Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Audit HTTP Security Headers Across URLs

Regularly check your endpoints for missing security headers and alert Slack.

Categories
CloudInfrastructure

Security headers are silent infrastructure - they either help or they are absent, and nobody notices. This blueprint probes each URL weekly, reports exactly which headers are missing per URL, and alerts Slack. Enable the schedule after a first manual run.

How it works

  1. probe_headers (io.kestra.plugin.scripts.shell.Commands on Alpine) curls each URL, lowercases the response headers, and diffs against the required set via the ::{"outputs": ...}:: protocol.
  2. gaps_found (io.kestra.plugin.core.flow.If) branches to alert_gaps or log_clean.
  3. The errors block alerts on probe failure.
  4. Trigger: a disabled weekly Schedule.

What you get

  • Per-URL header gap list in every alert.
  • Execution-history audit trail of the probe.
  • A failure alert so a dead check is visible.

Who it's for

  • Platform teams who ship headers via CDN/infra and want proof.
  • Security champions chasing silent regressions.

Why orchestrate this with Kestra

curl prints headers; the flow turns them into a decision on a schedule, with history and alerts. The next step (ticket, PR to the CDN config, header scorecard) is one task away.

Prerequisites

  • Docker available on the Kestra Worker.
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for gap and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set urls.
  3. Run once and read header_gaps.
  4. Enable the weekly schedule.

How to extend

  • Fail the execution when gaps exist for pipeline gating.
  • Add headers like permissions-policy or a strict CSP.
  • Store results in KV and trend over time.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.