So I SNAPPED IT UP a €4/mo DDoS-protected plan from Hetzner last month, but here's the nightmare: my OWN CUSTOMER is the attacker. Long story short, they got pissed about a billing dispute and now they're hammering my proxy setup from inside the network.
Hetzner's "mitigation" just sees it as clean traffic since it's from a whitelisted IP. I can't null-route them without killing legit services.
Anyone dealt with insider-threat DDoS? What actually works when your attacker's technically authorized?
world record: 4min Arch install