पाठ 15 / 25

Fallbacks, Timeouts and Circuit Breakers

Keep working when the model does not.

Graceful degradation

Model providers have outages, rate limits and slow periods. Give every AI call a timeout and a fallback: a simpler non-AI experience, a cached answer, or a smaller backup model. A circuit breaker stops calling a failing provider after repeated errors, serving the fallback immediately for a cooldown period instead of making every user wait for timeouts, then tries again. The product should stay usable with the AI part switched off.

A circuit breaker around an LLM call, run

I ran this with Python 3 (scipy 1.18.1 where imported) on example numbers, not data from a real product. After three consecutive timeouts the breaker opens: at 10 seconds the provider is healthy again, but the breaker still serves the fallback during its 30-second cooldown. At 40 seconds it tries again and the AI summary returns.

import time
class Breaker:
    def __init__(self, threshold=3, cooldown=30):
        self.fail, self.threshold, self.cooldown, self.opened = 0, threshold, cooldown, None
    def call(self, fn, fallback, now):
        if self.opened is not None and now - self.opened < self.cooldown:
            return fallback(), "fallback (breaker open)"
        try:
            out = fn(); self.fail = 0; self.opened = None; return out, "llm"
        except Exception as e:
            self.fail += 1
            if self.fail >= self.threshold: self.opened = now
            return fallback(), f"fallback ({type(e).__name__})"
outcomes = [True, False, False, False, True, True, True]      # provider ok / timeout per request
def make_llm(ok):
    def llm():
        if not ok: raise TimeoutError
        return "AI summary"
    return llm
b = Breaker()
for t, ok in zip([0, 1, 2, 3, 10, 40, 41], outcomes):
    result, path = b.call(make_llm(ok), lambda: "plain list of recent events", now=t)
    print(f"t={t:>2}s provider {'ok     ' if ok else 'timeout'} -> {path:<26} {result}")

Output:

t= 0s provider ok      -> llm                        AI summary
t= 1s provider timeout -> fallback (TimeoutError)    plain list of recent events
t= 2s provider timeout -> fallback (TimeoutError)    plain list of recent events
t= 3s provider timeout -> fallback (TimeoutError)    plain list of recent events
t=10s provider ok      -> fallback (breaker open)    plain list of recent events
t=40s provider ok      -> llm                        AI summary
t=41s provider ok      -> llm                        AI summary

Design the fallback first

Decide what users see when AI is unavailable before building the AI path; it is also your kill-switch experience.

त्वरित जाँच: Why use a circuit breaker for model calls?

  • To stop sending requests to a failing provider and serve a fallback quickly
  • To make the model smarter
  • To increase costs
  • To skip timeouts entirely
Answer

To stop sending requests to a failing provider and serve a fallback quickly — Fail fast, recover automatically.