10 ms·
Firebase bill is usually $50, but I was surprised to see a $70k bill in one day
- android521 2y agoDamn, Just learned that firebase budget is not a hard limit. This is bad. Is there a way to setup a hard budget limit? if not, i think I will need to replace firebase for my web app.
- dpig_ 2y agoAs far as I can tell, no cloud products outside of consumer-facing SaaS allow you to set hard limits or automatic stops. The best you can do is configure spending alerts (and hope you're awake to see them). I've found it pretty nerve-wracking, then, to attempt to get some hobby projects online. I don't like writing blank checks for my hobbies..
- jsheard 2y agoDoes Firebase allow you to set up a billing limit, or is it one of those exciting cloud services where no matter what you do you're always one mistake away from losing your house?
- stavros 2y agoApparently she had a $20 limit, but, if my calculations are correct, $70k is more than that, which seems odd.
- whoisburbansky 2y agoSomebody else pointed out that it's likely just an alert, not a hard limit, which checks out given Firebase documentation (https://firebase.google.com/docs/projects/billing/avoid-surprise-bills https://firebase.google.com/docs/projects/billing/avoid-surp...), which has no mention of hard limits and explicitly warns you that an alert won't stop anything.
- stavros 2y agoAh, oops...
- layman51 2y agoThey have a documentation page titled “Avoid surprise bills”[1] but I imagine it’s easy for some developers to skip over that. [1]: https://firebase.google.com/docs/projects/billing/avoid-surprise-bills https://firebase.google.com/docs/projects/billing/avoid-surp...
- unsnap_biceps 2y agohttps://firebase.google.com/docs/projects/billing/avoid-surprise-bills https://firebase.google.com/docs/projects/billing/avoid-surp... > We don't turn off services and usage because although you might have a bug in your app causing an increase in spend, you might just be experiencing unexpected positive growth of your app. You don't want your app to shut down unexpectedly when you need it to work the most. Frankly, I don't see anything on that page that would actually prevent a surprise bill.
- jsheard 2y ago> A budget alert sends an email whenever your project's spending level hits a threshold that you've set. Budget alerts do NOT turn off services or usage for your app. It's not an automatic hard-stop so you could still screw yourself over pretty badly with runaway spending.
- rezokun 2y agoeg. OpenAI enforces strict limits until you spend a significant amount of money.
- mason55 2y agoMy guess is that OpenAI’s margins are much lower so they aren’t in a position to forgive or have people skip out on big bills. For Firebase, their costs are probably pretty marginal.
- falcor84 2y agoFrom my experience, cloud LLMs are still being used by most systems as an "additional feature" with fallback to alternative basic functionality, or some other form of graceful degradation. On the other hand, there typically isn't a good fallback to having your main DB go down.
- danpalmer 2y agoI understand joking about this and the possible downsides, but there are good reasons why cloud services are set up this way: 1) it's impossible to bill at scale and exactly cut off service usage globally when a target is hit, and 2) most companies don't want a single point of failure like a misconfigured budget to bring down their production services. The answer is probably quota management, where a limit on the number of VMs or size of database or something, caps the worst-case scenario, and where it's arguably easier to monitor an approach to that quota as it's more granular than billing. Personally I think cloud providers could have an explicit "hobby mode" that limits certain things in such a way that the spend can't run away like this, with the trade-off that they're not really production grade in a sense, but then again those accounts are probably worth anything so I understand not building that out. That said, whenever I've seen one of these things happen, it always ends with "FooCloud said that as a one-time gesture of good will they would write off this accidental usage", so while briefly scary, maybe this is the system working fine overall?
- jsheard 2y agoAzure does actually have the ability to force-kill your resources when you hit a certain billing threshold, but only for things like free trials and student accounts. The instant you switch to a regular pay-as-you-go account that functionality disappears for uh... reasons. https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/spending-limit https://learn.microsoft.com/en-us/azure/cost-management-bill...
- danpalmer 2y agoThat's good, it makes sense it would be for only those sorts of accounts. Imagine building a billing system that could always do that, any time you accept a request, you need to check against a database if the user has hit their billing limit or if you can charge them for it. It obviously can't work. I imagine the way MS make it work is probably to slow down resource consumption for those accounts dramatically, and then just take the hit on overspend, knowing that it will be almost nothing.
