My co-founder and I launched Orbiter a little over two weeks ago, and the response so far has been fantastic. It's the best traction either of us have seen this early for a project. We've made a conscious effort to focus more on marketing than engineering since the launch, but of course problems come up.
Our most recent problem came in the form of bots looking for WordPress vulnerabilities. Orbiter is hosting for static websites, not WordPress sites, but that doesn't stop the script kiddies. Every couple of hours, we started getting blasted by requests for routes and paths that would never exist on our customers' sites. This resulted in another problem—one of our vendors rate-limiting us.
As we looked into the traffic, the rate limit didn't make sense. Yes, we were seeing a spike from bots, but combined with our early customer traffic, the volume was still not high enough to trigger rate limits. Still, we wanted to solve the bot problem as best we could. So, we set up firewall settings and added some safeguards in our code to reject requests that were clearly targeting WordPress sites.
But the second part of the problem was more concerning. Fortunately, we worked with our vendor partner and they discovered that their rate limiting rule didn't account for the shared IP address ranges that come along with some cloud providers. So our requests were being counted along with other requests that use the same cloud provider and had happened to be assigned the same IP address. This meant it wasn't our requests triggering rate limiting, it was the combination of requests from our product and countless others that ended up triggering rate limiting. The vendor fixed this problem quickly, thankfully.
Now, it's back to marketing and getting as many eyes on Orbiter as we can. If you're an indie hacker than needs to host a static website or web app, give us a try!