DDoS is a capacity contest. If the public IP is the origin, you brought a VM to a network fight. If the public IP is Cloud CDN, the fight happens on 200+ Tbps with the origin off to the side.

Volumetric versus application

L3-L4 floods fill pipes. L7 floods fill workers with expensive requests. The edge should take both. Origin Shield and cache also mean many L7 GETs never become origin GETs.

Hide then restrict

Cut over DNS, then firewall origin to pull paths only. An uncovered origin IP is a second public hostname you forgot.

DNS is a separate flood

Authoritative Cloud DNS is DDoS-protected Anycast. Host the zone there if the name itself is the target.

Practice before you need the phone

Know the emergency page and the number. An active incident is a poor time to create a distribution from scratch.