

You only need Crowdsec to monitor the exposed service ports. If Authentik is exposed, and has a Crowdsec plugin, then add it. Otherwise, you’re just wasting resources having it watch things it can’t take action with.
If you just need something to consolidate logs where you can watch them, use a centralized logging tool for that job.
You can easily create custom rules and bouncers if needed for something specific as well. They’re templatized for the most part. Possibly even something a stupid AI could kick out, but make sure you know what it’s doing, and don’t trust it outright.