Open-sourced a rate-limiting middleware for open-source-blog with token bucket and sliding window
Some background first. Our setup is open-source-blog plus three downstream services, seven figures of daily requests, peaking around nine in the evening.
Worth noting: the official docs do cover this, just in a very inconspicuous spot. I only found it reading the source comments, where the author explains the reasoning — roughly "so that it degrades into predictable behaviour in extreme cases".
-- The query that broke: a full scan over 20M rows. -- A composite index took P99 from 1.8s down to 42ms. SELECT id, title, created_at FROM posts WHERE community_id = ? AND status = 1 ORDER BY score DESC LIMIT 20;
We also fixed monitoring along the way: replaced average-based alerts with percentiles and split them per endpoint. False alerts dropped by about seventy percent and the on-call rotation visibly cheered up.
On trade-offs, my view is this: if nobody on the team owns this area long-term, do not introduce a second mechanism. With two coexistence you first have to work out which one is even in play when things break, and that costs far more than the performance you saved.