Put the spending ceiling into AI-generated code
Prasenjit Sarkar (@stretchcloud) uses the Durable Objects alarm loop to argue that alarms bill without traffic, that a single console cap cannot cover multi-vendor agent work, and that generated code needs execution quotas, idempotency checks and a kill switch.
- Products
- Durable ObjectsWorkers
- Source
- Author experience𝕏
- Author
- Prasenjit Sarkar (@stretchcloud)
Key points
- The author notes that Durable Objects alarms run outside the request path, so a loop keeps billing with zero traffic and no users watching.
- He writes that agents can reschedule, retry and reprocess the same context faster than a human reviews a bill, and that at the time of his post Cloudflare had nothing comparable to other vendors’ spend limits for Durable Objects specifically.
- His view is that a cap in one cloud console cannot cover agent work routed across several vendors; the ceiling has to be in the generated code: execution quotas, idempotency checks and a kill switch that does not rely on someone reading a dashboard.
- He recommends reviewing AI-written infrastructure code for its worst financial outcome, not just whether tests pass.
Original sources
Original source · Published
Read on 𝕏Prasenjit Sarkar
@stretchcloud · Original 𝕏 post
A Durable Objects alarm looped quietly for 23 days before it turned into a $10,811.41 bill. No breach, no bad actor, just a handler that kept rescheduling itself every time it succeeded, reading and writing Cloudflare's storage layer trillions of times before anyone noticed the…
More to read
Four layers of cost protection for small Cloudflare projects
David Z (@davezfr) writes an X article for vibe coders on budget alerts, stop conditions for paid paths, automatic pausing, and letting a personal agent verify and pause.
shmily7: a Durable Object alarm loop and a reported US$10,811.41 bill.
@shmily7 reports a Durable Object alarm loop in an unused test project, then says he paid the full US$10,811.41 bill to avoid service suspension. Cloudflare’s Ashley Peacock publicly says he is looking into it internally and will follow up. Cloudflare’s Dane Knecht later replies that he escalated it too. On October 9 the author declares the case closed: he reports that, with Ashley Peacock’s help, Cloudflare decided to refund the charges incurred during the bug in full, with the money still to arrive, and posts the support ticket reply he received.
A budget alert is a horn, not a brake
@GUYUE_LGY points to Cloudflare’s Budget alerts documentation: alerts send email when spend crosses a threshold but do not pause or cap usage. Before letting AI run unattended, the author checks what actually happens at the line.