What if the situation is the provider doesn't have built-in DDos protection ?
If it is an unimportant service you just suffer the DDoS or switch IPs.
Or you use a front end on a VPS that does have DDoS and use a IPv6 tunnel or tail scale to connect to your actual service.