Security (CrowdSec + mTLS)¶
TL;DR / when to use this: Two layers I run on the edge: CrowdSec banning IPs at the Cloudflare worker layer (so junk never reaches the home proxy), and Cloudflare mTLS for zero-trust-style access to sensitive apps without a full zero-trust setup. The reverse-proxy-side CrowdSec bouncer lives in SWAG; this doc is the edge layer.
CrowdSec Cloudflare Worker bouncer¶
A local CrowdSec bouncer only 403s traffic that already arrived through the tunnel. A Cloudflare Worker bouncer bans at the proxy layer — the traffic never hits your home server at all. Works on the free tier.
crowdsec-cloudflare-bouncer:
image: crowdsecurity/cloudflare-worker-bouncer
restart: unless-stopped
volumes:
- ./crowdsec-cloudflare-worker-bouncer.yaml:/etc/crowdsec/bouncers/crowdsec-cloudflare-worker-bouncer.yaml
ports:
- 2113:2113
logging:
options:
max-size: "10m"
max-file: "3"
Fill in the bouncer config:
API_KEY—docker exec -it crowdsec cscli bouncers add cloudflareCROWDSEC_LAPI_URL— the CrowdSec agent URLonly_include_decisions_from: ["cscli", "crowdsec"]— required for the Cloudflare free tier<ACCOUNT_ID>/<ZONE_ID>— bottom-right of the zone pageroutes_to_protect: ["*.example.com/*"]— you must list routes explicitly (wildcards allowed)CLOUDFLARE_ACCOUNT_TOKEN— scoped token per the docs- Set the worker route fail mode to Fail Open
Verify: Workers Routes → the worker; bans live in Storage & Databases → KV → KV Pairs.
Cloudflare mTLS¶
Great alternative to full zero-trust for apps like Paperless, Immich, and Vaultwarden:
- Confirm the tunnel works from your mobile network.
- Domain portal →
SSL/TLS → Client Certificates → Create Certificate; saveclient.crtandclient.key. Under Hosts, add the subdomain you want mTLS on — otherwise it won't enforce. Security → Security Rules → Templates → Enforce mTLS authentication; change the trigger from URI Path to Hostname, wildcard, e.g.paperless.domain.com*.-
Bundle for mobile clients:
Use a long passphrase (~20 chars). Import the
.pfxin the mobile app (e.g. Vaultwarden clients) — browsers won't take a client cert directly, so mTLS is app-first.
See also¶
- SWAG — CrowdSec engine + nginx bouncer + GeoIP whitelist
- Pangolin — VPS-layer CrowdSec for public access
- Blog posts: CrowdSec Cloudflare Worker bouncer · mTLS