独立开发者月报:涨价三倍销量、对抗爬虫与托管选型
Refactoring English: Month 20
New here?
新来的?
Hi, I’m Michael. I’m a software developer and founder of small, indie tech businesses. I’m currently working on a book called Refactoring English: Effective Writing for Software Developers.
嗨,我是迈克尔。我是一名软件开发人员,也是一家小型独立科技公司的创始人。我目前正在写一本名为《重构英语:软件开发人员的有效写作》的书。
Every month, I publish a retrospective like this one to share how things are going with my book and my professional life overall.
每个月,我都会发布这样一篇回顾文章,分享我的书和我的职业生活的进展。
Highlights
亮点
- July’s book sales tripled the already-strong sales I saw in June.
- I’m fighting the world’s dumbest scraper bot.
- I’m using AI to make a multiplayer browser game.
- 7月份的书销量是6月份已经强劲的销量的三倍。
- 我正在与世界上最愚蠢的爬虫机器人作斗争。
- 我正在使用AI制作一个多人浏览器游戏。
Goal grades
目标评分
At the start of each month, I declare what I’d like to accomplish. Here’s how I did against those goals:
在每个月开始时,我会宣布我想要完成的事情。以下是我在这些目标上的表现:
Pitch to 5 podcasts to talk about Refactoring English
向5个播客推销《重构英语》
- Result: Pitched to only one podcast
- Grade: D
- 结果:只向一个播客推销了
- 评分:D
I spent a lot of time working on a pitch to Talking Postgres, but then I realized the host has no contact information except for LinkedIn. So, I sent her a LinkedIn message but never heard back. I was a guest on The TMPDIR Podcast, though they invited me even before I pitched to them, so I can’t count that one.
我花了很多时间准备向Talking Postgres的推销,但后来我意识到主持人除了LinkedIn之外没有其他联系方式。所以,我给她发了一条LinkedIn消息,但从未收到回复。我作为嘉宾参加了TMPDIR播客,尽管他们在我推销之前就邀请了我,所以那不能算数。
Attract 30k unique readers to the Refactoring English website
吸引3万独立读者访问《重构英语》网站
- Result: The site had 23.8k unique readers
- Grade: B
- 结果:网站有2.38万独立读者
- 评分:B
I was secretly thinking of this goal as “get one post on the front page of Hacker News,” but I did and still didn’t reach 30k readers.
我暗自把这个目标视为“让一篇文章登上Hacker News首页”,但我确实做到了,却仍然没有达到3万读者。
Wrap up early access, and declare the 1.0 release of my book
结束早期访问,并宣布我的书的1.0版本发布
- Result: Still not at 1.0 release
- Grade: D
- 结果:仍未达到1.0版本
- 评分:D
I ended up spending more time than I expected responding to user feedback. My feedback app is working, but it also generates new work that’s hard to predict.
我最终花在回应用户反馈上的时间比预期的要多。我的反馈应用正在工作,但它也产生了难以预测的新工作。
Refactoring English metrics
《重构英语》指标
| Metric | June 2026 | July 2026 | Change |
|---|---|---|---|
| Unique visitors | 17,523 | 23,817 | +6,294 (+36%) |
| Revenue from pre-orders | $1,441.86 | $3,908.80 | +$2,466.94 (+171%) |
| 指标 | 2026年6月 | 2026年7月 | 变化 |
|---|---|---|---|
| 独立访客 | 17,523 | 23,817 | +6,294 (+36%) |
| 预购收入 | $1,441.86 | $3,908.80 | +$2,466.94 (+171%) |
June was the second best month of sales for my book since the Kickstarter, but then July’s sales tripled June’s.
6月是自Kickstarter以来我的书销量第二好的月份,但随后7月的销量是6月的三倍。
The main reason for the jump in sales was that I ended the early access discount. I announced on July 13th that early access pricing would end on July 20th, so the price would increase from $30 to $49.
销售激增的主要原因是结束了早期访问折扣。我在7月13日宣布,早期访问定价将于7月20日结束,因此价格将从30美元涨到49美元。
On the last day of the sale, I published a blog post called “Why I Stopped ‘Creating Content,’”, which reached the front page of Hacker News. And then it was the top post of the day on bubbles.town, a Hacker News-style site that’s more indie and less tech-centric.
在促销的最后一天,我发布了一篇题为“为什么我停止‘创作内容’”的博客文章,该文章登上了Hacker News的头版。随后,它成为了bubbles.town当天的热门帖子,这是一个类似Hacker News但更独立、更少科技导向的网站。
There was a huge spike in sales on the last day of the sale, with over $1k in sales on that day alone.
