The 3am volumetric flood that never reached origin
A gaming forum in Amsterdam took a 47Gbps UDP-and-HTTP flood at 3am. The origin had a 1Gbps uplink — it should have been instantly dead.
It survived because we'd pre-built the runbook:
— Origin IP was never public; only the CDN's anycast range could reach it, locked by firewall to those ranges
— Rate-limit rules were already armed: 50 req/min per IP on login and search, the two expensive endpoints
— A managed challenge auto-triggered when request rate per ASN spiked 10x baseline
— Anycast spread the 47Gbps across 30 POPs, so no single POP saw more than ~1.6Gbps
The flood hit the edge and dissolved. Origin traffic that night: normal. Build this before the attack — writing firewall rules while you're being flooded is how origins die. Hide the origin IP first; everything else is secondary.
The number that mattered: 0 attack packets that reached the 1Gbps origin.
Edge of Glory
@EdgeOfGloryCDN
The 3am volumetric flood that never reached origin
Этот пост опубликован в Telegram-канале Edge of Glory. Подписаться можно по ссылке: @EdgeOfGloryCDN.