Bot Traffic on AWS Load Balancer: A Cautionary Tale

This title was summarized by AI from the post below.

Last week we thought our product was finally “taking off”. Traffic on AWS Load Balancer was going up every hour. We didn’t run any big campaign… but still, numbers looked great. For a moment, we were happy. Then we checked actual users. Nothing changed. Something felt off. So we started digging. 1. First checked app logs → nothing useful 2. Then ingress logs → a bit weird 2. Then Load Balancer logs → yeah… something’s wrong It wasn’t users. It was bots. A lot of them. Same endpoints getting hit again and again Random user agents No real behavior — just hammering requests And the worst part? They were quietly increasing our AWS bill. -- Just fixed it step by step: 1/ Put AWS WAF in front and enabled basic bot + rate limiting 2/ Blocked a few obvious IP ranges 3/ Added rate limits on Kubernetes ingress 4/ Added some basic checks in backend (nothing crazy) Within a few hours: Traffic dropped (the fake one) Costs dropped Server felt lighter Honestly, the scary part is: If we didn’t check deeper, we would’ve celebrated "growth" that wasn’t even real. Not all traffic is good traffic. #aws #kubernetes #devops #buildinpublic

To view or add a comment, sign in

Explore content categories