Why you shouldn’t use Redis as a rate limiter: Part 1 of 2
A tour of the common Redis-based rate limiter implementations — and the correctness and performance traps each one hides.
We can't find the internet
Attempting to reconnect
Something went wrong!
Hang in there while we get back on track
Rate limiting and admission checks that help reduce overload and protect expensive work.
Set admission budgets for launch spikes and promos before excess work reaches your handlers.
Fewer moving parts to run and monitor. Spend less on Redis and ops.
Add via SDK. Keep your stack. Clear limits your customers understand.
UNDERSTAND OVERLOAD · KEEP USEFUL WORK MOVING
For developers, architects, and managers: 27 narrated lessons on why services overload and how to protect them. No cloud experience required. Start with one request, or jump to any lesson.
Four chapters, one learning path. Read or listen in any order. ~41 minutes total · Times shown at 1×.
Keep enough capacity to finish work and recover.
Contain one customer's excess without punishing everyone.
Reduce work entering a shared dependency when it slows.
Choose, combine, and test the right protections.
Read the explanation or use the course map above. Audio is optional.
Caller clock and remote outcomes
Not a completed request.
The caller needs a bound on this wait.
Narrated snapshots of a 30-second caller budget, not a database execution timer. Cancellation must propagate and be honored. Unknown outcomes are alternatives, not simultaneous facts.
Read the numbered steps in order. The explanation below follows the narration.
The caller has a chosen 30-second deadline.
Timeout, cancellation, connection failure, and operation outcome are different facts.
Timeout, cancellation, connection failure, and operation outcome are different facts.
Maya cannot wait forever. Her caller has a deadline: a point after which it stops waiting for an answer. In this example that deadline is thirty seconds. A timeout is the caller reaching that deadline without the expected response.
At five seconds, Maya has twenty-five seconds left to wait. The interface must still look unfinished. At thirty seconds, it shows a timeout, not a successful report and not an error message supposedly sent by the database.
The database may still be doing the work. Cancellation is a separate instruction asking that work to stop, and each part of the system must carry it through and honor it. A connection is the communication link used by two components. If that link fails, an application may learn about the failure immediately rather than waiting thirty seconds.
Does Maya timing out prove that a database change did not happen? No. A caller stopping its wait does not establish whether the operation stopped, completed, or changed stored data.
Follow the caller separately from the database. Waiting for a result consumes time, but the caller’s decision to stop waiting does not by itself establish what happened to remote work.
At this starting snapshot, zero seconds have elapsed and thirty seconds remain. The bar represents the caller’s elapsed waiting time, not percent completion of a database operation.
This defines the event we will show next. The request is still waiting in the starting snapshot; when its budget is exhausted without the expected answer, the caller times out.
The caller remains visibly pending. Only five of the thirty seconds have elapsed, leaving twenty-five. Nothing in this snapshot says a report was delivered or that the database finished.
The failure is shown on Maya’s caller, not as an error response supposedly sent by the database. The caller reached thirty seconds without its expected report; this is not a successful completion.
The separate database track remains unresolved. A caller timing out does not automatically cancel the database operation, stop its resource use, or establish whether a write took effect.
This is a separate signal asking the operation to stop, not an automatic consequence of the earlier timeout. Each component must propagate or handle cancellation and the downstream operation must actually honor it.
The application and database exchange calls and answers over a connection. A connection’s condition is a different fact from the caller’s waiting budget or the database operation’s final outcome.
A broken connection may report an error immediately, without consuming the full thirty-second waiting budget. A fast communication error still does not automatically prove that remote work had no effect.
No. The operation may still be running, may have stopped, or may have completed without its answer reaching the caller. A timeout does not prove that stored data stayed unchanged, or that a write was rolled back.
Content revision: 07c7dd00db17
Download review copy (27 lessons)Maya times out. Can the database still be working?
Yes. Cancellation must reach the operation and be honored; the timeout alone does not stop it.
Propagate deadlines and cancellation where supported. Track caller and downstream outcomes separately.
Thirty seconds is this example’s chosen deadline, not a universal default or required setting.
Start here. No earlier lesson is required.
Accepting a request is not the same as delivering a useful result.
100 arrivals/s − 80 completions/s = 20 extra unfinished requests/s.
For writes, an unknown response may conceal a committed side effect. Do not label a timeout as proof of rollback.
Original explanation inspired by Fred Hébert and operational references; no endorsement implied.
AI-generated narration: ElevenLabs Eleven v3, Daniel stock voice. Audio streams only when you start listening.
A tour of the common Redis-based rate limiter implementations — and the correctness and performance traps each one hides.
The myth of infinite serverless scale — why adding machines doesn’t fix overload, and what to do instead.