# Coarse ASN / cloud-provider IPv4 prefixes blocked from /api/* (datacenters). # One CIDR per line; lines starting with # ignored. Keep this list short and curated. # Add as needed; this is an extra layer, not the only defence. # AWS (sample — extend as needed) 3.0.0.0/9 13.32.0.0/15 52.0.0.0/11 54.144.0.0/12 # Google Cloud (sample) 34.64.0.0/10 35.184.0.0/13 # Azure (sample) 20.0.0.0/8 40.64.0.0/10 # OVH 51.38.0.0/16 51.83.0.0/16 # DigitalOcean 167.99.0.0/16 178.62.0.0/16 # Hetzner 116.202.0.0/16 135.181.0.0/16