Vaultwarden
3.1k ↗Lightweight Bitwarden-compatible password server in a single container
Collaborative intrusion prevention that parses logs and blocks bad actors
CrowdSec reads your logs (SSH, web servers, proxies), detects hostile behavior, and blocks it via "bouncers" at the firewall, reverse proxy or CDN level. Its twist on the fail2ban formula is the community blocklist: participating instances share anonymized attack signals and benefit from each other's detections.
The community sharing is optional but is also the main advantage — evaluate whether that exchange fits your privacy posture. The agent is light; bouncer setup varies by where you want enforcement.
A modern fail2ban successor for any server with ports open to the internet.
Lightweight Bitwarden-compatible password server in a single container
Authentication and authorization gateway for your reverse proxy