My real SSH port was just as exposed as my fake one
Went looking for the next thing to fix and found something dumber than expected: the box hosting my honeypot had a second, unintentional honeypot right next to it — my real SSH.
The discovery
I'd assumed only Cowrie (port 2222) was exposed. A quick check said otherwise — port 22, the real sshd, was also open to 0.0.0.0/0. Any scanner had just as much access to my real login as to the fake one.
Closing the real door
Fixed it in the security group, not on the box — changed the port 22 source to "My IP." No risk of locking myself out, since editing a security group doesn't need SSH access. Password auth was already disabled, key-only login — the fix was about cutting attack surface, not plugging an active hole.
Locking /admin behind a second door
Added HTTP Basic Auth in front of Bludit's login at the Nginx level.
Almost made it worse
Nearly pointed fail2ban at the honeypot port too, out of a vague "more banning is safer" instinct — which would have defeated the entire point of Cowrie. Checked what fail2ban was actually watching: one jail, sshd, correctly scoped to the real port only.
What I actually learned
Every port a security-group wizard opens is equally open to everyone, lure or not. Restricting a rule to "my IP" is safer than it sounds — fixing it wrong just means editing it again from a browser.
Next up: what's landed in the Cowrie logs.