mass-container-reinit-post-reboot-mimics-attack-pattern
When 100+ containers restart simultaneously after a VPS reboot, the combined initialization traffic (WAL replays, metric republishing, upstream reconnections, config pulls) produces CPU spikes, network ingress/egress bursts, and disk write spikes that look indistinguishable from a DDoS or runaway process. Before investigating attack hypotheses, check last -x reboot and container uptime uniformity to rule out post-reboot churn as the root cause.