Not sure this policy makes a ton of sense if you plan to embed sites on explore.ghost.org: https://github.com/TryGhost/ghost-docker/blob/29267589fecdabb5d7c4350859cd8c2255229c04/caddy/snippets/SecurityHeaders#L11