Decision inbox
CrowdSec scenarios arrive with target hostname, confidence and proposed remediation before an operator acts.
Bastion is the control layer between CrowdSec decisions and Plesk operations: AppSec rules, domain allow lists, expiries and audit context in one focused surface.
Bastion Security
example-host-03 / live decisions
Decision
source IP + ASN
audit trail per support action
Scope
server default / domain exception
no accidental fleet-wide bypass
Expiry
time-boxed by default
exceptions auto-close, no whitelist sprawl
Live on production — fuseboat.co reference deployment
Marketplace extension. No custom package flow.
Test CrowdSec LAPI before enforcing decisions.
Server default with domain-level overrides.
Source, hostname, scenario, decision, expiry.
Product cockpit
Every decision keeps its source, target hostname, scenario and expiry attached, so operators can enforce without losing context.
CrowdSec scenarios arrive with target hostname, confidence and proposed remediation before an operator acts.
Apply server defaults, then carve domain-specific allow lists with expiry and an operator note.
Every ban, captcha or bypass keeps enough evidence for the next ticket without leaving Plesk.
Bastion Security Live · refresh in 12s
1 818
attacks blocked in the last 24 hours
0 captchas
domains exempted
packets at firewall
7 unique · 50 hits
17 countries · 50 attacks tracked
mail.fuseboat.co · Switzerland · 17 hot zones
Controls
Architecture
Bastion Security sits between the CrowdSec decision stream and the Plesk operator, where scope, expiry and support context matter.
01
source, scenario, confidence
02
expiry, note, local override
03
server default, domain allowlist
04
ban, captcha, allow, rate-limit
operator sees
`source IP + ASN + target hostname + scenario + decision + expiry + operator note`, without leaving Plesk.
Stack fit
It is not positioned as a monolithic suite. It is the Plesk-native control plane for CrowdSec decisions and operator-safe exceptions.
Keep Imunify for suite-level malware, reputation and hardening. Add Bastion where CrowdSec decisions need Plesk-native scope and support review.
Bastion turns LAPI signal into hostname-aware actions, expiring exceptions and readable audit context for hosting teams.
For Plesk operators, policy belongs in the extension workflow, not in copied jail snippets and SSH-only playbooks.
Marketplace
Plesk install
CrowdSec-native
LAPI
Scoped override
domain + expiry
Audit trail
support-readable
Pricing
CHF 19
Per-server commercial license for hosters running production Plesk domains.
Custom
Volume licensing for MSPs and hosting platforms. Pricing on request.
FAQ