deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Developer pays $10,811 Cloudflare bill after looping Durable Object alarm

A vibe-coded Durable Object alarm that kept rescheduling itself generated about 6 trillion reads and writes, leaving a $10,811.41 Cloudflare bill that the author paid in full after support offered no relief.

Developer pays $10,811 Cloudflare bill after looping Durable Object alarm

A developer is out $10,811.41 after a Cloudflare Durable Object alarm became trapped in an infinite loop, churning through roughly six trillion reads and writes before the invoice landed. The author documented the incident on Serverless Horrors, a site that collects serverless failure stories, and the post reached the front page of Hacker News on October 8.

What happened

According to the post, the runaway alarm lived in a single project and was, by the author's own admission, a product of "vibe coding": AI-assisted code shipped without the review it needed. Durable Object alarms are designed to fire at a scheduled time, do a unit of work and stop. In this case the handler kept rescheduling itself, so it never stopped firing.

Because the account had no hard spending ceiling (the author notes Cloudflare does not offer one), nothing halted the meter while the loop ran. The result was a bill for $10,811.41, which the author paid in full and described as "the second most expensive lesson of my life."

Why one alarm scales so badly

For readers unfamiliar with the platform: Durable Objects are Cloudflare's stateful compute primitive, a single instance with its own storage, and alarms are the built-in scheduler that lets an object wake itself at a future time. The pattern is convenient for cleanups, retries and session timeouts. The catch is that an alarm handler which unconditionally sets its next alarm is effectively a perpetual loop running on infrastructure billed per operation.

On a laptop, that bug wastes some CPU cycles. On a metered global network, it produced on the order of six trillion reads and writes before anyone saw an invoice. The author's follow-up notes the loop was confined to one project, but the project boundary put no limit on the billing.

A support loop of its own

The aftermath was similarly circular. According to the author, the support ticket asking for a reduction drew only automated bot replies, repeatedly. Contacting Cloudflare staff on X and other channels produced an offer to "take a look" and, per the author, nothing beyond that. No refund or credit materialised, so the full amount was paid.

The author's stated conclusion is to move every project off Cloudflare onto a self-hosted VPS, trading the platform's elasticity for infrastructure whose cost cannot silently compound.

Why it matters

The story works as a warning on three levels.

Spending controls: on fixed infrastructure a runaway loop burns CPU; on serverless it burns money on every iteration, and if a platform has no hard cap, the only ceiling is how long the bug survives. Anyone running metered infrastructure should establish exactly what, if anything, stops charges from accruing before shipping code that schedules itself.

Vibe coding: cheap code generation makes it easy to deploy logic no human has read. In most systems that yields ordinary bugs; under per-operation billing, a logic error becomes a financial event. Scheduled code in particular deserves a manual reading of its termination conditions.

Support expectations: the author reports finding no relief through any channel, and the decision to leave the platform followed directly from that experience. Beyond the engineering lessons, the episode is a reminder that the true cost of a bad loop is not limited to the invoice. It can extend to trust in the platform itself.

  • #cloudflare
  • #serverless
  • #durable-objects
  • #vibe-coding
  • #billing

Related posts