Content Security Policy is an important part of building production-ready Module Federation systems. This lesson explains what content security policy means, how it works, and how to apply it with practical examples you can reuse.
Content Security Policy Overview
Content Security Policy is a building block you will reach for often in Module Federation. It keeps related logic together and makes your intent obvious to reviewers and future maintainers.
When you learn content security policy properly, you avoid the guesswork that leads to bugs and rework. The example below shows the shape you will use in most real Module Federation projects.
Start from a minimal Content Security Policy example and grow it only as needed.
Keep configuration explicit so Content Security Policy behaves the same in every environment.
Name things clearly so teammates understand your Content Security Policy at a glance.
Add tests around Content Security Policy early to lock in expected behaviour.
Module Federation Cheatsheet
Key Module Federation settings related to content security policy.
Option
Example
Purpose
name
name: 'shell'
Unique container name
filename
filename: 'remoteEntry.js'
Remote entry manifest
exposes
exposes: { './X': './src/X' }
Modules a remote shares
remotes
remotes: { app: 'app@url' }
Remotes a host consumes
shared
shared: { react: { singleton: true } }
Deduplicate libraries
lazy load
import('remote/Module')
Load remotes on demand
Suspense
<Suspense fallback={...}>
Handle async loading
How Content Security Policy Works in Module Federation
Content Security Policy builds on Module Federation's ability to load code from another independently built and deployed application at runtime. Each app can be a host, a remote, or both.
Always provide a fallback so a failing remote degrades gracefully instead of crashing the shell.
Remotes expose modules through a remoteEntry.js manifest.
Hosts declare remotes and import exposed modules dynamically.
Shared dependencies are deduplicated, ideally as singletons.
Each micro frontend builds and deploys on its own schedule.
Practical Guidance for Content Security Policy
In production, content security policy needs careful version management and graceful failure handling. Align shared dependency versions and always render a fallback when a remote cannot load.
Concern
Recommendation
Shared versions
Use singletons with requiredVersion
Runtime errors
Wrap remotes in error boundaries and fallbacks
Deployment
Resolve remotes from a runtime manifest
Performance
Lazy-load remotes and cache remoteEntry.js
Common Mistakes
Copying content security policy snippets without understanding what each line does.
Skipping error handling and edge cases when wiring up content security policy.
Leaving content security policy untested, so regressions slip into production.
Over-engineering content security policy before you actually need the extra flexibility.
Key Takeaways
Content Security Policy is a core part of working effectively with Module Federation.
Start small and keep content security policy focused on a single responsibility.
Apply consistent patterns so content security policy scales across your project.
Test and document content security policy to keep it maintainable over time.
Pro Tip
Pair content security policy with automated tests from day one. It is far cheaper to catch Module Federation regressions in CI than in production.
You now understand content security policy in Module Federation and how to apply it in real projects. Next, continue with Authentication Sharing to keep building your skills.