Actually wrong. Just because the IP isn’t never hidden. Ddos isn’t an issue if a reverse proxy or similar has tools to stop it. And even then when there is real attack something more is needed than entry level solution. And if bots or slave users are knocking closed ports or IP-limited ports that isn’t so big issue. I would call it another thursday on WordPress world but Discourse is another world is so many ways.
On other hand, I’m not an expert of this.
But I’m curious… how much traffic is needed that ddos is succesful? Of course it depends of resources of setup, but please give me some numbers.