There's an NGINX container which has a bunch of security features (i.e. WAF with OWASP, auto ban of strange actors, bot challenges, integrated blocklists of bad actors, request limits etc) built-in, is well documented and even has an optional GUI.
It's called Bunkerweb and they're also at /r/BunkerWeb and on Discord.