← All posts

Set Your Billing Alerts Before You Need Them

An open combination padlock resting on a laptop keyboard

Someone pushes code to a public repo. A bot finds the cloud key in under a minute. They wake up to a bill with four digits on it.

The scary part is not the amount. It is the timeline. Scanners hit new public commits in seconds. You can lose a month of sleep to something that took ten seconds to exploit.

The fix takes an afternoon. Most people do it after the bill.

Billing alerts, today

Highest-value hour you will spend on your infrastructure. Every provider has it. Almost nobody sets it up on day one.

Use a hard cap if offered. Some services stop spending at a limit instead of just emailing you. An alert you sleep through is not protection.

Set three thresholds. Normal, double normal, and something is very wrong. The gap tells you whether it is growth or an attack.

Send them where you actually look. Your phone, or a Discord webhook. A billing email in a weekly inbox is decoration.

Do this for every metered service. Hosting, AI APIs, email, SMS.

Keys are passwords

Most leaks are boring mistakes repeated forever.

  • Never commit them. .env in .gitignore before your first line of code.
  • Git history is forever. Deleting the line does not unleak it. Rotate the key.
  • Scope everything down. Read-only where possible, IP-restricted where offered. A leaked read-only key is an incident. A leaked admin key is a catastrophe.
  • Separate dev and production. Your dev key ends up in more places than you can track.
  • Rotate on any doubt. Screenshot, chat paste, unsure if that repo was private? Rotate. Keys are free.

Locking down a VPS

A fresh droplet gets scanned within minutes. That is just background noise on the internet now.

SSH keys only. Set PasswordAuthentication no. This alone stops the overwhelming majority of automated attacks.

No root login. Normal user with sudo.

Firewall deny by default. Usually 22, 80, 443. Nothing else.

Automatic security updates. Unpatched software causes more real breaches than clever zero-days.

Never expose a database. Bind to localhost, tunnel over SSH. Every week someone finds another wide-open Mongo instance full of real user records.

Watch for the weird stuff

Prevention fails sometimes. Noticing fast is the backup.

Alert on shapes, not just totals: usage from countries you do not operate in, spend spiking at 4am, one key suddenly busy, resources you did not create.

That last one matters most. Crypto miners are the usual endgame for a stolen cloud key. They spin up the biggest instances available in regions you never touch.

If it happens anyway

  1. Revoke the key. Now, not after. Break your own app if you have to.
  2. Kill resources you did not create.
  3. Read the audit log. Find out what was accessed.
  4. Call your provider. They often forgive fraudulent charges, especially reported quickly. Be honest.
  5. Rotate everything nearby. If one key in that .env leaked, assume they all did.

Then find the hole. A leak you patch but do not understand comes back.

Takeaways

  • Billing alerts and hard caps on every metered service, before you need them.
  • Keys are passwords: never committed, always scoped, separate per environment.
  • SSH keys only, deny by default, and never a publicly reachable database.

Open your cloud console and check whether a budget alert exists. If not, that is your next fifteen minutes.