central trace export flowing through the fanout gateway while disabling tenant trace
and score export. When omitted, false, or blank, tenant export remains available
if tenant keys and a known destination are configured.
Langfuse tenant base URLs are selected from the startup-configured destination map rendered into LibreChat and the fanout gateway. Tenant API keys can still be added through tenant app configuration at runtime without restarting either component. The internal collector provides trace memory limiting, batching, tenant routing, and removal of LibreChat-only routing attributes before export.
The fanout gateway stores one-time media upload plans in Redis so media create
and byte-upload requests can land on different gateway replicas. Set
langfuseFanout.redis.uri for an external Redis service, or enable the bundled
Redis chart with redis.enabled=true and let the chart derive the internal URI.
Scale the gateway manually with langfuseFanout.replicaCount; the chart does
not create a fanout HPA.
The internal collector receiver is bound to 127.0.0.1:4319 by default because
only the gateway sidecar should send traces to it.
The gateway exposes Prometheus metrics at /metrics. Configure
langfuseFanout.metrics.secret.name and .key to pass a bearer token secret to
the gateway; if omitted, /metrics returns 401. Use
langfuseFanout.service.annotations for scrape annotations when your cluster
uses annotation-based discovery. The gateway container also has configurable
/healthz liveness and readiness probes under langfuseFanout.
See otel/langfuse-fanout/README.md
for the central Langfuse secret and values example.
Content Security Policy
LibreChat's application-level CSP is disabled by default. Enable it through
librechat.configEnv so Kubernetes rollouts can start in report-only mode
before enforcing:
librechat:
configEnv:
CSP_ENABLED: "true"
CSP_REPORT_ONLY: "true"
CSP_REPORT_URI: "https://reports.example.com/csp"
After reviewing the reports, set CSP_REPORT_ONLY: "false" to enforce. Use the
CSP_*_EXTRA variables from .env.example for deployment-specific CDNs,
analytics endpoints, or embedded frames.
The chart does not set CSP at the ingress layer: the policy carries a nonce that
has to be freshly generated for each HTML response and matched against the
<script> tags in that same response, which only the app can do.