पाठ 16 / 25
Rate Limiting
Protect services from overload and abuse.
Token bucket and friends
Rate limiters cap requests per client, API key or IP. The token bucket refills at a steady rate and allows bursts up to its capacity; the leaky bucket smooths output; fixed and sliding windows count requests per period. In a distributed system, counters usually live in a shared store such as Redis with atomic operations. Rejected requests get 429 Too Many Requests with a Retry-After header.
A token bucket allowing bursts, run
I ran this with Python 3.12.3 using only the standard library; inputs are fixed or seeded, so the output is reproducible. A bucket of 10 tokens refilling at 5 per second allows a burst of 10 at once, then 5 more after a second, and a steady 5 requests per second indefinitely.
# Token bucket: 5 requests/second sustained, bursts of up to 10
class TokenBucket:
def __init__(self, rate, capacity):
self.rate, self.capacity = rate, capacity
self.tokens, self.last = capacity, 0.0
def allow(self, now):
self.tokens = min(self.capacity, self.tokens + (now - self.last) * self.rate)
self.last = now
if self.tokens >= 1:
self.tokens -= 1
return True
return False
b = TokenBucket(rate=5, capacity=10)
burst = [b.allow(0.0) for _ in range(12)] # 12 requests at t=0
print("burst at t=0 :", burst.count(True), "allowed,", burst.count(False), "rejected")
later = [b.allow(1.0) for _ in range(7)] # 1s later: 5 tokens refilled
print("7 more at t=1 :", later.count(True), "allowed,", later.count(False), "rejected")
steady = [b.allow(2.0 + i * 0.2) for i in range(10)] # exactly 5 req/s
print("steady 5 req/s:", steady.count(True), "of 10 allowed")
Output:
burst at t=0 : 10 allowed, 2 rejected 7 more at t=1 : 5 allowed, 2 rejected steady 5 req/s: 10 of 10 allowed
Limit at several layers
Edge limits stop abuse cheaply; per-service limits protect databases and downstream dependencies.
त्वरित जाँच: Which HTTP status signals rate limiting?
- 500 Internal Server Error
- 404 Not Found
- 429 Too Many Requests
- 301 Moved Permanently
Answer
429 Too Many Requests — With Retry-After when possible.