What do you do when even your rate limiting layer gets fully saturated with requests? Does one have any options other than involving CF?
I thankfully never was in the postion to experience this but I always wondered how far let's say nftable rules go in thwarting a DoS attack against a conventional webapp on a tiny VPS.