Comment on Self Hosting- Security recommendations
fonix232@fedia.io 1 week ago
The recommendations so far are quite solid.
I'd also add that crowdsec with the right collections as a primary filter within your reverse proxy setup can be extremely useful, potentially even better than fail2ban, as CS delivers a literal "scan every packet and put them against these rules" approach - where the rules are crowd sourced, thus are more up to date than any manual blocklists, filter list etc. can be, and can spot even 0day intrusion approaches.