पाठ 11 / 25

Fallbacks and Graceful Degradation

Design useful fallbacks and degrade features instead of failing whole requests.

Something is better than an error

When a dependency fails, a fallback returns an alternative result. Options, in rough order of preference: cached or last-known-good data (yesterday's recommendations, the last fetched exchange rate); a sensible default (a generic "popular items" list, a standard delivery estimate); a reduced feature (hide the reviews widget, disable search filters); a deferred action ("payment pending, we will email you" with the work queued for later); or a clear, friendly error for the specific feature while the rest of the page works. Identify for each dependency whether it is critical (checkout cannot complete without payment authorisation) or optional (recommendations, reviews, personalisation). Optional dependencies should never fail the whole request. Be honest with users and careful with money: never pretend a payment succeeded, and make sure fallback data cannot cause wrong business decisions.

A degradation plan for a product page

Decide fallbacks in design, not during an incident.

dependency        critical?  fallback when unavailable
----------------  ---------  -------------------------------------------------
catalogue         yes        serve CDN-cached page (stale-if-error), else error
price service     yes        last cached price + "price confirmed at checkout"
inventory         partly     show "check availability" instead of stock count
reviews           no         hide the reviews section
recommendations   no         static "popular in this category" list
personalisation   no         generic page
feature flags     no         built-in safe defaults compiled into the app

A restaurant with a limited menu

When the tandoor breaks, a good restaurant does not close; it hands you a menu without tandoori dishes. Customers are mildly disappointed rather than sent home hungry.

त्वरित जाँच: The reviews service for a product page is down. What is the best behaviour?

  • Return HTTP 500 for the product page
  • Render the page without the reviews section
  • Retry the reviews call forever
  • Redirect users to the home page
Answer

Render the page without the reviews section — Optional features should degrade without failing the critical path.