- 2y ago
- danpalmer 2y agoFirebase is pretty simple to use, and possibly because of this, I've seen quite a few terrible implementations. I think it attracts people who only know app development, where security, scalability, authentication, etc, are not really a concern because you have exactly one user on one device. It's easy to accidentally make a bunch of information world-readable, and if a malicious user gets hold of the right details they can simply read all your content out, or even start writing bad content in, racking up a bill in the process. Whether this is what happened here or not I have no idea. And I don't think this is even really a problem with Firebase, just an indicator of the sort of developer who ends up using Firebase and their background.
- mrtksn 2y agoIt's simple to start but quite hard to master actually. It has plenty of counterintuitive concepts that even an experienced developer can get wrong and result in ruinous expenses or catastrophic security issues. Especially on Firestore. For example, the access rules that you define on your properties are not filters(they are rules on what you can ask the system to do) even if they look like filters at first glance and the way it accessing data is billed is based on what has had to be processed to return the results and not on what the actual results were returned. This makes it very easy to create very expensive and compromised apps if you slip. Also, unlike more traditional system, doesn't produce smoke so it passes all the smell tests and you learn about your mistakes once things go very bad.
- bherms 2y agohopefully dev has insurance? but anyway, this is partially why I spin up an LLC for every app i make... just declare bankruptcy and kill it
- kstrauser 2y agoYou're not wrong. An LLC and similar aren't perfect, but it gives you an enormous amount of legal bargaining power compared to not having one.
- falcor84 2y agoIn what sense is it not perfect? As long as you don't commit actual fraud, creditors can't "pierce the corporate veil" of an LLC, can they?
- bherms 2y agoIt's not technically fraudulent to use your personal bank account, per se. You need to keep great records though. But from what I understand that could be enough to consider the veil pierced. Also need to make sure you don't personally ensure any debts.
- kstrauser 2y agoWhat the sibling said. You also have to be sufficiently business-like in your projects, according to legal advice I got. If you slap an LLC on your obviously hobby project, they might be able to make the case that it wasn’t a legitimate business operation. That is fraud isn’t the only way to pierce the veil, I was told.
- spacecadet 2y agoThis is the way.
- falcor84 2y agoThat's a really cool idea. Would you mind sharing more? In particular, do you use something like Stripe Atlas for that? And if so, is there any impact to your account with them when you declare a bankruptcy?
- iambateman 2y agoThe idea that an app will experience stratospheric growth so suddenly that costs must be allowed to grow 1,000x hour-over-hour has always been insane to me. Why does Firebase insist on hanging the sword of Damocles over all of its customers? I’ve read so many stories before and experienced these fears the first time I was setting up Firebase…this has been going on for years
- chuckadams 2y agoThat's every cloud provider. At this point, I think they're actively conspiring to not implement billing caps.
- danpalmer 2y agoI used to think this until I tried architecting out how you'd build a billing cap. I recommend it as a design exercise. It's easy to build a bad billing cap that would slow down services and cause outages, but it's basically impossible to build a good billing cap.
- hackingonempty 2y agoHow is the service being able to answer the question "is there budget available for this action?" different from "is there authorization for this action?"
- williamstein 2y agoOne example - Google Cloud network egress charges aren’t known until up to ~2 days after they happen. Since they can be obscenely expensive (eg $0.23/GB), they can make budget computation difficult.
- stefanfisk 2y agoWhat is the cause of this delay?
- mrtksn 2y agoIn the days before, there used to be a hard spending limit - I know this because of an old official tutorial video on youtube. Last time I checked, there was billing alert functionality and they were recommending creating a function that will halt your service when it hits the limit - the problem is, billing lags behind and you can rack up a hefty sum until anything is triggered. Amazing service but its a scary one. Every time a social-media-worthy accident happens, they cancel the bill but I wonder how many are burned without recourse. Maybe if your rack up something modest like 5K accidentally, its better to push it as high as you can and get it declined on your CC and increase your social media prospects :)
- cozzyd 2y agoIf you owe Google $70k, you have a problem. If you owe Google $70T, Google has a problem.
- jlcummings 2y agoIt’s weird how normalized over cap billing became acceptable simply because chargeable metrics were not collected/resolved until after the fact. Seems like an obvious gap in the process or a little bit shady.
