Hi and thanks for your extensive reply ! > You've run SWAG for 4 or 5 years, so you already know what babysitting a stack feels like The thing is : it now runs pretty smoothly and I don't babysit that much, if not at all. Except when I forgot I've rebuilt the container and didn't update UFW rules but that's on me. What "scares" me is precisely that : is it running smoothly because I did my job, or because I haven't seen *the* black swan already. > The one thing I'd add to the other comment: give it a deadline. If after a few months you're still fighting the CI trigger, go back to Coolify with no shame, you'll have learned what you wanted anyway. Great advice, if I go through with the experiment I'll keep it in mind. > CrowdSec was built as its successor, both read the same nginx logs and both will ban the same bad guys I've read in tutorials that they are complimentary solutions. Fail2ban focusing on forms (whatever...form...they take) and Crowdsec being more generalist. For example, the Crowdsec instance I setup regularly ban my phone when I'm on 5G, because for some reasons it does http probbing (maybe to stay connected to services, idk). I've never been banned by Fail2ban for this reason. On the other hand if I'm mixing up my accounts and passwords, Fail2ban stands up, not Crowdsec. That's why I'm currently keeping both : to act as "sequential" nets. Maybe they do the same thing but there is some kind of priority, that's why notice actions from one service and not the other. > What's missing, from the security corner: whitelist yourself. Your home IP, plus whatever box runs Ansible and your CI. Yup I already whitelisted my home IP on my home server Crowdsec. > If you want the request dropped before it reaches Symfony, wire the AppSec component (our WAF: ModSecurity/CRS compatible rules, with virtual patches for known CVEs) into the nginx bouncer that SWAG's mod ships. Bot detection on top of that is fresh (1.8, still alpha), so treat it as a toy for now, and exempt your API clients or they'll fail the challenge. Yeah it's something I setup on my home server as soon as I saw the news and the changelog. I don't think I managed to set it up properly, I still need to work on it. As a side note : with Crowdsec having its one bot detection, do you consider services like [Anubis](https://anubis.techaro.lol/) still relevant ?