- Add Traefik plugin via HelmChartConfig (crowdsec-bouncer-traefik-plugin) - Create bouncer Middleware in stream mode - Apply bouncer to all public ingresses - IPs flagged by CrowdSec will now be blocked at Traefik level
- Remove uptime-kuma (heavier, requires manual config) - Add Gatus (lightweight, config-as-code) - Monitor all services: Gitea, Podinfo, Vaultwarden, Authelia, Flux, K8s API - Protected by Authelia ForwardAuth - status.davidepiu.xyz