I realized the other day that due to complex logic in the location blocks, various WordPress static files like images and stylesheets didn't get the HTTP Strict Transport Security header set. We need to include it on each level where we are setting headers, because nginx overwrites headers if you set them again in a child block.