Hi, just my grain of salt on the security part, I work at CrowdSec. The rest is just me having built the same kind of duct-tape stack at home. Would I do it? Yes, and "to learn how it works inside" is reason enough. Under the hood Coolify is the same pieces you listed (Docker, a reverse proxy, a git hook, a backup job) plus somebody else's glue, and the glue is what you pay for in evenings when it breaks. You've run SWAG for 4 or 5 years, so you already know what babysitting a stack feels like. The one thing I'd add to the other comment: give it a deadline. If after a few months you're still fighting the CI trigger, go back to Coolify with no shame, you'll have learned what you wanted anyway. Now the part I actually know something about. Fail2ban "working in concert with crowdsec" sounds nice and mostly doubles your work. CrowdSec was built as its successor, both read the same nginx logs and both will ban the same bad guys, so you end up with two ban lists and a fun afternoon the day you can't tell which one blocked your client. Does fail2ban catch anything on top? Not really. Pick one (you can guess which one I'd pick ) and switch the other off. What's missing, from the security corner: whitelist yourself. Your home IP, plus whatever box runs Ansible and your CI. Everybody bans their own CI at least once. And since you mentioned CVEs: the log-based scenarios only see an exploit attempt after nginx has already answered it. If you want the request dropped before it reaches Symfony, wire the AppSec component (our WAF: ModSecurity/CRS compatible rules, with virtual patches for known CVEs) into the nginx bouncer that SWAG's mod ships. Bot detection on top of that is fresh (1.8, still alpha), so treat it as a toy for now, and exempt your API clients or they'll fail the challenge. Last thing: if you ever go back to Coolify, we have bouncers for Traefik and Caddy too, so CrowdSec is one piece that won't lock you into either setup. If you get stuck wiring the WAF bit into SWAG, hop onto our Discord, there's always someone around.