If we're thinking of last resort solutions here as in "KF is knocked off clearnet completely and we need to fix that desperately due to funding, upkeep and whatnot":
Decentralize. Open-source a docker container that can run on any computer/server, Linux and Windows. In one easy docker command, a helpful hoster can deploy it. This hoster can go buy a cheap $2 domain, and put it behind a big-boy DDoS mitigation service. Through Tor, that service can talk to the Tor origin (the one here that doesn't go down - multiple if Josh makes more to help with this) and serves a clearnet mirror of Kiwi Farms on the hoster's domain.
A open-source KiwiFlare variant can exist on these containers so we aren't funneling shit traffic through Tor and slowing the real visitors down on that node. A bad actor running a bad node without the said KiwiFlare just opens a bad clearnet domain that will be slow for anyone trying to use it because Tor is overwhelmed from that source, it doesn't make the other domains any less slow - Tor handles that for us. Obviously Kiwi Flare would still be auditing the traffic as it comes in through Tor on the origin side, same way it does connecting through Tor now. Load times become practically double getting in, but I mean, it's not unbearably bad.
You cannot DDoS the Tor network. We do this, we have clearnet domains running Kiwi Farms (a ton of them, I know myself and likely many others would host some), and each individual one would have to be knocked down the process of going through each DDoS provider. Lots of them have free options that are very good at protecting the domains like Cloudflare, AWS Shield, Google Cloud Armor, Fastly, Sucuri, QUIC.
Each clearnet domain would indeed be vulnerable to quick actions by these companies, it's just a bet on how slow or willing they are to move. Maybe good links can be kept privately amongst groups of people independently hosting them here and giving them out to users they know/like so when normie public links go down the most of us aren't bothered while the hoster of that normie domain jumps ship to another DDoS mitigation provider.
And like I said maybe Josh goes all in on this and spins up a few more Tor routed origins that can be shared across hosters. Improve Tor latency this way so all that traffic going straight through Tor to one origin doesn't slow all Tor traffic going in.
There are two kinds of DDoS attacks: application and network. Application attacks can be mitigated by a web application firewall (WAF) like KiwiFlare. Network attacks require a packet scrubber. There is no such thing as a firewall that can stop a network attack. The attack breaks the service (and in our instance the entire network for the entire service provider) before it ever gets seen by a firewall. That's why any comment about "why not just block it" is retarded.
So effectively, this puts us on the safe side of the network layer again and we're fighting application. Obviously this ain't a weekend project and is also a big fat fuck you to all the companies we're hopeful might take us back in. We'd be violating their terms of service horrifically. But fuck these people and their censorship, I say it's worth it and would be a fantastic, impressive feat to pull off if we do it correctly.