LLM-first uptime monitoring

metadata audit fixups: security headers, twitter:card=summary, JSON-LD author master

Cross-property audit on 2026-05-13 flagged three gaps relative to divepool's setup: - ansible/templates/Caddyfile.j2: add security headers matching divepool's posture (HSTS preload, X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy, Permissions- Policy, -Server). Defense-in-depth even though pingarthur has no user-facing UI - homepage.go: twitter:card summary_large_image -> summary. summary_large_image expects 2:1 landscape, our og:image is 1000x1000 square so summary renders correctly. (Bluesky tolerates the mismatch; Twitter would crop.) - homepage.go: JSON-LD creator -> author. Both valid for SoftwareApplication per schema.org, but author is the preferred property and aligns with divepool's WebApplication convention OpenAPI sitemap loc deliberately kept at the bare /api/v1/openapi path so social-preview bots get the OG-tagged HTML stub; the .json suffix variant always returns raw JSON and defeats the preview. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>


+15 -2
2 changed files