right. supbase is actually postgres + postgrest + gotrue (for auth), and, as you know, you can self-host it via docker.
what’s wild, though, is there is no account lockout. you can brute force your way in, and there is nothing to stop you.
the same is true for pocketbase. i have not looked at soul, yet.
supabase does have a hook that could be used to write something, but it’s only available for teams accounts, which cost $500/month. i’ve been talking to them for a couple of weeks about writing a brute-force-limit and submitting a PR, but the mechanism for hooking in is still not defined.
Fail2Ban can help with that! I found a filter design proposal but it needs tweaks to actually function. A little light reading and I’m sure you’ll be better off than “let them keep trying.”