Authelia should come with rate limiting to protect against brute-force attacks. That could be enough.
I'd generally advise to make sure such protection actually works. Like look up the limits and try to login with a wrong password 30 times... Especially if you added stuff on top (fail2ban, crowdsec...). Has happened to me I misconfigured stuff and it didn't limit anything... Now I check to make sure for important bits like an authentication service.