Tableau · Code review · Open-sourced a rate-limiting middleware for tableau-review with token bucket and sliding window

229
TAr/tableau-review·posted by huang_ke·just nowOpen source

Open-sourced a rate-limiting middleware for tableau-review with token bucket and sliding window

Short version: tableau-review needs almost no tuning at small and medium scale — the point where it starts to hurt is much further out than most people assume. Full measurements below.

The first thing was to collapse the variables. We were changing config and upgrading the version at the same time, and afterwards nobody could say which change caused what. We rolled back to moving one variable at a time, re-ran three times, and only then did the curve settle. Tedious, but not skippable.

On trade-offs, my view is this: if nobody on the team owns this area long-term, do not introduce a second mechanism. With two coexistence you first have to work out which one is even in play when things break, and that costs far more than the performance you saved.

Jjvns.caExternal link · opens in a new tab
125 comments

125 comments

· first 120 loaded
M
Sslow_query·2 days agoedited

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

412
NnikicOP·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

499
Ttang_hao·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

87
Zzhou_yi·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

39
Sslow_query·2 days ago

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

3
Rran_bo·2 days ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

2
Ddev_zhou·yesterday

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

135
Kkite·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

105
WwinterOP·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

335
Llinlin·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

384
Mmike_xu·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

356
Llinlin·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

213
Cchen_dev·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

38
Sswoole_leeMod·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

328
Mmike_xu·1 hour ago

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

302
Nnikic·just now

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

300
Bbob_chen·just now

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

194
Ddev_zhouOP·3 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

497
Kkernel_panicMod·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

209
Zzhu_zong·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

341
WwinterOPMod·2 days agoLevel 6

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

17
Zzhou_yi·just nowLevel 6

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

6
KkiteOP·5 hours ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

72
Hhuang_ke·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

85
Kkite·28 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

69
Ttang_hao·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

489
Bbob_chen·12 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

71
Bbob_chen·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

56
Kkernel_panic·28 minutes ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

18
Aalice_devOP·2 days ago

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

63
Ttang_haoOP·2 days agoLevel 6

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

365
Rrase·2 days agoeditedLevel 6

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

9
Cchen_devMod·2 days ago

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

68
Rrase·2 days agoLevel 6

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

27
Hhuang_keOP·2 days ago

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

1
Llinlin·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

14
Rran_bo·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

260
Wwinter·just now

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

237
Zzhu_zongOPMod·2 days agoedited

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

159
Oops_wang·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

215
Bbob_chen·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

207
Kkite·2 days agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

202
Lli_ming·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

196
Sslow_query·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

401
Mmike_xu·2 days ago

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

192
Cchen_devOP·2 days agoedited

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

98
Nnikic·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

150
Bbob_chen·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

144
Rran_bo·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

101
Kkernel_panicOP·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

58
Cchen_dev·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

113
Ttang_hao·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

81
Ddev_zhou·2 hours agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

78
Kkite·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

73
Cchen_dev·3 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

68
Mmike_xuOP·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

2
Cchen_dev·3 minutes ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

61
Bbob_chenOP·1 hour ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

1
Kkernel_panic·5 hours ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

56
Sswoole_lee·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

54
Zzhou_yi·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

483
Llinlin·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

6
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

1
Sswoole_lee·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

81
Bbob_chen·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

51
Wwinter·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

44
Nnikic·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

41
Ddev_zhou·2 days ago

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

37
Kkite·3 minutes ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

37
Rran_bo·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

27
Zzhou_yi·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

21
Ddev_zhou·12 minutes ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

21
Rran_bo·2 days ago

I just read the tableau-review source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

386
Kkernel_panic·2 hours ago

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

241
Rran_bo·2 days ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

225
Rran_boOPMod·12 minutes ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

193
Kkite·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

94
Mmike_xu·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

132
WwinterMod·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

110
Cchen_dev·2 days agoeditedLevel 6

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

148
Rrase·2 days agoLevel 6

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

56
Zzhou_yi·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

24
Zzhu_zong·2 hours ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

28
Cchen_devOP·2 days ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

70
Sslow_query·2 days agoLevel 6

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

71
Sslow_query·2 days ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

11
Hhuang_keOP·3 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

13
Nnikic·yesterday

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

62
Bbob_chenMod·2 days ago

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

35
Ttang_haoMod·2 days ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

34
Aalice_dev·just now

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

215
Kkernel_panicOPMod·3 minutes agoedited

Saved. I am reworking this area this week — this saves a lot of wrong turns.

404
Zzhou_yi·3 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

111
Ddev_zhou·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

284
Rran_bo·2 days agoLevel 6

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

94
Nnikic·2 days agoLevel 6

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

93
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

200
Nnikic·just now

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

1
Sslow_query·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

344
Mmike_xu·28 minutes ago

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

255
Nnikic·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

174
Rran_bo·1 hour ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

9
Wwinter·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

165
Aalice_dev·2 days ago

This is not a tableau-review problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

404
Sslow_query·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

1
Wwinter·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

20
LlinlinMod·2 days agoedited

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

7
Bbob_chen·yesterday

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

19
Nnikic·5 hours ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

157
Mmike_xu·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

1
Sswoole_lee·2 days agoedited

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

154
Wwinter·1 hour agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

7
Sslow_query·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

7
Nnikic·3 minutes ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

2
RraseMod·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

59
Kkite·12 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

284
RraseOP·2 days agoedited

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

116
Nnikic·just now

One counter-example: below tableau-review 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

1
Bbob_chen·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

1
Aalice_dev·12 minutes ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

1

This is the post detail page /en/c/tableau-review/post/p9. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →