Secure Hosting
All casesCase study
Houssni.nl 24 August 2026

Secure Hosting

The brief

A stable, hardened hosting environment with monitoring, technical optimisation and ongoing management.

Houssni.nl needed a reliable and secure hosting environment that could better withstand modern threats without introducing the management complexity associated with large enterprise platforms.

The Challenge

In a traditional single-server environment, the application and its security layers are closely coupled. This provides less isolation when suspicious or malicious traffic reaches the infrastructure.

For Houssni.nl, we therefore wanted an architecture in which public traffic would never connect directly to the application server and security controls could be managed independently from the hosting environment.

The Approach

We designed a two-server architecture that separates the public-facing security layer from the application environment.

All incoming connections first pass through a dedicated DMZ server. This server acts as the controlled entry point to the infrastructure and inspects traffic before it is forwarded to the application environment.

Suricata IDS/IPS analyses network traffic and can detect and block known suspicious patterns. CrowdSec adds another layer by using threat intelligence from the wider CrowdSec community to automatically block known malicious sources.

Firewall rules then enforce that the application server only accepts traffic through the security layer. Direct connections from the public internet to the application environment are blocked.

Only after traffic has passed through these security controls is it forwarded to the separate application server, where Coolify manages hosting and deployments within an isolated environment.

By separating security from application hosting in this way, the infrastructure gains an additional layer of defence without making day-to-day management unnecessarily complex.

The Result

The application server is not directly reachable from the public internet. Firewall rules ensure that incoming traffic can only reach the application environment through the dedicated security layer.

Suspicious and known malicious traffic can be detected automatically and blocked where possible, while the environment can be monitored continuously.

At the same time, operational management remains straightforward through Coolify. The architecture also provides room to scale security controls, capacity, and applications independently as the environment grows.

Explore more work