Skip to content

Design an API Rate Limiter, stage 1 of 10: model

What the numbers say

Thirty instances, 40,000 requests a second, plans measured per minute. Before choosing a design, check which simple ideas the arithmetic already rules out.

System so far· 4 parts
123CLIENTAPI clientsEDGELoad balancerSERVICEAPI instancesDATABASEPostgres

Select a component to see what it is responsible for and which state it owns.

  1. 1API clients → Load balancer: Requests with API key
  2. 2Load balancer → API instances: Round-robin across instances
  3. 3API instances → Postgres: Admitted requests; plan lookups (cached)

What you need to know

0 of 3 checks done
  1. A rate limit is a promise per key: "this API key gets 600 requests a minute". The hard part is that the key's requests don't arrive at one place. The load balancer spreads them round-robin over every instance, so with 30 instances each one sees about 1/30th of any key's traffic.

  2. Work it out

    A Pro key sends 600 requests a minute, spread evenly over 30 instances. About how many of them does one instance see per minute?
    per minute