在促销的最后一天,销售额出现了巨大峰值,仅当天就超过了1000美元。
When I bumped the price to $49, sales quickly plummeted, which I expected. I plan to experiment more with pricing after I get to the book’s official 1.0 release.
当我将价格提高到49美元时,销售额迅速下降,这在我的预料之中。我计划在书籍正式发布1.0版本后,进一步试验定价策略。
I’m fighting the world’s dumbest scraper bot
我在与世界上最愚蠢的爬虫机器人作斗争
I published my blog post on Monday and got a big jump in visitors. Then, Tuesday, there was another huge surge:
我在周一发布了博客文章,访客数量大幅增加。然后,周二又出现了另一波巨大的激增:
I saw the big jump in visitors and thought some popular blogger linked to me, and then I realized it had to be bots.
我看到访客数量大幅增加,以为是有热门博主链接到了我的网站,但随后我意识到这一定是机器人。
All the visitors were going to the Hacker News Popularity Contest. It’s happened before where a blogger talks about their rank in the contest and links to my tool, and I see a big jump in visitors, but never like this, and never such a sustained wave of visitors.
所有访客都涌向了Hacker News人气竞赛页面。以前也发生过博主谈论他们在竞赛中的排名并链接到我的工具的情况,导致访客数量大幅增加,但从未像这次这样,也从未有过如此持续的访客浪潮。
When I saw the second spike, I thought, “Wow, I’m on a roll this week!” I was telling my wife about it when I had a startling realization:
当我看到第二次激增时,我想:“哇,我这周真是顺风顺水!”我正告诉妻子这件事,突然有了一个惊人的发现:
I got another fifty thousand visitors today! I’m not even sure where they’re coming from. My guess is someone tweeted it.
我今天又增加了五万访客!我甚至不确定他们来自哪里。我猜是有人在推特上提到了它。
Hmm, actually, if someone tweeted it, I’d see Twitter as the referrer.
嗯,实际上,如果有人发了推特,我应该会看到Twitter作为引荐来源。
Oh… It’s bots.
哦……是机器人。
And I checked the logs and saw that all of the requests had the exact same browser user agent:
我检查了日志,发现所有请求都有完全相同的浏览器用户代理:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36That’s Chrome 125, a browser version that’s over two years old. The browser version made it easy to identify the bots, as it’s unlikely that any human users who read my blog still use a browser that old.
那是Chrome 125,一个已经超过两年的浏览器版本。这个浏览器版本让我很容易识别出机器人,因为不太可能有阅读我博客的人类用户还在使用这么老的浏览器。
The scraper seemed to just repeatedly load the root contest page and then click every link over and over again, so I tried getting sneaky with it. I put a rewrite script on Bunny that checked the user agent and returned a fake response if it was the scraper. So instead of generating a page with 3,000+ links, it would generate a page with only three links.
这个爬虫似乎只是反复加载竞赛根页面,然后一遍又一遍地点击每个链接,所以我试图耍点小聪明。我在Bunny上放了一个重写脚本,检查用户代理,如果是爬虫就返回一个虚假的响应。因此,它不会生成一个包含3000多个链接的页面,而是生成一个只有三个链接的页面。
For whatever reason, my fake responses didn’t work. I suspect the scraper had already added the full set of URLs to a database, and so hiding them from the homepage didn’t do anything.
不管出于什么原因,我的虚假响应没有起作用。我怀疑爬虫已经把完整的URL列表添加到了数据库中,所以从主页上隐藏它们并没有起到任何作用。
I tried rate-limiting, but the lowest rate limit Bunny supports is 1 KB/s, and most of the app’s data is in files that are only a few KB each. The scraper was rotating around 100ish different IP blocks, so I couldn’t throttle by IP.
我尝试过限速,但Bunny支持的最低速率是1 KB/s,而应用的大部分数据都在只有几KB大小的文件中。爬虫在轮换大约100个不同的IP段,所以我无法按IP进行限速。
Finally, I just blocked by IP range. I vibecoded a tool that scraped my Bunny logs for the specific user agent and collected all the IPs associated with the attack. That worked, but then the attack started up again a week later from new IPs and a new, slightly more recent user agent, so I just re-ran my script and updated my list of IPs to block, and that seems to be working.
最后,我干脆按IP段屏蔽。我用vibecoded(一种快速编码方式)写了一个工具,从Bunny日志中抓取特定用户代理,并收集了所有与攻击相关的IP。这奏效了,但一周后攻击又开始了,来自新的IP和稍新的用户代理,所以我重新运行脚本并更新了要屏蔽的IP列表,这似乎有效。
The weirdest thing about the attack is that the bots don’t care about being blocked. They just keep hammering the server anyway. I’d expect them to say, “Oh, no use wasting compute and bandwidth on requests that have 100% been blocked at the TCP level for the past two weeks,” but they don’t mind apparently.
