

Fail2ban config can get fairly involved in my experience. I’m probably not doing it the right way, as I wrote a bunch of web server ban rules — anyone trying to access wpadmin gets banned, for instance (I don’t use WordPress, and if I did, it wouldn’t be accessible from my public facing reverse proxy).
I just skimmed my nginx logs and looked for anything funky and put that in a ban rule, basically.
You can have a lot of smart functionality and remain local-only (e.g., Home Assistant). All my smart devices are on their own VLAN with no Internet access — if something breaks it’s not the cloud’s fault, it’s mine.