crowdsec
Installation
SKILL.md
CrowdSec
CrowdSec detects hostile behavior from logs and HTTP requests, then exposes alerts and decisions through LAPI. The engine alone does not block traffic: install and verify at least one remediation component (bouncer) before claiming protection.
Safety Gate
Before any mutation, confirm the target host/container, scope, backup or rollback,
and maintenance window. Prefer read-only inspection and simulation first. Never
manually delete decisions, collections, or data without recording the reason and
an undo path. Save bouncer keys when created; they are shown once. Use
simulation: true while tuning scenarios so detections are observed without
enforcement, then verify allowlists before live blocking.