Circuit Breaker diagram template
Stop calling a failing dependency, serve a fallback response and probe carefully for recovery.
About this design
A failing dependency is dangerous mostly because callers keep waiting on it. Threads pile up behind slow requests, the caller exhausts its own capacity, and a small outage cascades upward. A circuit breaker wraps the call and counts failures. While the circuit is closed, requests flow normally. When failures cross a threshold the circuit opens and calls fail immediately, with no waiting, returning a cached value or a degraded response instead. After a cool-down the breaker moves to half open and lets a few trial requests through; success closes it again, failure reopens it. This template shows the caller, the breaker, the protected service and a fallback. Discuss thresholds based on error rate rather than count, bulkheads that cap concurrency per dependency, timeouts that are shorter than the user's patience, and alerting when a breaker opens.
Diagram as text
This is the source of the diagram, in the ArchBoard diagram DSL. Paste it into Tools, Diagram from text to rebuild or change it.
title "Circuit breaker"
direction LR
service caller "Caller" -> service cb "Circuit breaker"
cb -[closed]-> microservice dep "Payments service"
cb -[open: fail fast]-> cache redis "Fallback response"
cb -> monitor prometheus "State metrics"
cb -[half-open probes]-> depMore reliability templates
Multi-Region Active-Passive
A warm standby region with replicated data and DNS failover for disaster recovery.
Blue-Green Deployment
Two identical environments with an instant traffic switch and a quick rollback.
CDN with Origin Shield
Edge caches, a shield layer and an origin protected from simultaneous cache-miss storms.