← ClaudeAtlas

crowdseclisted

Use when the user is installing, configuring, operating, or debugging CrowdSec — including cscli, LAPI/CAPI, hub collections, parsers/scenarios/whitelists deployment, bouncers (firewall, nginx, traefik, caddy), WAF (AppSec component) deployment, bot detection / AppSec challenge mode (blocking headless browsers and scrapers, allowing verified crawlers), profiles, notifications, upgrades, and fail2ban migration. Covers bare-metal/systemd, Docker, Kubernetes/Helm, and CrowdSec Console enrollment. This is an operational skill — it does not author WAF rules, scenarios, or parsers.
crowdsecurity/crowdsec-skill · ★ 24 · AI & Automation · score 78
Install: claude install-skill crowdsecurity/crowdsec-skill
# CrowdSec — operations, deployment, configuration, and debugging **Glossary:** *AppSec* is the engine component name (in configs, hub paths, `cscli appsec-*`, Helm workload); *WAF* is the user-facing term for the same thing. This skill uses both interchangeably. ## Boundary — what this skill does and does not do | You want to… | Use | |---|---| | Install / upgrade / uninstall CrowdSec | this skill | | Configure acquisition, hub, profiles, notifications | this skill | | Install and wire a bouncer (firewall, nginx, traefik, caddy) | this skill | | Deploy the WAF (AppSec component) | this skill | | Deploy and tune bot detection (AppSec challenge mode) | this skill | | Debug "logs not parsing" / "no alerts" / "bouncer not blocking" | this skill | | Migrate from fail2ban | this skill | | **Write** a parser, scenario, or WAF (AppSec) rule | the `crowdsec-local-mcp` mcp | | Drive the **cloud Service API** (manage blocklists / allowlists / firewall integrations / metrics / decisions programmatically) | the `crowdsec-service-api` skill | ## Step 1 — Detect the environment Run probes in this order. Stop at the first match. ```bash # systemd / bare-metal systemctl list-unit-files crowdsec.service >/dev/null 2>&1 && systemctl is-enabled crowdsec >/dev/null 2>&1 # docker docker ps --format '{{.Names}} {{.Image}}' 2>/dev/null | grep -E '(^|/)(crowdsec)([: ]|$)' # kubernetes kubectl get pods -A 2>/dev/null | grep -i crowdsec ``` If nothing matches and the user reports CrowdSec is i