Rate Limiting
Refusing work is a feature
A system with no limit does not serve unlimited traffic. It serves traffic until it saturates, and then it serves everyone badly — latency runs away, queues grow without bound, and requests time out after consuming resources without producing anything useful.
Rate limiting converts that into a choice. Instead of degrading for everyone, you refuse some requests quickly and cheaply so the rest continue to be served properly. A fast 429 is a much better outcome than a 30-second timeout, for both sides.
It also contains blast radius. One client with a runaway retry loop should not be able to take down a service for everyone else, and without a limit that is exactly what happens.
Shedding load is not admitting defeat. It is the difference between a partial outage and a total one.
3 components2 connections0:00
Recording…