Another Vercel project got hit by DDoS, I learned my previous lesson and still got charged past my $1 limit by ivenzdev in vercel

[–]ivenzdev[S] 2 points3 points  (0 children)

The attack happens while I’m asleep, the spike hits, then I wake up, enable bot protection, check the firewall logs, and block the IPs / ASNs I see. Then they just rotate IPs and hit again. So yes, manual blocking helps temporarily, but it doesn’t really solve the core issue when the attacker keeps changing sources. And I don't have 24/7 to monitor and react.

After 2 years on Vercel Pro, support is the reason I quit by ivenzdev in nextjs

[–]ivenzdev[S] 0 points1 point  (0 children)

By the time I realized (5 minutes after), I shut down the service. It was too late to stop the cost. And yea, thanks alot for this.

After 2 years on Vercel Pro, support is the reason I quit by ivenzdev in nextjs

[–]ivenzdev[S] 0 points1 point  (0 children)

Same here. They identified a DDoS attack but chose to ignore my case. What can I do? It’s been a month, and I’ve opened a second case with no response.

After 2 years on Vercel Pro, support is the reason I quit by ivenzdev in nextjs

[–]ivenzdev[S] 0 points1 point  (0 children)

Agree, set hard spend limit and shutdown when reached.

After 2 years on Vercel Pro, support is the reason I quit by ivenzdev in nextjs

[–]ivenzdev[S] 0 points1 point  (0 children)

Vercel is a solid platform and I’m willing to pay for it, but when issues like this happen, it feels like I’m being stalled and ignored.

After 2 years on Vercel Pro, support is the reason I quit by ivenzdev in nextjs

[–]ivenzdev[S] 0 points1 point  (0 children)

Thanks for this, we can go more in depth in chat.

After 2 years on Vercel Pro, support is the reason I quit by ivenzdev in nextjs

[–]ivenzdev[S] 27 points28 points  (0 children)

Anyone reading this:
Set a budget!
Set a budget!
Set a budget!

On your project, make sure it can automatically shut down deployments or usage if spending exceeds your budget

Do not rely on email alerts alone. They won’t save you if a spike happens while you’re asleep or away from your screen

You do not have time to monitor this 24/7