So apparently if someone knows / guesses the name of your S3 bucket - even if it's private (!) - they can just bankrupt you by sending infinite PUT requests and there is nothing you can do about it.
> requests get rejected
> but AWS still counts it as a write operation against your account for which you have to pay at a rate of $0.005 per 1000 requests
This seems insane to me. Especially because a lot of services rely on presigned URLs for uploads / downloads which exposes your bucket name to the client. In this case the author got their bill waved, but AWS support made it clear it's an exception not the rule.
Congrats to @nestframework, @SpaceVim, @edgedatabase, @vite_js, & more for shipping major version updates in July ๐
Read about their projects & updates:
https://t.co/qaOV28iJFB
Planning on a release this August? Submit your project to be featured: https://t.co/DrBEZXbUoQ