पाठ 3 / 25

Deadlines and Timeout Budgets

Propagate deadlines through call chains so work stops when nobody is waiting.

Every request has a deadline

A user will not wait forever, so a request has an overall deadline: for example, the page must respond within 2 seconds. Each downstream call gets a slice of that budget, and each layer's timeout must be shorter than its caller's, otherwise the caller gives up while the callee keeps working on an answer nobody will read. Deadline propagation passes the remaining time along with the request: gRPC does this natively with deadlines that travel in metadata, and HTTP services can pass a header such as a custom X-Request-Deadline and compute timeouts from it. When the remaining budget is too small to do useful work, fail immediately instead of starting expensive operations. Deadlines also make retries safer: a retry is attempted only if enough budget remains for it to succeed.

Spending a deadline budget across calls

Each call gets what is left, minus a little for local work.

import time

class Deadline:
    def __init__(self, seconds):
        self.expires_at = time.monotonic() + seconds
    def remaining(self):
        return max(0.0, self.expires_at - time.monotonic())

async def product_page(product_id):
    deadline = Deadline(2.0)                          # whole request budget
    product = await catalogue.get(product_id, timeout=min(0.5, deadline.remaining()))
    if deadline.remaining() < 0.2:
        return render(product, recommendations=[])   # not enough time: skip optional work
    recs = await recommendations.get(product_id, timeout=min(0.3, deadline.remaining() - 0.1))
    return render(product, recommendations=recs)

Inner timeouts must be shorter

If the gateway times out at 5 seconds but the service it calls waits 10 seconds on its database, the database keeps working on abandoned requests during an incident. Make timeouts shrink as you go deeper.

त्वरित जाँच: A gateway has a 3-second timeout. What should the timeout of the service it calls be?

  • Longer than 3 seconds so it can finish
  • Exactly 3 seconds
  • Shorter than 3 seconds, leaving room for the gateway to respond
  • No timeout at all
Answer

Shorter than 3 seconds, leaving room for the gateway to respond — Inner timeouts must be shorter than outer ones so work is not wasted after the caller gives up.