Registers tomMoulard/fail2ban v0.7.1 as an experimental plugin and applies it globally on the web-secure entrypoint alongside security-headers. Bans IPs after 5 failures within 10 minutes for 3 hours; whitelists RFC1918 ranges to protect internal/Docker traffic. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>