Back to articles
Technology Insight

Securing Your Infrastructure: Integrating Traefik v3 with CrowdSec for Automated Brute-Force Mitigation

June 5, 2026

Introduction: The Growing Necessity of Edge Security

In the contemporary digital landscape, securing a Virtual Private Server (VPS) has evolved from a best practice into a critical business necessity. As organizations migrate more services to containerized environments, the exposure to automated threats—specifically brute-force attacks—has increased exponentially. While traditional firewalls provide a basic layer of defense, modern infrastructure requires a more dynamic, intelligent approach. This is where the synergy between Traefik v3 and CrowdSec becomes a game-changer for DevOps professionals and system administrators.

Traefik, as a leading modern cloud-native reverse proxy and load balancer, provides the entry point for your traffic. However, proxying traffic is only half the battle; the other half is vetting that traffic. CrowdSec serves as a high-performance, community-powered security engine that analyzes logs to detect malicious behavior. By integrating these two tools, you create a self-defending perimeter that not only identifies attackers but also shares that intelligence across a global network, proactively blocking known bad actors before they even reach your application logic.

Understanding the Architecture: Traefik v3 and CrowdSec

Before diving into the configuration, it is essential to understand how these two components interact. Traefik v3 introduces enhanced performance and expanded support for the Gateway API, making it even more robust for handling high volumes of requests. CrowdSec operates on a behavior-based detection logic. It parses logs from various sources (in this case, Traefik’s access logs) and applies "scenarios" to identify patterns typical of brute-force attempts, such as high-frequency 401 or 404 errors from a single IP address.

The Role of the Bouncer

The communication bridge between Traefik and CrowdSec is the Bouncer. In a typical setup, the CrowdSec Traefik Bouncer acts as a middleware. When a request hits Traefik, the middleware queries the CrowdSec Local API (LAPI) to check if the source IP is blacklisted. If the IP is flagged, the request is denied immediately with a 403 Forbidden status, effectively neutralizing the attack at the edge.

Step 1: Prerequisites and Environment Setup

To follow this guide, you should have a VPS running a Linux distribution (Ubuntu 22.04 or 24.04 recommended) with Docker and Docker Compose installed. Ensure you have a domain name pointed to your VPS IP address, as Traefik thrives on host-based routing.

  • A VPS with at least 2GB of RAM.
  • Docker Engine v20.10+ and Docker Compose v2.0+.
  • Basic knowledge of YAML syntax and container networking.

Step 2: Configuring CrowdSec Security Engine

The first component to deploy is the CrowdSec container. This engine will be responsible for parsing logs and managing the local database of banned IPs. Below is a foundational Docker Compose snippet for CrowdSec:

Note: Ensure you mount the Traefik log directory as a read-only volume so CrowdSec can monitor incoming requests in real-time.

Generating the API Key

Once CrowdSec is running, you must generate an API key for the Traefik Bouncer to authenticate with the CrowdSec LAPI. This is done via the cscli command-line tool within the container:

  1. Access the container: docker exec -it crowdsec sh
  2. Run: cscli bouncers add traefik-bouncer
  3. Save the generated token; you will need it for the Traefik configuration.

Step 3: Implementing Traefik v3 with the CrowdSec Middleware

Traefik v3 simplifies the use of plugins and middlewares. To integrate CrowdSec, we utilize the CrowdSec Mesh Bouncer or the specialized Traefik middleware plugin available on the Traefik Pilot/Plugins marketplace.

Static Configuration (traefik.yml)

You must enable the plugin in your Traefik static configuration. This tells Traefik where to download the middleware code from:

experimental.plugins.crowdsec.moduleName: "[github.com/maxlerebourg/traefik-bouncer](https://github.com/maxlerebourg/traefik-bouncer)"

Dynamic Configuration and Middleware Definition

In your dynamic configuration file (or via Docker labels), define the middleware. This is where you specify the address of your CrowdSec LAPI and the API key generated in the previous step.

  • Enabled: Set to true to activate the filter.
  • CrowdsecLapiScheme: Typically http or https.
  • CrowdsecLapiHost: The network address of your CrowdSec container (e.g., crowdsec:8080).
  • CrowdsecLapiKey: Your secret token.

Step 4: Automating Brute-Force Detection

CrowdSec uses "collections" to group parsers and scenarios. For a VPS running Traefik, you should install the crowdsecurity/traefik and crowdsecurity/http-cve collections. These include pre-configured logic to detect:

  • HTTP Brute-Force: Too many requests to login endpoints.
  • Path Traversal: Attempts to access restricted system files.
  • Scan/Discovery: Botnets searching for hidden directories (.env, .git).

When a threshold is met, CrowdSec issues a Decision. This decision is then synced to the Traefik middleware, which begins dropping packets from the offending IP. This happens automatically, requiring zero manual intervention from the administrator once the initial setup is complete.

Step 5: Monitoring and Maintenance

A set-and-forget security system is a myth; monitoring is vital. CrowdSec provides a powerful dashboard (CrowdSec Console) that visualizes attacks. On the local machine, you can use cscli decisions list to see currently active bans and cscli alerts list to see the history of detected threats.

Testing the Configuration

To verify the setup, you can simulate a brute-force attack from a separate IP address (e.g., using a tool like Nikto or a simple curl loop). After a few dozen rapid requests, check the CrowdSec logs. You should see a new decision generated, and subsequent requests from the testing IP should return a 403 error from Traefik.

Conclusion: Scaling Your Security Posture

By integrating Traefik v3 and CrowdSec, you have successfully transformed a standard reverse proxy into a sophisticated security gateway. This architecture is not only effective against brute-force attacks but is also highly scalable. Whether you are running a single WordPress site or a complex microservices architecture, this combination provides a resilient defense mechanism that grows with your needs.

The beauty of this solution lies in its community-driven nature. By using CrowdSec, your VPS benefits from the collective intelligence of thousands of other users. When an IP is blocked on one user's server for malicious behavior, that information is shared, protecting your infrastructure before the attacker even targets you. In the world of cybersecurity, proactive defense is the only way to stay ahead.