Migrate DNS to Cloudflare (proxy all A records) UFW: deny all, allow SSH + Cloudflare IP ranges only for 80/443 Fail2Ban for SSH WAF rules to block .php, .env, wp-admin requests
Questions:
Should I request a new primary IP from Hetzner, or is proxying through Cloudflare sufficient to make the old IP irrelevant? Any recommended Traefik middlewares for rate limiting since Coolify uses Traefik?
Stack: Coolify, Docker, Traefik, Node.js apps