Skip to content

Security (CrowdSec + mTLS)

TL;DR / when to use this: Two layers I run on the edge: CrowdSec banning IPs at the Cloudflare worker layer (so junk never reaches the home proxy), and Cloudflare mTLS for zero-trust-style access to sensitive apps without a full zero-trust setup. The reverse-proxy-side CrowdSec bouncer lives in SWAG; this doc is the edge layer.

CrowdSec Cloudflare Worker bouncer

A local CrowdSec bouncer only 403s traffic that already arrived through the tunnel. A Cloudflare Worker bouncer bans at the proxy layer — the traffic never hits your home server at all. Works on the free tier.

  crowdsec-cloudflare-bouncer:
    image: crowdsecurity/cloudflare-worker-bouncer
    restart: unless-stopped
    volumes:
      - ./crowdsec-cloudflare-worker-bouncer.yaml:/etc/crowdsec/bouncers/crowdsec-cloudflare-worker-bouncer.yaml
    ports:
      - 2113:2113
    logging:
      options:
        max-size: "10m"
        max-file: "3"

Fill in the bouncer config:

  • API_KEY — docker exec -it crowdsec cscli bouncers add cloudflare
  • CROWDSEC_LAPI_URL — the CrowdSec agent URL
  • only_include_decisions_from: ["cscli", "crowdsec"] — required for the Cloudflare free tier
  • <ACCOUNT_ID> / <ZONE_ID> — bottom-right of the zone page
  • routes_to_protect: ["*.example.com/*"] — you must list routes explicitly (wildcards allowed)
  • CLOUDFLARE_ACCOUNT_TOKEN — scoped token per the docs
  • Set the worker route fail mode to Fail Open

Verify: Workers Routes → the worker; bans live in Storage & Databases → KV → KV Pairs.

Cloudflare mTLS

Great alternative to full zero-trust for apps like Paperless, Immich, and Vaultwarden:

  1. Confirm the tunnel works from your mobile network.
  2. Domain portal → SSL/TLS → Client Certificates → Create Certificate; save client.crt and client.key. Under Hosts, add the subdomain you want mTLS on — otherwise it won't enforce.
  3. Security → Security Rules → Templates → Enforce mTLS authentication; change the trigger from URI Path to Hostname, wildcard, e.g. paperless.domain.com*.
  4. Bundle for mobile clients:

    openssl pkcs12 -export -inkey client.key -in client.crt -out client.pfx
    

    Use a long passphrase (~20 chars). Import the .pfx in the mobile app (e.g. Vaultwarden clients) — browsers won't take a client cert directly, so mTLS is app-first.

See also