We are currently suffering from a network-level DDoS attack. Or maybe just a single actor. Anyway, our downlink is jammed.
We have finally reached a somewhat stable level of operation. In the past hours, we managed to partially restore service, but mostly managed to do so only for a subset of our users (due to DNS propagation delays and IPv6 vs IPv4 connectivity differences).
Currentely, Codeberg is available for all the situations we monitor for, and we expect that most connectivity issues will be resolved soon after all DNS caches clear.
We appreciate all the love and support we receive from you, thank you so much.
However, the sad story is, that this day was a massive disruption for most people who develop software on a serious level on Codeberg, from large Free/libre software projects to companies and freelancers, and we are sorry about this.
We acknowledge if this makes you want to move elsewhere, but we're of course happy about everyone who can stay .
Bad news: DDoS has followed to the new location.
Good news: There, we have at least basic DDoS protection.
Bad news: The server is still unreachable.
We have received first numbers. The DDoS is apparently about 11Gbit/s over UDP traffic currently.
@silverfish Well, using cloudflare would kinda mean giving up on all our ideals:
- no big corporate services, everything under our control
- privacy by default, but Cloudflare likes to decrypt traffic in the middle
- no proprietary dependencies, everything runs using free/libre software
However, we have currently used DDoS mitigation from a smaller provider that does not do man in the middle sniffing, so we only had to sacrifice partially using non-free software for a while. ~f
@Codeberg
I hope that works and that you go through this and come out stronger.
You can also look at Deflect (https://deflect.ca/). I have direct contact, they're willing to help if you ping them.
@silverfish
@zeh
Thank you for the offer, and the service sounds really interesting as an alternative to Cloudflare, especially for smaller-scale websites.
Unfortunately, having a third-party decrypt traffic to Codeberg is currently a no-go and it looks like their service mostly relies on that.
However, we are receiving some help setting up network-level DDoS protection and more is in preparation, so we're confident we'll find an alternative soon.
@silverfish