CrowdSec

Operational skill for installing, configuring, operating, and debugging CrowdSec (cscli, LAPI/CAPI, hub, bouncers, WA...

Play video

An operational skill that turns Claude into a hands-on CrowdSec operator. Install, configure, manage, and debug the CrowdSec Security Engine directly from your terminal — across bare-metal/systemd, Docker, and Kubernetes environments. Covers the full operational lifecycle: installation and upgrades, hub collection management, bouncer deployment (iptables, nftables, nginx, traefik, caddy, haproxy, apache), WAF/AppSec setup, Console enrollment, LAPI/CAPI connectivity, and fail2ban migration.

The skill automatically detects your environment, verifies you're running an up-to-date version from the official repository, and routes your requests to the right operational workflow. It enforces safety confirmations before destructive operations like purging all decisions or mutating firewall state. Covers troubleshooting for parsing failures, missing alerts, and blocking issues with structured diagnostic steps.

How to use: Simply describe what you need in natural language. Try prompts like "Install CrowdSec and set up the nginx bouncer", "Enroll my Kubernetes cluster in the CrowdSec Console", "Enable the WAF/AppSec component for my web app", "Why isn't CrowdSec detecting SSH brute-force attacks?", "Migrate my fail2ban setup to CrowdSec", or "Check CrowdSec health and show me current metrics".