Security
The security model separates public service exposure from private administration. WireGuard provides the private network path, while SSH and NoMachine apply independent authentication policies for terminal and graphical access.
Host and service controls enforce those boundaries with firewalld and SELinux. CrowdSec adds detection from ingress logs, while detection and firewall response remain independently verifiable layers.