Friendly reminder to put your projects behind a CDN: Watched Cloudflare eat 18k malicious requests silently
Just a quick anecdote on why basic infrastructure hygiene matters, even for smaller apps.
I run a web app for QR code generation. While checking Posthog analytics this week, I spotted a bizarre spike. A single IP address from Thailand was aggressively hammering the site - over 18,000 requests in less than an hour. (Basically a mini-DDoS or a really aggressive scraper gone rogue).
What blew my mind was that our actual server performance wasn't degraded at all. No dropped connections, no latency spikes. Cloudflare caught it all.
I went into the Cloudflare security dashboard, confirmed the suspicious pattern, and dropped a block rule on the IP. Traffic instantly returned to normal.
**Just a reminder:**
* If you're running raw exposed servers without a WAF/CDN, you're leaving yourself wide open to script kiddies and botnets. * Have a logging tool that gives you geographical and IP-level breakdowns. * It's highly worth configuring alerts for traffic anomalies so you don't just stumble upon this stuff casually.