When is it time to move beyond basic rate limiting
Ifiok Etim
·3009 views
we've got basic rate limiting in place on our API Gateway, and it's handling simple request throttling pretty well. But as we scale and introduce more complex user behaviors and potential abuse vectors, I'm wondering when it's time to think about more sophisticated approaches. Are you guys using things like leaky bucket, token bucket, or even more advanced algorithms at the application or service level? What prompted the switch for you, and what were the biggest challenges in implementing and managing it?
32 comments