Wrap Up
In this chapter, we discussed different algorithms of rate limiting and their pros/cons. Algorithms discussed include:
-
Token bucket
-
Leaking bucket
-
Fixed window
-
Sliding window log
-
Sliding window counter
Then, we discussed the system architecture, rate limiter in a distributed environment, performance optimization and monitoring. Similar to any system design interview questions, there are additional talking points you can mention if time allows:
-
Hard vs soft rate limiting.
-
Hard: The number of requests cannot exceed the threshold.
-
Soft: Requests can exceed the threshold for a short period.
-
Rate limiting at different levels. In this chapter, we only talked about rate limiting at the application level (HTTP: layer 7). It is possible to apply rate limiting at other layers. For example, you can apply rate limiting by IP addresses using Iptables 15 (IP: layer 3). Note: The Open Systems Interconnection model (OSI model) has 7 layers 16: Layer 1: Physical layer, Layer 2: Data link layer, Layer 3: Network layer, Layer 4: Transport layer, Layer 5: Session layer, Layer 6: Presentation layer, Layer 7: Application layer.
-
Avoid being rate limited. Design your client with best practices:
-
Use client cache to avoid making frequent API calls.
-
Understand the limit and do not send too many requests in a short time frame.
-
Include code to catch exceptions or errors so your client can gracefully recover from exceptions.
-
Add sufficient back off time to retry logic.
Congratulations on getting this far! Now give yourself a pat on the back. Good job!
Reference materials
- Rate-limiting strategies and techniques: https://cloud.google.com/solutions/rate-limiting-strategies-techniques
- Twitter rate limits: https://developer.twitter.com/en/docs/basics/rate-limits
- Google docs usage limits: https://developers.google.com/docs/api/limits
- IBM microservices: https://www.ibm.com/cloud/learn/microservices
- Throttle API requests for better throughput: https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-request-throttling.html
- Stripe rate limiters: https://stripe.com/blog/rate-limiters
- Shopify REST Admin API rate limits: https://help.shopify.com/en/api/reference/rest-admin-api-rate-limits
- Better Rate Limiting With Redis Sorted Sets: https://engineering.classdojo.com/blog/2015/02/06/rolling-rate-limiter/
- System Design — Rate limiter and Data modelling: https://medium.com/@saisandeepmopuri/system-design-rate-limiter-and-data-modelling-9304b0d18250
- How we built rate limiting capable of scaling to millions of domains: https://blog.cloudflare.com/counting-things-a-lot-of-different-things/
- Redis website: https://redis.io/
- Lyft rate limiting: https://github.com/lyft/ratelimit
- Scaling your API with rate limiters: https://gist.github.com/ptarjan/e38f45f2dfe601419ca3af937fff574d#request-rate-limiter
- What is edge computing: https://www.cloudflare.com/learning/serverless/glossary/what-is-edge-computing/
- Rate Limit Requests with Iptables: https://blog.programster.org/rate-limit-requests-with-iptables
- OSI model: https://en.wikipedia.org/wiki/OSI_model#Layer_architecture
Finished reading?
Mark it complete to track your progress.