正在加载内容...

963963 Chat News Review Independent coverage of news

A Field Guide to Rate Limiting

By James Whitfield · · 1231 words
A Field Guide to Rate Limiting

For access control, the constraint matters more than the feature list. Periodic jobs should be safe to run twice, because they will be. Teams working on access control usually discover this the hard way. You rarely need a new component to fix a boundary problem. The signal you want is often already logged, just not aggregated. This is most visible in access control.

Access Control: You can often replace a coordination problem with an idempotency key. Access Control: Anything that grows without a bound will eventually hit one. Access Control: Documentation that is not tested tends to describe the previous version.

Consent is ongoing. A person can withdraw it at any point, including after previously agreeing or after an activity has begun. If they say stop, move away, become unresponsive or otherwise indicate discomfort, pause immediately and ask what they want. Do not argue, bargain or demand an explanation.

Edge Caching: A queue smooths spikes but also hides how far behind you are. Retries without jitter turn a small outage into a large one. That applies to edge caching as well. In practice, edge caching behaves differently: Separating the reads from the writes buys room to change either side.

Cost Controls: The first thing to settle is the failure mode, not the happy path. Cost Controls: Measurements taken once are anecdotes; you need a baseline that repeats. Cost Controls: Costs usually concentrate in a small number of operations, so find those first.

Crawl Budget: If a metric has no owner, it will drift until it causes an incident. Crawl Budget: The cheapest optimisation is usually removing work nobody asked for. Crawl Budget: Aggregating at write time trades flexibility for predictable read cost.

Release Process: The first thing to settle is the failure mode, not the happy path. Release Process: Measurements taken once are anecdotes; you need a baseline that repeats. Release Process: Costs usually concentrate in a small number of operations, so find those first.

For schema migration, the constraint matters more than the feature list. The first thing to settle is the failure mode, not the happy path. Teams working on schema migration usually discover this the hard way. Measurements taken once are anecdotes; you need a baseline that repeats. Costs usually concentrate in a small number of operations, so find those first. This is most visible in schema migration.

Configurations should be reviewable in a diff, not only in a console. This is most visible in access control. Consider access control specifically. The best time to add an index is before the table gets large. Access Control: Failures are usually correlated, so plan for the shared dependency.

Serving static bytes is the cheapest thing you can do at the edge. That applies to backup strategy as well. In practice, backup strategy behaves differently: A schema is an interface; changing it is a migration, not an edit. Track the denominator as carefully as the numerator. The same reasoning holds for backup strategy.

Data Pipelines: The interesting number is not the average, it is the 99th percentile. Data Pipelines: Adding a cache in front of a slow query is a fix; fixing the query is a cure. Data Pipelines: Every abstraction you add is a place where behaviour can differ from intent.

Consider rate limiting specifically. If the rollback plan needs a meeting, it is not a rollback plan. Rate Limiting: Small pages that stay small are easier to keep fast than large ones made fast. Write the invariant down; otherwise it lives only in someone's memory. That applies to rate limiting as well.

Teams working on crawl budget usually discover this the hard way. You can often replace a coordination problem with an idempotency key. Anything that grows without a bound will eventually hit one. This is most visible in crawl budget. Consider crawl budget specifically. Documentation that is not tested tends to describe the previous version.

Backup Strategy: Configurations should be reviewable in a diff, not only in a console. The best time to add an index is before the table gets large. That applies to backup strategy as well. In practice, backup strategy behaves differently: Failures are usually correlated, so plan for the shared dependency.

Choose a cool, dry storage location away from direct sunlight, heaters, bathrooms with frequent steam and sharp objects. Do not leave the product in a vehicle or another place exposed to large temperature changes. Keep it out of reach of children and pets. A sealed container can help keep dust away, but only pack the product when both it and the container are dry; trapped moisture can remain on surfaces and in seams.

In practice, queue design behaves differently: Configurations should be reviewable in a diff, not only in a console. The best time to add an index is before the table gets large. The same reasoning holds for queue design. For queue design, the constraint matters more than the feature list. Failures are usually correlated, so plan for the shared dependency.

Monitoring Alerts: You can often replace a coordination problem with an idempotency key. Monitoring Alerts: Anything that grows without a bound will eventually hit one. Monitoring Alerts: Documentation that is not tested tends to describe the previous version.

Edge Caching: Serving static bytes is the cheapest thing you can do at the edge. Edge Caching: A schema is an interface; changing it is a migration, not an edit. Edge Caching: Track the denominator as carefully as the numerator.

API Design: The interesting number is not the average, it is the 99th percentile. API Design: Adding a cache in front of a slow query is a fix; fixing the query is a cure. API Design: Every abstraction you add is a place where behaviour can differ from intent.

A respectful response acknowledges the limit and follows it. A partner may ask a clarifying question, provided the question is not a way to wear someone down. Repeated requests after a clear no, guilt, anger used to secure agreement, or threats to end the relationship can undermine consent. Silence or lack of resistance should not be treated as agreement.

Crawl Budget: The interesting number is not the average, it is the 99th percentile. Crawl Budget: Adding a cache in front of a slow query is a fix; fixing the query is a cure. Crawl Budget: Every abstraction you add is a place where behaviour can differ from intent.

Observability: If a metric has no owner, it will drift until it causes an incident. Observability: The cheapest optimisation is usually removing work nobody asked for. Observability: Aggregating at write time trades flexibility for predictable read cost.

For edge caching, the constraint matters more than the feature list. The first thing to settle is the failure mode, not the happy path. Teams working on edge caching usually discover this the hard way. Measurements taken once are anecdotes; you need a baseline that repeats. Costs usually concentrate in a small number of operations, so find those first. This is most visible in edge caching.

Use direct, ordinary language. For example, ask, “Would you like to continue?” or “Are you comfortable with this?” A clear spoken answer can reduce guesswork, especially when you are unsure how to read someone’s response. Consent can be communicated in different ways, but a practical approach is to check verbally rather than infer agreement from silence, body language or the absence of resistance.

Related reading