这次攻击最奇怪的地方在于,机器人并不在乎被屏蔽。它们仍然继续猛击服务器。我本以为它们会说:“哦,别浪费计算和带宽在那些过去两周内100%被TCP层屏蔽的请求上”,但显然它们并不介意。
Even after I block the attackers’ IPs, they just keep hammering away.
即使在我屏蔽了攻击者的IP之后,他们仍然继续猛击。
I reached out to Netlify support the day the attack began, but they were useless. I had to wait a week for each response. I think the first response was AI-generated because it told me to modify settings that didn’t exist. And then the second response seemed more human, but it basically said, “It looks like you solved this problem in the two weeks it took for me to respond, so nothing left for me to do!” Fortunately, they did refund me the $55 in overage fees after I asked.
攻击开始当天我就联系了Netlify支持,但他们毫无用处。每次回复都要等一周。我觉得第一个回复是AI生成的,因为它让我修改不存在的设置。第二个回复看起来更像人工,但基本上说:“看起来你在等我回复的两周内解决了这个问题,所以我没什么可做的了!”幸运的是,在我要求后,他们退还了55美元的超额费用。
Where can I host a static site?
我可以在哪里托管静态网站?
I host all my static sites with Netlify, and they’ve been getting progressively worse, but their complete indifference to the scraper bot attack has inspired me to find a vendor that will handle scraper bots more proactively.
我把所有静态网站都托管在Netlify上,它们变得越来越差,但他们对爬虫机器人攻击的完全漠视促使我寻找一个能更主动处理爬虫机器人的供应商。
The obvious answer is “Cloudflare,” but I’m alarmed at how much of the Internet’s infrastructure has centralized around Cloudflare, so I don’t want to centralize it further.
显而易见的答案是“Cloudflare”,但我对互联网基础设施如此集中围绕Cloudflare感到震惊,所以我不想进一步集中化。
I also considered just hosting on a VPS or a VPS + Bunny as a CDN, but I don’t want my site to go offline the day I’m on the front page of Hacker News because my VPS crashes or I misconfigure caching on Bunny. I want a solution where I just pay someone else to keep my site online.
我也考虑过只托管在VPS上,或者VPS + Bunny作为CDN,但我不希望我的网站在登上Hacker News首页的那天因为VPS崩溃或我错误配置Bunny缓存而离线。我想要一个解决方案,我只需付钱给别人来保持我的网站在线。
- Surge
- Pros
- Focused exclusively on static hosting, which is exactly what I want
- Unlimited bandwidth, so they assume the cost of scraper bot attacks
- Cons
- Run by a single person (I think), so increased outage risks
- All management is through their terminal app. There’s no web app
- It doesn’t look like they support multi-factor authentication, though it looks like they’re working on it
- The upload process unconditionally uploads every file rather than an rsync-like sync of only the changed files, which is a pain for my large sites that only change incrementally
- statichost
- Pros
- Run by a single person, so customer service is responsive and comprehensive
- Focused mainly on static hosting without extra complexity
- Cons
- Run by a single person, so increased outage risks
- The upload process unconditionally uploads every file rather than an rsync-like sync of only the changed files, which is a pain for my large sites that only change incrementally
- Bot scraper protection is not included
- Bundles together site builds and hosting, but I only want hosting
- A big selling point is being EU-centric, but I’m in the US
- Vercel
- Pros
- Claims to prevent DDoS / scraper bots
- I think they support rsync-style uploads
- Cons
- Surge
- 优点
- 专注于静态托管,这正是我想要的
- 无限带宽,所以他们承担了爬虫机器人攻击的成本
- 缺点
- 由一个人运营(我想),所以停机风险增加
- 所有管理都通过他们的终端应用进行。没有网页应用
- 看起来他们不支持多因素认证,不过似乎正在开发中
- 上传过程会无条件上传所有文件,而不是像rsync那样只同步更改过的文件,这对我的大型网站来说很麻烦,因为它们只是增量更改
- statichost
- 优点
- 由单人运营,因此客户服务响应迅速且全面
- 主要专注于静态托管,没有额外复杂性
- 缺点
- 由单人运营,因此宕机风险增加
- 上传过程会无条件上传所有文件,而不是像rsync那样只同步更改过的文件,这对我的大型网站来说很麻烦,因为它们只是增量更改
- 不包含机器人爬虫保护
- 将网站构建和托管捆绑在一起,但我只想要托管
- 一个重要的卖点是专注于欧盟,但我在美国
- Vercel
- 优点
- 声称能防止DDoS/爬虫机器人
- 我认为他们支持rsync风格的上传
- 缺点
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力