Rate limiting & resilience · Key takeaways
1 min readRapid overview
Key takeaways
- Limit at the edge by authenticated identity; token bucket for bursts, sliding window for smoothness.
- Distributed limits need an atomic shared counter or local counts with periodic sync; choose fail-open or fail-closed.
- 429 for a client over quota, 503 for an overloaded service, both with Retry-After.
- Timeouts everywhere, shrinking with depth; retry once, at one layer, within a budget, with jitter.
- Circuit breakers fail fast and let dependencies recover; bulkheads keep failures in their compartment.
- Bounded queues, load shedding and planned degradation stop a slowdown becoming an outage.