Skip to main content

Vercel Made Blocked Traffic Free — Here's What That Costs to Build Yourself

10 min readDora NodaDora Noda
Share
On this page

On May 18, 2026, Vercel published a three-paragraph changelog entry that quietly ended one of the nastiest billing failure modes in serverless hosting: paying for traffic your own firewall already rejected. From that day on, any request the Vercel Web Application Firewall denies, challenges, or rate-limits costs the project owner nothing — no CDN request charge, no data-transfer charge, no configuration required.

If you self-host on machines you own, this is the rare hosted-platform giveaway you should study rather than dismiss. Vercel just set the price of "absorb hostile traffic without billing the victim" to zero, and your platform now has to match that expectation. This post is the honest accounting: what the waiver actually covers, what each layer of the bundle costs to rebuild yourself, and the checklist a self-hosted PaaS control plane needs to ship before "own your infrastructure" is a fair trade.

The accounting, up front​

Here is the whole comparison in one table. Each row is a layer of the protection bundle; the middle column is what Vercel charges, and the right column is what it costs a Cluster-API-managed fleet on owned hardware to provide the equivalent.

LayerVercel (all plans, incl. Hobby)Self-hosted equivalent
Volumetric L3/L4 absorption$0, automatic, unlimitedHetzner/Arbor baseline free; true absorption requires an edge network (see below)
L7 WAF rules (deny/challenge)$0 (custom rules free; ~3 on Hobby, 40 on Pro)Cloudflare Free: $0 (limited managed ruleset + 5 custom rules); DIY Coraza/ModSecurity: $0 in licenses, hours in tuning
Rate limitingPlan-gated (paid tiers)Cloudflare Free: 1 rule, $0; Gateway API BackendTrafficPolicy: $0 + controller ops
Bot managementAttack Challenge Mode included; managed Bot Protection on paid tiersCloudflare Turnstile + Bot Fight Mode: $0
Bandwidth for blocked traffic$0 since May 18, 2026Origin bandwidth you never serve is free by construction — but only if you block at the edge, not at origin

Two things jump out. First, the self-hosted column has a lot of zeros too — this is a winnable comparison. Second, every zero on the right has an asterisk: either someone else's edge network or your own engineering time. The rest of this post prices those asterisks.

What the waiver actually covers (and what it doesn't)​

Precision matters here, because the generous headline hides real boundaries. The May 18 changelog waives exactly two billable metrics — CDN Requests and Fast Data Transfer — and only for traffic the WAF itself denied, challenged, or rate-limited. That is the new part. Keep it distinct from the old part: unlimited DDoS mitigation has always been free on every plan, including Hobby, and this change doesn't alter that.

What still bills you on Vercel after the waiver? Anything served before mitigation kicked in, or never classified as an attack. If a scraper's requests pass your WAF rules and hit a serverless function that queries your database, you pay for the function duration and the transfer as before — the waiver covers blocked traffic, not merely unwanted traffic. And the WAF features that do the classifying remain plan-gated: per the usage and pricing docs, DDoS mitigation, IP blocking, and custom rules are free everywhere, while rate limiting and managed rulesets are paid-tier features.

So the honest statement of Vercel's bundle is: free detection and absorption of obvious attacks on every plan, free custom deny-rules with tight limits on Hobby (~3 rules, with 100 GB of transfer and 1M CDN requests included), and the full managed-ruleset plus WAF-rate-limiting toolkit behind Pro at $20 per seat per month. The waiver removes the tail risk — the surprise bill — not the reason to configure rules in the first place.

Why the waiver exists: denial-of-wallet is the threat model​

The changelog names the three motivating abuse cases plainly: a scraper hammering product pages, a credential-stuffing botnet hitting a login route, a bot abusing an expensive endpoint. All three share a shape that metered serverless pricing turns toxic — the attacker spends nearly nothing per request while the victim pays per request served. Security researchers have called this denial-of-wallet since at least 2021, when a much-cited paper estimated a modest 1,000-node botnet could land a serverless app with a $40k/month bill.

The background traffic environment has only gotten louder. Cloudflare's Q4 2025 threat report documents a record 31.4 Tbps DDoS attack from the Aisuru-Kimwolf botnet — 35 seconds long, peaking near 200 million requests per second, mitigated automatically — and notes hyper-volumetric HTTP attacks surging through late 2025, with DDoS incidents more than doubling year over year. Vercel is not alone in responding with billing policy either: AWS set the precedent in November 2024 when CloudFront stopped charging for requests blocked by AWS WAF. "Don't bill the victim for the attack" is becoming the industry norm, and any platform that meters traffic will be judged against it — including yours.

Rebuilding the bundle, layer by layer​

Start at the bottom of the stack. An owned Hetzner dedicated server already ships with automatic, free network-level DDoS protection, plus a stateless firewall at the switch port — genuinely useful against garden-variety volumetric floods, and it costs nothing beyond the server itself.

Its ceiling is the honest part: provider-level scrubbing handles small-to-medium floods and then degrades toward null-routing your address when the water gets too deep. That is not a criticism of Hetzner specifically; no single-homed box absorbs terabit-scale attacks. It is physics, and it is why the top row of the accounting table says "requires an edge network."

