aliteq.

Your vibe-coded app went down and nobody told you: the 5 boring reasons

Expired certificates, free-plan limits, paused databases, too many connections and no backup. None are glamorous, all are in the vendors' own docs, and one gave our own site error pages for days.

SyntaxUpdated 5d ago8 min readWeb story
Photo of a power cord running from a wall outlet across a dark floor, with a single amber night-light glowing in the background
Share

I build with AI tools the same way you do. The apps I ship are not usually broken by hackers. They are broken by a number I never looked up. This page lists the five numbers, what each failure looks like from the outside, and the one check that catches it. If you want the security side, that is a different list: the 6 security checks. This one is about staying up.

Table of six boring failures: expired TLS certificate (90-day Let's Encrypt certificates, no warning email since June 2025), Workers Free CPU cap of 10 milliseconds, 128 megabyte memory cap, 60 Supabase database connections, Supabase free projects paused after 7 days of low activity, and no downloadable backup on the free plan.
Six limits, where each one lives, and what warns you. · aliteq research

1. The TLS certificate that quietly expires

Short answer: A TLS certificate is the file that lets your site load over HTTPS. Let's Encrypt certificates last 90 days. If renewal fails and nobody is told, browsers show a full-page "Not secure" warning and visitors leave.

Most hosts renew certificates for you, so this feels like someone else's job. It becomes yours when you bring your own domain, run your own server, or the renewal job breaks without noise. Let's Encrypt says its default certificates are valid for 90 days and recommends renewing every 60. Until 4 June 2025 it also emailed you before expiry. It ended that service, and its own announcement points to third-party monitors instead, naming one that is free for up to 250 certificates.

Certificates are also getting shorter. Per Let's Encrypt's published schedule, the default moves to 64 days on 10 February 2027 and to 45 days on 16 February 2028. A shorter life means a broken renewal hurts sooner. Their blog says a hardcoded 60-day renewal "will no longer be sufficient" and recommends renewing about two thirds of the way through. That is day 60 for 90 days, about day 43 for 64 and day 30 for 45 (our arithmetic).

Bar charts of Let's Encrypt default certificate lifetime: 90 days today, 64 days from 10 February 2027, 45 days from 16 February 2028, and 6 days for the opt-in short-lived profile. A second chart shows renewing about two thirds through: day 60, day 43 and day 30.
Let's Encrypt's published schedule, and the renewal point it recommends. · aliteq research
  • What it looks like: a browser warning on your own domain, while the app itself is fine.
  • The check: ask your AI tool, "Who renews my certificate, and what tells me if that fails?" Then add an expiry alert from any monitor that checks certificates.
  • The quote that matters: Let's Encrypt recommends "sufficient monitoring in place to alert appropriately if certificates aren't renewed when expected."

2. The free plan runs out of CPU, memory or requests

Short answer: Free hosting plans cap how much work one request may do. On Cloudflare Workers Free that is 10 ms of CPU and 128 MB of memory, plus 100,000 requests a day. Go over and your visitor sees an error page, not a slow page.

Cloudflare's limits page lists the Free plan at 100,000 requests a day, 10 ms of CPU time per request and 128 MB of memory. Waiting on a database or an outside API does not count as CPU. Heavy work does. Cloudflare says an average Worker uses about 2.2 ms per request, while pages that render on the server or parse big payloads often use 10 to 20 ms. Break the CPU or memory limit and the visitor gets Error 1102, "Worker exceeded resource limits". Break the daily request limit and they get Error 1027.

This is not theory for me. aliteq.com is vibe-coded and runs on Workers, and it hit these limits twice.

  • 19 July 2026: our homepage loaded the full text of about 40 articles to draw a list of cards. That blew past the 128 MB memory limit and the site threw Error 1102. The fix was to fetch only the columns a card needs.
  • 22 to 25 September 2026: on the Free plan our Worker returned 20,662 exceeded-resources errors in seven days. Our busiest day, 22 September, was 101,033 requests, right at the 100,000 ceiling. Those errors showed up as 503s on our main pages, and verified Googlebot received 657 of them in one week. We found it by reading the Workers analytics, not because anything alerted us.
  • 27 September 2026: we upgraded to Workers Paid, $5 a month. The errors went from 60 to 78 per 15 minutes to zero right after.
Three numbers from aliteq's Workers analytics on the Free plan: 20,662 exceeded-resources errors in 7 days, 101,033 requests on 22 September, and 657 verified Googlebot 503s in a week. Timeline: Error 1102 on 19 July, 503s on 22 to 25 September, upgrade to Workers Paid on 27 September.
Our own numbers from Cloudflare Workers analytics, September 2026. · aliteq research

The lesson is not "pay for hosting". It is that a free plan has a ceiling, and the ceiling arrives on the day you get attention. On Workers Paid, Cloudflare's docs say the default CPU limit is 30 seconds per request, configurable up to 5 minutes, and there is no daily request cap. Memory stays at 128 MB on both plans.

  • What it looks like: random error pages on your busiest or heaviest routes, while a quiet page works.
  • The check: find the "errors" or "invocation statuses" view in your host's dashboard and look at it once a week. Ask your AI tool, "Which of my pages loads the most data into memory?"
  • Related: the cost side of this is in what hosting actually costs.

3. The free database that goes to sleep

Short answer: Supabase pauses Free Plan projects that show low activity over a 7-day period. Your app then cannot reach its data until you resume it. Paid projects are not paused.

