We implemented CrowdSec for bot/scraping mitigation. The architecture is sound, but it ended up having an unacceptable false positive rate for us. This may be an issue with any kind of IP reputation approach. After a couple of months of work getting it ready to go I had to turn it off after a couple of days.
Interesting, did you implement only IP reputation (via blocklist) or did you deploy the WAF as well? Regarding bot scrapping, you would probably want to try the new bot detection feature recently released
itintheory · · focus · HN ↗
mazzma · · focus · HN ↗
itintheory · · focus · HN ↗
wrt bot detection - this sounds very much like Anubis which we're also using with some success.