Skip to main content -
We Built Automatic Quota Failover, Then Ran a Drill and Watched It Miss Five Crons
-
The 2019 Change That Silently Blocked a Renewal Notice for Nearly Seven Years
-
The Block Rule That Also Blocked a Paying Customer's Front Door
-
An Outage Alert That Kept Blaming Us for Someone Else's Server
-
An Error Spike Was Actually Two Separate Problems
-
The Auth Gate Had Exactly One Correct Position, and I Guessed
-
The Runbook Said Three Minutes
-
The Safety Check I Trusted Wasn't One
-
The bot swarms moved faster than my firewall rules
-
The Zombie That Blocked Everything
-
The Migration Flip That Took Down a Live Customer (and the Blast Radius I Could Measure in 12 Seconds)
-
It Looked Exactly Like a Bot Swarm. It Was SQL Server Parameter Sniffing.
-
The customer's own scraper IS the bot swarm you've been fighting
-
The Prod Box Was DDoSing Itself: An iCal Calendar Feature Looping Through the Public Edge
-
"The Whole Island Can't Reach Your Site": US Territories Are Separate Countries to Cloudflare
-
Five firewall rules beat the proxy swarm, but the real bug was my blind spot
-
Operator, not IP: fingerprinting a 40,000-IP proxy swarm by its RIPE maintainer
-
Whack-a-mole is a real strategy: firewall blocks as a legitimate holding pattern
-
The bot swarm that turned out to be one bad query plan
-
My agents quietly hoarded 48 GB of Chrome profiles until the machine froze
-
The exit survey that overwrote a live mailer
-
Bot Swarm Detection: The Three-Signal Triangle That Catches What IP Reputation Misses
-
The One-Shot Data-Repair Script as a First-Class Artifact
-
When the Paywall Flow Is Broken, Build the Staff Tool, With Dry-Run, a Cap, and an Audit Row
-
The method outlasts the patch
-
The fastest fix was blocking the bot by name
-
"Bamboo is broken" was wrong: a deploy that races the filesystem under CPU pressure
-
UTC logs, a local clock, and the canary request: timezone discipline in an incident
-
The decorative database: when your blocklist table isn't actually on the request path
-
A Migration Became the Audit I Had Never Run
-
The UA blocklist is the right-sized fix for an identified crawler (and the wrong one for a swarm)
-
The bot-swarm that broke the playbook: URL fan-out beats top-IP-by-volume
-
The fix that ran on every request
-
The attacker was our own redirect logic
-
The call was coming from inside the house
-
The rate-limiter that banned our power users: 302 to 200 redirects look like an attack
-
The SSL bug was easy. The bot traffic made it a day-long incident.
-
Route a Change by Its Blast Radius, Not Its Size or Your Schedule