Timeout, retry, rate limit và backpressure
Resilience là quản lý capacity và failure boundary, không phải thêm retry vào mọi exception. Deadline, retry ownership, breaker, bulkhead và rate limit phải cùng bảo vệ business outcome.
1. Deadline budget
Phân bổ overall deadline cho queue, pool acquisition, connect, TLS, write, server processing, downstream và response read. Mỗi timeout phải ngắn hơn remaining deadline; propagate deadline/cancellation khi protocol hỗ trợ. Timeout không chứng minh operation chưa xảy ra, nên side effect vẫn cần idempotency/reconciliation.
remaining = caller_deadline - now
pool/connect/read timeout = min(local_cap, remaining - safety_margin)
stop when remaining <= 0; do not start another retry
2. Retry và hedging
Chỉ retry transient failure và replay-safe operation. Dùng bounded exponential backoff + jitter, tôn trọng Retry-After, dừng theo deadline/attempt cap. Gateway × client × service retries có thể nhân tải; chỉ một tầng nên sở hữu retry policy. Hedging giảm tail latency chỉ với idempotent reads, duplicate-capacity budget và cancellation của bản chậm.
| Failure | Default action |
|---|---|
| Validation/authz/most 4xx | Không retry; sửa request hoặc credential |
| Connection reset trước write/known safe read | Có thể retry bounded nếu operation replay-safe |
| 429/503/temporary overload | Retry theo Retry-After và global deadline, giảm concurrency |
| Timeout sau unknown side effect | Không retry mù; query/reconcile/idempotency key |
3. Circuit breaker
Closed đo error/slow-call rate; open fail fast; half-open gửi probe để kiểm tra recovery. Breaker không thay timeout. Scope theo dependency/operation để một endpoint lỗi không chặn toàn service; fallback không được âm thầm trả dữ liệu sai.
4. Bulkhead và connection capacity
Tách thread, connection và concurrency quota để dependency không chiếm toàn capacity. Semaphore limit phù hợp virtual threads; executor pool/queue phải bounded. Queue dài biến overload thành latency và memory pressure, không phải resilience.
5. Rate limiting
Fixed/sliding window, token bucket và leaky bucket có trade-off burst, fairness và storage. Dimension theo principal/tenant/IP/operation/resource cùng global ceiling; distributed counter consistency và fail-open/closed tùy risk. Trả 429 với limit guidance nhưng không lộ policy giúp attacker tối ưu abuse.
| Dimension | Use case | Failure consideration |
|---|---|---|
| Principal/tenant | Fairness và business quota | Identity spoofing hoặc shared account |
| IP/device | Anonymous abuse protection | NAT false positive; IPv6/proxy parsing |
| Operation/resource cost | Report/export/payment protection | Không chỉ đếm request giống nhau |
| Global | Protect total capacity | Fail-open có thể overload; fail-closed có blast radius |
6. Load shedding và backpressure
Từ chối sớm low-priority hoặc expensive work khi saturation; dùng bounded queue, admission control, page/payload limit và load-shed signal. Backpressure khiến producer chậm lại hoặc giảm concurrency; buffer vô hạn chỉ trì hoãn crash.
7. Failure testing và evidence
Inject latency, reset, partial response, duplicate, DNS failure, TLS expiry, pool exhaustion và retry storm. Quan sát attempts, deadline propagation, queue/pool occupancy, breaker state, rate-limit decision và business outcome (không chỉ HTTP 200).