Chapter 3: Distributed Rate Limiting with Redis & GCRA Algorithm
Prerequisite: Before reading this chapter, please ensure you have read the previous article in this series: Chapter 2: The 3 Caching Vulnerabilities (Penetration, Breakdown, Avalanche) & Go Singleflight. If caching is the shield protecting your database, Rate Limiting is the armor guarding your API servers from DDoS attacks and resource exhaustion caused by abusive clients. 1. Why Local Rate Limiting Fails in Microservices Local RAM limiters fail because Load Balancers distribute traffic across multiple nodes. A user allowed 100 req/sec can exploit a 5-node cluster by sending 500 req/sec, bypassing the intended limit. Centralized state via Redis is required. ...