System Design Tutorial 0/48 lessons ~6 min read Lesson 22

    Rate Limiting & Throttling

    Rate limiting protects services from abuse and overload — token bucket, sliding window, and leaky bucket at gateway or service level.

    Course progress0%
    Focus
    21 guided sections
    Practice signal
    Examples included
    Career prep
    Interview Q&A included

    Introduction

    Rate limiting protects services from abuse and overload — token bucket, sliding window, and leaky bucket at gateway or service level.

    The story

    A partner API without rate limits got scraped; origin melted. Token bucket at gateway: 1000 req/min per API key — abusive key throttled, others unaffected.

    The business problem

    Teams that skip disciplined Rate Limiting & Throttling thinking pay in outages, cost overruns, and failed interviews:

    • Outages: components chosen without scale math fail at peak.
    • Cost: over-engineered microservices for 100-user products.
    • Latency: missing cache/CDN/replica on read-heavy paths.
    • Interviews: boxes without numbers and trade-offs don't hire.

    The problem teams faced

    This lesson addresses:

    • When and why Rate Limiting & Throttling matters in real architectures.
    • How to sketch components and data flows under interview time pressure.
    • Trade-offs vs alternatives — what senior engineers articulate aloud.
    • Production patterns and failure modes you've seen or will see.

    Understanding the topic

    Core idea: Rate Limiting & Throttling in production system design.

    • Problem — what force this topic addresses.
    • Building blocks — components typically involved.
    • Trade-offs — what you gain and what you pay.
    • Interview — how this appears in design loops.

    Internal architecture

    Rate Limiting & Throttling — system view:

    text
    Client → API Gateway
    ↓ rate limit check (Redis token bucket)
    ↓ allow / 429 Too Many Requests
    Backend services protected
    Per-user, per-IP, per-API-key policies

    Visual explanation

    Three diagrams: architecture flow, design process, and scaling lens:

    Rate Limiting & Throttling architecture
    Rate
    Entry point
    Limiting
    Core logic
    &
    Persistence
    Scale path
    Next bottleneck
    Component view — name each box in interviews.
    Design process
    Clarify scale
    QPS · storage
    Pick approach
    Trade-off
    Draw path
    One flow
    Failure mode
    What breaks?
    Repeat this loop for every system design question.
    Scale & reliability
    Bottleneck
    Find first
    Mitigation
    Cache · shard
    Measure
    SLI/SLO
    Iterate
    Phase 2
    Always close with how design evolves at 10× traffic.

    Informative example

    Example — Rate Limiting & Throttling:

    text
    Token bucket: burst allowed, refill rate steady — good for APIs
    Sliding window: precise count per minute — stricter
    429 + Retry-After header; client exponential backoff

    Execution workflow

    1Rate Limiting & Throttling design workflow
    1 / 5

    Clarify requirements

    Functional scope + NFRs (scale, latency, consistency).

    5 minutes in interviews.

    Real-world use

    Used in production at major tech companies and every FAANG system design interview loop. Patterns align with AWS/GCP well-architected frameworks and Google SRE practice.

    Production case study

    A partner API without rate limits got scraped; origin melted. Token bucket at gateway: 1000 req/min per API key — abusive key throttled, others unaffected.…

    • Context: production or interview scenario from this lesson.
    • Decision: component and trade-off choices explained.
    • Outcome: measurable latency, availability, or cost impact.

    Trade-offs

    • Pro: structured approach reduces outages and interview failures.
    • Con: upfront thinking takes time — faster than wrong rebuild.
    • Con: every product has unique constraints — adapt templates.

    Decision framework

    • Always estimate before drawing microservices.
    • Match consistency model to business domain (money vs likes).
    • Document rejected alternatives — ADR or interview closing.

    Best practices

    • State assumptions explicitly (DAU, read:write ratio).
    • Draw async vs sync paths with different line styles.
    • Close with monitoring and on-call failure modes.

    Anti-patterns to avoid

    • Jumping to Kafka and microservices without scale justification.
    • Single DB box with no read replica or cache on read-heavy design.
    • Ignoring idempotency on write APIs with retries.

    Common mistakes

    • Underestimating peak QPS (forgetting peak factor).
    • Hot shard from poor partition key choice.

    Debugging tips

    • Trace one request ID through diagram — find missing component.
    • Ask "what fails first at 10×?" for every design.

    Optimization strategies

    • Cache + CDN first for read-heavy; shard when single DB saturates.
    • Async queue for slow side effects (email, analytics).

    Common misconceptions

    • More components ≠ better design — simplest meeting NFRs wins.
    • Interviews test process — not memorizing Netflix architecture.

    Advanced interview questions

    Interview Prep

    Practice concise answers, then expand each card for the explanation.

    3 questions
    1IntermediateQuestionHow does Rate Limiting & Throttling appear in interviews?+

    Answer

    Usually as a component choice or deep-dive within a larger design. Explain trade-offs vs alternatives and give scale numbers.

    Follow-up

    What breaks first at 10×?
    2IntermediateQuestionRelated building blocks?+

    Answer

    Connect to load balancers, cache, DB replication, queues, and observability from this course — show compositional thinking.

    Follow-up

    Draw the data flow.
    3AdvancedQuestionSenior-level trade-off?+

    Answer

    Name CAP/consistency choice, cost vs latency, build vs buy (managed service), and operational burden of your choice.

    Follow-up

    Phase 1 vs phase 2?

    Summary

    You can explain Rate Limiting & Throttling in a 45-minute system design interview with numbers, diagrams, and trade-offs. Teach it back without notes — you own this piece.

    Ready to mark this lesson complete?Track your journey across the entire course.