# Deadlines and Timeout Budgets — Rate Limiting, Circuit Breakers & Resilience Patterns

Source: https://www.skillbyai.com/en/resilience-patterns/f-deadlines

> Propagate deadlines through call chains so work stops when nobody is waiting.

## Every request has a deadline

A user will not wait forever, so a request has an overall **deadline**: for example, the page must respond within 2 seconds. Each downstream call gets a slice of that budget, and each layer's timeout must be **shorter** than its caller's, otherwise the caller gives up while the callee keeps working on an answer nobody will read. **Deadline propagation** passes the remaining time along with the request: gRPC does this natively with deadlines that travel in metadata, and HTTP services can pass a header such as a custom `X-Request-Deadline` and compute timeouts from it. When the remaining budget is too small to do useful work, **fail immediately** instead of starting expensive operations. Deadlines also make retries safer: a retry is attempted only if enough budget remains for it to succeed.

## Spending a deadline budget across calls

Each call gets what is left, minus a little for local work.

```python
import time

class Deadline:
    def __init__(self, seconds):
        self.expires_at = time.monotonic() + seconds
    def remaining(self):
        return max(0.0, self.expires_at - time.monotonic())

async def product_page(product_id):
    deadline = Deadline(2.0)                          # whole request budget
    product = await catalogue.get(product_id, timeout=min(0.5, deadline.remaining()))
    if deadline.remaining() < 0.2:
        return render(product, recommendations=[])   # not enough time: skip optional work
    recs = await recommendations.get(product_id, timeout=min(0.3, deadline.remaining() - 0.1))
    return render(product, recommendations=recs)
```

## Inner timeouts must be shorter

If the gateway times out at 5 seconds but the service it calls waits 10 seconds on its database, the database keeps working on abandoned requests during an incident. Make timeouts shrink as you go deeper.

**Quiz:** A gateway has a 3-second timeout. What should the timeout of the service it calls be?

- [ ] Longer than 3 seconds so it can finish
- [ ] Exactly 3 seconds
- [x] Shorter than 3 seconds, leaving room for the gateway to respond
- [ ] No timeout at all

*Answer:* Shorter than 3 seconds, leaving room for the gateway to respond. Inner timeouts must be shorter than outer ones so work is not wasted after the caller gives up.
