|
|
|
|
|
by maartenh
1291 days ago
|
|
Hm, using Apache APISIX for DDoS protection on a single node? That won't really stop a real DDoS. Not much you can do on a single server, if a botnet is saturating the network links to your server(s), without help from your infra provider. This setup can be used to prevent the backends from being overloaded, which one can probably already do from a single host, and depending on the speed/amount of work by the backends done, not a lot of bandwidth is required to overload most systems that have a limited amount of request processing capacity. I would argue that this is load management/shedding though, and not DDoS protection. |
|
You can't really protect against it, you can only have enough bandwidth to handle everything.