The L7 layer is where the build-vs-rent decision actually lives. Option one is Cloudflare in front of your origin: the free tier is remarkably complete for this purpose — unmetered DDoS mitigation, a limited managed ruleset plus five custom WAF rules, one rate-limiting rule, Bot Fight Mode, and Turnstile/Managed Challenge, all at $0 with no per-request WAF fee and no egress charge on proxied traffic. The step up to Pro ($20/month per zone annually) buys the full Cloudflare plus OWASP managed rulesets and a second rate-limit rule. For most small fleets, this single decision replicates 90% of Vercel's bundle in an afternoon of DNS and rule work.

Option two is DIY at your own ingress: Coraza (the modern, Go-native ModSecurity successor, embeddable as an Envoy WASM filter) or classic ModSecurity for WAF semantics, fail2ban for brute-force IP banning, and rate limiting expressed natively in the Gateway API layer. That last one deserves a concrete example, because it is the piece a PaaS control plane can generate per tenant at deploy time. With Envoy Gateway, a per-route limit is a BackendTrafficPolicy your controller can template:

yaml
apiVersion: gateway.envoyproxy.io/v1alpha1
kind: BackendTrafficPolicy
metadata:
  name: tenant-login-rate-limit
  namespace: tenants
spec:
  targetRefs:
    - group: gateway.networking.k8s.io
      kind: HTTPRoute
      name: tenant-login-route
  rateLimit:
    type: Global
    global:
      rules:
        - clientSelectors:
            - headers:
                - name: x-tenant-id
                  value: acme
          limit:
            requests: 100
            unit: Minute

The licenses are $0. The price is engineering time: writing the controller that emits these policies per deploy, tuning WAF rules against false positives on real tenant traffic, running the global rate-limit backend (usually Redis), and being on call when a rule misfires. Budget days to stand up and a steady drip of tuning forever — that drip is the number most "self-hosting is free" math forgets.

The layer you cannot self-host​

Strip away the tooling discussion and one asymmetry remains: volumetric absorption at internet scale is not a software feature, it is a capacity business. Cloudflare, AWS, and Vercel absorb a 31.4 Tbps flood the way a seawall absorbs a wave — by being bigger than the wave. Your Hetzner rack, however well tuned its Coraza rules, is a sandcastle by comparison; when the flood exceeds your provider's scrubbing capacity, your prefix gets null-routed and every tenant on that box goes dark together.

This is why the self-hosted answer to Vercel's bundle is necessarily hybrid: own the machines, rent the edge. The pragmatic pattern is Cloudflare (or equivalent) in front of every tenant domain by default, with origin lockdown so traffic that bypasses the edge is rejected rather than served. Know the free tier's limits going in — one rate-limiting rule and a limited managed ruleset per zone means a multi-tenant platform either standardizes ruthlessly on shared rules or budgets Pro seats for tenants with complex needs. Either is fine; discovering the limit during an incident is not.

The default-shipped checklist​

The TODO this post answers demands a concrete accounting of what a self-hosted PaaS control plane must ship by default before "own your infrastructure" is a fair trade against Vercel's free bundle. Here it is, each item with its acceptance criterion:

  1. Per-deploy rate limiting at the Gateway API layer. Every tenant route ships with a generated BackendTrafficPolicy (or your controller's equivalent) from the first deploy — login and other abuse-prone routes get stricter limits by convention. Done when: a load test against a fresh tenant hits 429s before it hits origin saturation.
  2. An opt-in Cloudflare-proxy pattern for tenant domains. The control plane supports fronting any tenant domain with proxied DNS plus a baseline managed-ruleset, toggled per tenant, with documented free-vs-Pro breakpoints. Done when: enabling it is one field in the tenant spec, not a support ticket.
  3. Origin lockdown to match. Once the edge is in front, direct-to-origin traffic must fail closed — authenticated origin pulls or an allowlisted edge-IP set. Done when: curling the origin IP directly returns nothing usable.
  4. Generated baseline WAF rules per tenant. Every tenant gets deny-rules for the classics (wp-admin probes, known exploit paths, bad-bot user agents) without asking. Done when: a fresh deploy's firewall log shows blocked probes within the first hour — because the internet will probe it within the first hour.
  5. Firewall observability and alerts. Blocked/allowed/challenged request counts per tenant, visible in the platform dashboard, with anomaly alerts on sudden spikes. Done when: a tenant asks "am I under attack?" and the answer is a link, not an investigation.

None of this is exotic technology. That is precisely the point: Vercel's waiver didn't move the technology frontier, it moved the expectation frontier. The bill for hostile traffic is now $0 by default on the platform your tenants compare you against, and matching that is a checklist, not a research project.

Own the machines, rent the edge​

Self-hosting still wins the argument it has always won: your compute and bandwidth on owned hardware cost a fraction of metered serverless, with no per-seat tax and no pricing page that can change under you. Vercel's May 2026 waiver doesn't touch that math — it attacks the other flank, the part where the hosted platform quietly absorbs abuse you'd otherwise staff an on-call rotation to handle.

The fair trade is now explicit. Match the free bundle with a rented edge and a control plane that ships protection by default, and "own your infrastructure" keeps every bit of its force. Skip it, and the first credential-stuffing wave against a tenant's login page will price your missing WAF more vividly than any blog post can.

Bex.co is the open-source, AI-native Render alternative — push a git repo, get a running HTTPS service on machines you own. Star the repo on GitHub or deploy your first app today.

Related articles

Run this on infrastructure you own

bex is the open-source, AI-native Render alternative — push a git repo and get a running HTTPS service on your own machines.

Get started with bex