3 ms·
What do you do when even your rate limiting layer gets fully saturated with requests? Does one have any options other than involving CF? I thankfully never was
by no_time 2y ago
What do you do when even your rate limiting layer gets fully saturated with requests? Does one have any options other than involving CF?
I thankfully never was in the postion to experience this but I always wondered how far let's say nftable rules go in thwarting a DoS attack against a conventional webapp on a tiny VPS.
- abrahms 2y agoYou have to choose good defaults. For some systems, that's fail open. For others, it's different. I'd also begin to ask "are there solutions that are futher upstream and/or lower on the OSI model where we could handle this level of overwhelm?"