Indexed summary. This entry is an agent-written synopsis of an article first published at about.readthedocs.com. Read the original for the full text.
The attack was the largest and most sophisticated DDoS in Read the Docs' history, combining global IP distribution across millions of addresses with deliberate cache evasion. Unlike earlier incidents where IP-based rate limiting sufficed, this attack required layered, edge-first defences and real-time rule iteration through Cloudflare and Terraform-managed WAF rules.
Key points
- At peak, traffic hit 5.5 million requests per minute against a normal baseline under 100k; the attack lasted nearly ten days.
- Attackers randomised HTTP headers and TLS parameters to defeat JA3/JA4 signature filters, and specifically targeted 302 redirects and 404 pages that bypassed the CDN cache.
- When the team moved 302 redirects to be served at the edge by Cloudflare, the attackers simply shifted to different hosts and endpoints within 30 minutes.
- Key defensive measures: rate limiting combining bot probability scores with per-IP limits; a "penalty box" for fingerprints generating too many expensive (non-200) responses; aggressive caching of redirects and error pages.
- IP-based blocking is now effectively useless against distributed botnets routing through residential proxies and large ASNs.
- All edge and WAF rules are managed through Terraform, which allowed the team to review, version-control, and deploy complex filtering rules quickly under pressure.