If it's just you, and you're fine with the regular login... Just disable signup and don't add more authentication mechanisms like oauth/openID. I'm using nginx as a reverse proxy as well. For now, I added a lot of "deny" directives to ban all the address ranges from Tencent, Alibaba, OpenAI. It's not a 100% solution, but works well enough for me. I'm mostly worried about AI crawlers causing too much load on my server. And it stopped since, so I don't think I'm gonna need Anubis and all these extra things in front if my applications. If you like you can look into solutions like a web application firewall like Crowdsec.