- deleted 2y ago[deleted]
- ChrisMarshallNY 2y agoMaybe this has something to do with it? https://x.com/tamarajtran/status/1867342095033258466 https://x.com/tamarajtran/status/1867342095033258466 There's a really good reason that I don't link to my apps on this site (or most, for that matter). They are free apps, running on a shoestring budget. But that whole account looks a little dodgy. The posts make it seem like one of those "I made $30K/mo, from my living room! You can too!" outfits.
- danpalmer 2y agoPeople always underestimate how easy it is to sell $70k for $30k.
- andrewmcwatters 2y agoI've had the very nice pleasure of always doing business with providers who would simply drop access to the server when bandwidth had been met or exceeded with my service. But what's odd to me is that I don't often read about other people having the same experience. So... are all of you seriously with hosts that don't shut off access to your servers? I'd rather that happen than suddenly get a bill I can't afford.
- Havoc 2y agoThat’s the third big GCP bill story I’ve seen in like 48 hours. Over on Reddit someone got stuck with a 450k one. Struggling to find the third thread again though. Maybe they deleted it Also seeing an uptick in people suggesting insurance as the solution. Which seems insane to me but what do I know
- deleted 2y ago[deleted]
- danpalmer 2y agoThe insurance thing also seems weird to me, what are you insuring against? It sounds like people are suggesting insurance against... cloud providers just deciding to randomly bill you, but that's not how it works. Are you buying insurance against having a successful business? No one is going to sell that. Are you buying insurance against being hacked? That makes sense and does exist, but only solves one very specific version of this and isn't really about cloud billing, plus it's likely not accessible to the size of business (or individual use) who get bitten by this sort of thing. Are you buying insurance against incompetence using the services? You can get professional indemnity insurance, and I guess your own LLC could probably sue your own indemnity insurance in this sort of case, but you'd need to defend the decisions as reasonable at the time and not negligent.
- kccqzy 2y agoThey are just insuring against an unexpectedly large bill. That's how I read it. It doesn't even have to involve any proof or disproof of negligence. Just make it a purely financial transaction. You pay $1,000 as a premium such that if the cloud bill exceeds $10,000 the insurance will pay you half of that, up to a limit of $20,000. It makes sense as a financial product. Of course the numbers above are purely hypothetical.
- tasuki 2y agoNo it does not make any sense whatsoever. If you wanted to sell such insurance, I'd be very happy to buy it for my upcoming $20,000 cloud bill!
- nomilk 2y ago> Upwork engineer Arguably worse than an average 2025 LLM.
- cr125rider 2y agoSomeone came up to me at CES peddling outsourcing teams. I told him we just use Copilot.
- nomilk 2y agoIf he had a good sense of humour he'd have replied "so do we"
- hardwaregeek 2y agoYeah there's your problem. Hiring a random person and giving them unlimited access to compute resources is a bold move to say the least. If you're gonna work on something like this, do it yourself or hire someone who you can really trust. That won't totally prevent it but it's better than rando Upwork contractor who will move on to the next gig
- amazingamazing 2y agotldr: stored 1pb in a GCS bucket. this persons twitter account is about how they have hacked growth and have had 3 number one apps, crazy growth, etc. well, I hope they can pay. also, billing caps really don’t make any sense. a competitor could easily exploit that to take your service down. best to you know, architect your stuff correctly… speaking of architecture, creating a paas where you have a hard billing cap would pretty much obliterate performance as you would need round trips each time you do anything in order to confirm you’re not over the amount.
- danpalmer 2y agoDid they jump from zero to 1PB in one day? Or is this something like GCS usage only shows up on a Firebase dashboard view once a month? (I'd look this up myself but replies on Xitter seem to be Muskwalled)
- amazingamazing 2y agoyes, apparently on october 18th alone they managed to rack up a single petabyte, which honestly sounds implausible, but who knows what they were doing.
- kccqzy 2y agoThe thread said the app was only running for one day, so I think it wrote 1PB during that one day.
- rezokun 2y agoSo, better if competitor will make you bankrupt?
- ashu1461 2y agoThis happened to me previously where enabling a firestore backup service almost doubled my bill. In my case the google support people were very gracious to wave that off, it took some time but it happened. Had a good experience with them. Though I wish taking backups on firestore was easier.
- hattmall 2y agoRun your cloud contracts (or anything possible to incur liability) through a separate LLC so if there are billing issues you can just move on. The structure should look like: "My App LLC" has contract with "My Host LLC" for hosting services. "My Host LLC" provides those services via a cloud provider. If "My Host LLC" racks up a 2 million dollar bill with the cloud provider and goes out of business then I just move to "New Host LLC" and carry on. It's not as if the patients of a Doctor who fails to pay his office rent would become liable. This is the entire purpose of LLCs.
