I have similar setup on my home server except my Crowdsec & Anubis live in a dockerised VPS proxy that tunnels over WireGuard to the real server behind OPNSense. Saves me a ton not having bandwidth obliterating AI crawlers hit my internet bill. As an added bonus, I can move or shutdown the public VPS entry if things get too ‘spicy’ without any downtime on connections via the VPN.
I have similar setup on my home server except my Crowdsec & Anubis live in a dockerised VPS proxy that tunnels over WireGuard to the real server behind OPNSense. Saves me a ton not having bandwidth obliterating AI crawlers hit my internet bill. As an added bonus, I can move or shutdown the public VPS entry if things get too ‘spicy’ without any downtime on connections via the VPN.