At 21:47 CET on 30 November, a customer running a game community in Amsterdam started receiving a carpet-bomb attack: UDP reflection across a /24, peaking at 1.9 Tbit/s and 412 Mpps. It is by a wide margin the largest thing our edge has absorbed.
What happened at the edge
Detection is flow-based and runs continuously, not on a threshold you have to buy into. The signature crossed the trigger 1.4 seconds in; scrubbing was fully engaged at 3.1 seconds. The targeted instance saw about 40 seconds of degradation while TCP recovered, and nothing else on the site was affected — no packet loss on neighbouring instances, no elevated latency at the exchange.
What we changed afterwards
1.9 Tbit/s against 7 Tbit/s of scrubbing capacity in that region is a comfortable margin until it is not. We doubled edge capacity across the fleet in December, from 7 to 14 Tbit/s, and moved the Amsterdam and Frankfurt scrubbing pools onto separate transit paths so a single upstream cannot become the bottleneck.
The unglamorous part
- 01Nobody was paged. The system did what it was built to do and the on-call engineer read about it in the morning summary.
- 02The customer was told before they noticed, because the notification is automatic.
- 03It cost us about €4,100 in transit overage for the month. That is included in the price you already pay; there is no scrubbing invoice.