- fargle 2y agoah, yes. the "Shady Roofing Contractor" business model. "don't worry, all the work has warranted by New Quality Roofing Services IV, LLC" although, there's very little about that structure that's unique to an LLC. it can be done the same with a corporation. i'm certain this only works when the amount of debt being ripped off (ahem in dispute) is not a lot more than the cost to sic a really good law firm on you.
- feoren 2y agoI'm not a lawyer but this sure sounds illegal. Piercing the veil?
- standeven 2y agoLLC liability protections are not absolute. I wouldn’t be surprised if this would fall under gross negligence or callous indifference or some other legal umbrella that voids the liability protection. I also wouldn’t be surprised if there’s some fine print in the account agreement that creates a personal guarantee.
- tessierashpool9 2y ago> callous indifference i like this one. the ultimate law to subjugate everybody once and for all!
- jahewson 2y agoThat’s not going to fly. Firstly, because cloud contracts generally prohibit renting out the cloud services as-is - you can build a product on top of it but not act as a reseller of their platform. Secondly, and perhaps most importantly because setting up separate LLCs with the goal of avoiding lawful debts is the demonstrates fraudulent intent and will get your LLCs veil-pierced.
- jijojv 2y agoI always use a virtual credit card number (like Citi provides) everywhere which has a daily hard limit.
- papichulo4 2y agoGood advice indeed, but paying is only one part of the problem; you'd still owe the bill.
- Havoc 2y agoProvides precisely zero protection against this. Even if your card declines or you used a prepaid card...you're still legally liable for the full amount.
- pier25 2y agoUgh I still have a couple of apps running on Firebase. I can't wait to get rid of those. In 2016 Firebase seemed the holy grail for frontend devs and I deeply regret ever using it.
- KronisLV 2y agoWe are going to continuously see cases like these until the vendors implement functionality like: Hard Spending Limit If you configure hard spending limits, then upon the sum of money being reached, the service will be stopped until manual user action is taken. This can result in service outages. Spending limit: ______ $ I have read and agree with the terms: [X] [Confirm] Which is likely to happen never. That's why I mostly use traditional VPSes.
- hdjjhhvvhga 2y agoOne of the reasons Supabase is getting so popular now.
- Gud 2y agoAbsolutely. Even getting a super sweet deal, like “$1/month” can backfire, because suddenly you are on the hook for $299 /ysatly, because the three month subscription defaults on a high premium once it’s over. Not what would be the consumer friendly choice, which would be to charge “same as before”, i. e $0.
- Havoc 2y ago>Which is likely to happen never. Correct. Because it would change the dynamic with enterprise customers. Right now CEO/CFO is forced to accept unlimited open ended billing. If there was a way to set a hard limit companies would utilize it as part of their annual budgeting, not just hobbyists. That would be bad for big cloud's profits.
- andrewstuart 2y agoGo get a $50 unlimited traffic VPS from IONOS.
- ChrisMarshallNY 2y agoI notice that the post is now gone. Looks like she locked her feed. Probably because of this discussion.
- frabia 2y agoThis is ridiculous (for Firebase). There have been countless episodes like this one happening, as well as the amount of people asking for a hard-block when the spending reaches a certain limit (currently there's only a notification that is triggered, which is anyway lagged behind the actual execution). Making a mistake can happen to anyone (especially for a platform that targets itself to new devs) and makes me seriously consider leaving the platform. To Firebase: either you must automatically condone such mistakes or implement the requested feature. To anybody else: Does Supabase or other platforms offer this?
- paullazer 2y agoThat’s exactly the kind of nightmare scenario that inspired us to create Prelude (https://prelude.so/ https://prelude.so/). Authentication flows are targeted by fraud like SMS pumping that leaves companies with super high bills that make no business sense. Our API helps apps take control of their SMS verification costs by proactively blocking fraudulent and suspicious verification attempts before they ever trigger an SMS. On top of that, we let users set daily limits as an additional safety net, so surprises like this don’t happen.
- deleted 2y ago[deleted]
- Vampiero 2y agoClearly the problem here is using SMS as a verification method instead of an authenticator or literally just an email.
- iJohnDoe 2y agoProbably a silly question, but what are the apps she built? Just curious what they are. Thanks.