DDoS is a capacity contest. If the public IP is the origin, you brought a VM to a network fight. If the public IP is Cloud CDN, the fight happens on 200+ Tbps with the origin off to the side.
Volumetric versus application
L3-L4 floods fill pipes. L7 floods fill workers with expensive requests. The edge should take both. Origin Shield and cache also mean many L7 GETs never become origin GETs.
Hide then restrict
Cut over DNS, then firewall origin to pull paths only. An uncovered origin IP is a second public hostname you forgot.
DNS is a separate flood
Authoritative Cloud DNS is DDoS-protected Anycast. Host the zone there if the name itself is the target.
Practice before you need the phone
Know the emergency page and the number. An active incident is a poor time to create a distribution from scratch.
