You can also specify a CSP using a document's meta tags:
<meta http-equiv="Content-Security-Policy" content="default-src *; script-src https://assets.example.com; style-src https://assets.example.com"></meta>
I'm not sure if that introduces any additional attack vectors (other than somebody modifying the document in an unencrypted connection) but it's useful for when hosting statically.EDIT: updated to mimic example in post