frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

$82K GCP bill in 48 hours – so I built an automatic API key kill switch

https://cloudsentinel.dev
1•daudmalik06•2h ago

Comments

daudmalik06•2h ago
Original incident: https://www.reddit.com/r/googlecloud/s/3S1KWpWRZm

After reading about a 3-person startup that received an $82,000 Gemini API bill in 48 hours (normal monthly spend: $180), I started building CloudSentinel.

The core problem: GCP has no native kill switch. Budget alerts send an email. Quota limits throttle requests. Neither revokes a key automatically. And billing data is delayed by hours — useless for real-time protection.

The architecture:

CloudSentinel monitors raw API request count — updated in near real-time. We create an Alerting Policy inside the user's own GCP project using MQL. When the request threshold is crossed, Google fires a Pub/Sub webhook to CloudSentinel. We receive it and revoke that exact key automatically.

The security decision I'm most proud of:

Revoke-Only IAM model. The Custom IAM Role has three responsibilities: - Read API key IDs and metadata (never key values) - Create monitoring rules inside the user's project - Revoke a specific key when a threshold is crossed

The permission apikeys.create is not in the role. Not restricted — absent. Even if CloudSentinel is fully compromised, an attacker can only remove access, never create keys or touch anything else.

Early access open at https://cloudsentinel.dev

Have you ever dealt with a GCP billing surprise or a leaked key? Happy to hear your experience and discuss the architecture.

Surpassing vLLM with a Generated Inference Stack

https://infinity.inc/case-studies/qwen3-optimization
1•lukebechtel•1m ago•0 comments

MorphMind – steerable AI specialist teams you can guide

https://agentlab.morphmind.ai
1•jay_morphmind•1m ago•1 comments

White supremacist social media grips teens plotting attacks in Southeast Asia

https://www.reuters.com/business/media-telecom/white-supremacist-content-grips-teens-plotting-att...
1•alephnerd•2m ago•0 comments

The first multi-behaviour brain upload

https://theinnermostloop.substack.com/p/the-first-multi-behavior-brain-upload
1•dtj1123•3m ago•0 comments

Emacs and Vim in the Age of AI

https://batsov.com/articles/2026/03/09/emacs-and-vim-in-the-age-of-ai/
1•eduction•4m ago•0 comments

Launch HN: Didit (YC W26) – Stripe for Identity Verification

4•rosasalberto•6m ago•0 comments

Parameter Variation for Powder-Bed Arc Additive Manufacturing

https://www.mdpi.com/2075-4701/16/3/259
1•PaulHoule•7m ago•0 comments

Tools I found that make using Claude Code easier on your phone

https://zilliz.com/blog/3-easiest-ways-to-use-claude-code-on-your-mobile-phone
1•Fendy•7m ago•0 comments

Show HN: Svglib a SVG parser and renderer for Windows

https://github.com/bibhas2/svglib
1•leopoldj•9m ago•0 comments

The ugly history of regime change

https://www.profgmedia.com/p/this-time-is-different
2•shimm723•11m ago•0 comments

What software knowledge will stay relevant?

https://www.natemeyvis.com/what-software-knowledge-will-stay-relevant/
1•speckx•12m ago•0 comments

Show HN: Base Layer – Open-source behavioral compression from any text

https://www.base-layer.ai/
1•agulaya24•12m ago•0 comments

Para-biathlete wins silver using ChatGPT as his coach

https://www.theguardian.com/sport/2026/mar/09/ukraine-winter-paralympics-chat-gpt-artificial-inte...
1•defly•12m ago•0 comments

Amazon is holding a mandatory meeting about AI breaking its systems

https://twitter.com/lukolejnik/status/2031257644724342957
3•lwhsiao•12m ago•0 comments

Show HN: Claude Tuner – Monitor your Claude usage and find the right plan

https://claudetuner.com
1•xlos21•14m ago•1 comments

CragCLI – a new calculator for the command line

https://cragcli.info
3•librasteve•14m ago•2 comments

Show HN: Jottit – Reviving the Original from 2007

https://jottit.org
1•simonbc•15m ago•0 comments

Stripe: Billing for LLM Tokens

https://docs.stripe.com/billing/token-billing
1•tosh•15m ago•0 comments

Unlocked SaaS, file source as truth?

1•abmmgb•15m ago•1 comments

Understanding OBD2 codes (past, present, future)

https://crewchief.cc/blog/understanding-obd2-codes
1•meandave•15m ago•0 comments

Ask HN: What Happened to Llama Models?

1•elpakal•16m ago•0 comments

Meta to Acquire Moltbook

https://www.bloomberg.com/news/articles/2026-03-10/meta-to-acquire-moltbook-viral-social-network-...
2•marc__1•16m ago•0 comments

Disorder Drives One of Nature's Most Complex Machines

https://www.quantamagazine.org/disorder-drives-one-of-natures-most-complex-machines-20260309/
2•Brajeshwar•20m ago•0 comments

Spacecraft's impact changed asteroid's orbit in a save-the-Earth test

https://apnews.com/article/asteroid-nasa-draft-dimorphos-9abccd32d4cb532a66249dd6145685cb
2•Brajeshwar•20m ago•0 comments

Volkswagen to cut 50k jobs as profits drop

https://www.bbc.com/news/articles/c4gqyyly9v8o
1•gehwartzen•20m ago•0 comments

Microsoft 365 confirms new premium tier, stuffed with AI and few discounts

https://www.theregister.com/2026/03/09/microsoft_adds_a_premium_tier/
2•Brajeshwar•20m ago•0 comments

Smol AI WorldCup: What Small LLMs Can Do

https://huggingface.co/blog/FINAL-Bench/smol-worldcup
3•seawolf2357•21m ago•0 comments

Debian decides not to decide on AI-generated contributions

https://lwn.net/SubscriberLink/1061544/125f911834966dd0/
18•jwilk•21m ago•5 comments

License Laundering and the Death of Clean Room (The Chardet Saga)

https://shiftmag.dev/license-laundering-and-the-death-of-clean-room-8528/
1•allixsenos•21m ago•0 comments

We are building data breach machines and nobody cares

https://idealloc.me/posts/we-are-building-data-breach-machines-and-nobody-cares/
2•idealloc_haris•23m ago•1 comments