
2 June 2026
Migrating from NPM to NPMplus with CrowdSec and MaxMind
After using Nginx Proxy Manager to expose several self-hosted services, I wanted to strengthen the reverse proxy layer without losing management simplicity. I therefore migrated to NPMplus, a fork of Nginx Proxy Manager, then added CrowdSec and MaxMind-based geographical restriction. Everything is deployed using Docker Compose to keep the stack reproducible and easy to update.
Why leave NPM
Nginx Proxy Manager did a good job of managing domains, certificates and redirections. NPMplus takes this foundation as a fork, with a familiar interface, while opening up more possibilities on the security side. Above all, I wanted better integration with CrowdSec, more control over access and a configuration better suited to my current usage.
- Keep an interface close to NPM for managing proxy hosts.
- Add CrowdSec remediation directly at the reverse proxy level.
- Limit certain access based on country of origin using a MaxMind GeoIP database.
Docker Compose Architecture
I kept Docker Compose as a single entry point. The idea is to be able to restart or move the stack without having to recreate each service by hand. The volumes contain the NPMplus configuration, the logs analysed by CrowdSec and the GeoIP database used for geographical restrictions.
- NPMplus: reverse proxy, certificates and proxy hosts.
- CrowdSec: log analysis and creation of blocking decisions.
- Remediation component: application of CrowdSec decisions on the proxy side.
- MaxMind / GeoIP: association of IP addresses with a country to apply geographical rules.
Simplified Compose diagram: NPMplus receives traffic, writes logs, CrowdSec analyses them, then the remediation component applies decisions. The MaxMind database is mounted as a volume to enable geographical restrictions.
Firewalling architecture

The architecture separates public traffic from the management plane. NPMplus remains the entry point for exposed services: it terminates TLS, applies GeoIP rules based on MaxMind and uses CrowdSec decisions to block sources considered malicious. Administration goes through a Teleport bastion host with strong authentication rather than management interfaces exposed directly on the internet.

Migration of proxy hosts
Migration was done service by service. I first took over the existing proxy hosts, checked the internal destinations, then checked the certificates and access rules. This step is important: an error in the reverse proxy can make a service inaccessible or, worse, expose something that shouldn't be.
- Verification of ports and internal destinations.
- Checking certificates before switching over.
- Testing services from the local network and then from the outside.

Adding CrowdSec
CrowdSec adds a detection layer on top of the reverse proxy. It reads logs, recognises certain suspicious behaviour and produces blocking decisions. In the console, I can monitor the state of the engine, active scenarios, blocklists used and the remediation component linked to NPMplus.
The interesting point is that protection no longer depends solely on rules written by hand. Community blocklists and CrowdSec scenarios make it possible to filter some opportunistic traffic: web scans, IPs already known for attacks or repeated behaviour on non-existent routes.

Geographical restriction with MaxMind
For certain services, I don't need to accept worldwide traffic. I therefore added a geographical restriction based on MaxMind. The principle is simple: the GeoIP database identifies the country associated with an IP, then the plugin applies an allowance or blocking rule depending on the proxy host concerned. Updating this database is automated in Docker Compose, which avoids having a manual maintenance step to manage.
This is not absolute protection: a VPN or relay can bypass this type of filter. But it is a good reduction in the exposure surface for services intended for personal or family use, especially combined with CrowdSec and strong authentication when necessary.
Points to watch
- Keep real client IPs in the logs, otherwise CrowdSec and GeoIP lose part of their value.
- Mount log and configuration volumes explicitly in Docker Compose.
- Test geographical restrictions from multiple networks before considering the configuration reliable.
- Automate updating the MaxMind database with a dedicated container.
Summary
This migration allowed me to keep the simplicity of NPM while strengthening the security of the reverse proxy. NPMplus centralises host management, CrowdSec filters out some of the malicious traffic, and MaxMind adds useful geo-restriction for services that are not intended to be accessible everywhere. At the same time, Teleport isolates the administration plane behind a bastion host with strong authentication. Keeping the reverse proxy and security stack in Docker Compose makes it clearer and easier to redeploy.