unwrap() is for invariant violations. in this particular case, the invariant was a soft limit which they treat as a hard one
The Cloudflare outage was caused by an unwrap().
I think Rust's standard library is very well-designed overall, but I think unwrap was a mistake.
Code that can panic should stand out—e.g. with panic!()—and "like panic! but harder to spot and easier to reach for" is a bad pitch.