This one fits a pattern with vibe-coded side projects: you build it, share it, then get busy. Supabase's docs say a Free project is considered inactive if it does not get enough user database activity over the past week, and that a few user requests a day is typically enough to avoid a pause. It sends a warning email about a week before and another when the pause happens. A paused project can be restored from the dashboard for up to a year after pausing (the docs said 90 days until recently; they say one year as of 4 October 2026). The docs also say Pro and higher plans are not paused for inactivity.

The email is the only warning, and it goes to the project owner. If that is an address you never read, the first sign is your app showing empty pages or errors.

  • What it looks like: a working app that suddenly cannot load any data.
  • The check: open the project's owner email once and make sure Supabase's pausing warning would reach you. If the app matters, the docs' own fix is the Pro Plan.
  • Related: what a database is and what Supabase is, if those words are new.

4. The database runs out of connections

Short answer: Every database allows only so many open connections at once. Supabase's smallest compute sizes (Nano on Free, Micro on paid plans) list 60 direct database connections and 200 pooler clients. Past the limit, new requests fail at peak.

A connection is an open line between your app and the database. A busy app, or one that opens a fresh line on every request, can use them all up. Supabase's compute docs list 60 maximum database connections and 200 pooler clients for both Nano and Micro, and say these are recommended values you can change. Its connection guide says a serverless or edge function should use the shared pooler in transaction mode, because those environments "open many short-lived connections". A long-running server can connect directly.

So the right connection string depends on where your code runs. AI tools often paste in the first one they find. That works in testing with one user and fails with fifty.

  • What it looks like: the app is fine on a quiet afternoon and throws database errors when a post gets shared.
  • The check: ask your AI tool, "Does my backend run as a long-lived server or as serverless functions, and which Supabase connection string is it using?" Match it to Supabase's connection guide.
  • Related: the slow-query cousin of this problem is in why a Lovable app gets slow after adding data.

5. The backup that was never there

Short answer: On Supabase, daily backups are for paid plans: 7 days on Pro, 14 on Team. Free projects should export their own data. A backup that does not exist cannot fail visibly, so nobody notices until the day you need it.

Supabase's backup docs say Pro Plan projects can access the last 7 days of daily backups, Team 14 and Enterprise up to 30. For Free projects they recommend regular exports with the CLI db dump command and off-site copies, and the production checklist says backups are not available for download on Free. Two more details matter. Backups do not include files you stored through the Storage API, only the metadata. And deleting a project permanently removes its data and all backups.

That last one is the scary combination for a vibe coder: an AI agent with the right permissions, a request to "clean up the old project", and no copy anywhere else.

  • What it looks like: nothing, until data is gone. Then it is final.
  • The check: write down where a copy of your data lives other than the project itself. If the answer is "nowhere", run an export today and put it somewhere that is not the same account.
  • The test that counts: a backup you have never restored is a guess. Restore it once into a scratch project.

The one alert to set today

You do not need a monitoring stack. You need to find out before your visitors do. Here are the smallest useful versions of each check.

Add an expiry alert for your domain. Let's Encrypt no longer emails you.

Look at your host's errors page. Error 1102 on Cloudflare means a CPU or memory limit.

On Supabase Free, make sure the 7-day pause warning email reaches a real inbox.

Serverless functions use the pooler in transaction mode. Servers can connect directly.

Export the database and storage files, then restore once into a scratch project.

If you only do one, set the uptime alert. An external checker that loads your homepage and emails you when it fails will catch an expired certificate, a free-plan error page and a paused database, because all three break the page. Let's Encrypt lists certificate monitors on its Monitoring Service Options page, which is a place to start. We have not tested any of them. For the rest of the path from a working app to a live one, read how to ship a vibe-coded app.

Quick answers

Why did my vibe-coded app show "Not secure" when nothing changed?
Most likely the TLS certificate expired or failed to renew. Let's Encrypt certificates last 90 days and the service stopped sending expiry emails on 4 June 2025, so a broken renewal can go unnoticed until browsers warn visitors.
What is Cloudflare Error 1102?
It means a Worker exceeded its resource limits. Cloudflare uses the same code for exceeding the CPU time limit and the memory limit. On the Free plan the CPU limit is 10 ms per request and memory is 128 MB per isolate.
Will my Supabase free project be deleted if it pauses?
No, it is paused, not deleted. Supabase's docs say you can restore a paused project from the dashboard for up to one year after it was paused. Paid projects are not paused for inactivity.
How many database connections can I use on Supabase?
On Nano (Free) and Micro compute, the docs list 60 maximum database connections and 200 pooler clients. These are recommended values you can change, and serverless code should use the pooler in transaction mode.
Do I need backups if I am on the free plan?
Yes. Supabase says Free projects should export their own data and keep off-site copies, because daily backups are a paid feature. Storage files are not included in database backups either.
Is upgrading to a paid plan the fix?
It removes some limits, such as Supabase pausing and the Workers daily request cap, and it did stop our errors. It does not renew certificates, check your connections or make a restorable backup for you.

Found this useful? Share it

Share
Syntax

Build Editor

Syntax

I explain what's actually happening when you build software by talking to an AI — what the model is doing, what's really running your app, and where the sharp edges are. No jargon without a picture, no hype, and an honest 'hire someone' when that's the answer.

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading