Rate Limiter diagram template

A distributed rate limiter at the gateway with shared counters and a rules store.

Rate Limiter architecture diagramOpen in ArchBoard

Builds a new scene in your browser. Your existing scenes are not touched.

About this design

A rate limiter protects a service from both abuse and accidents, and the interesting question is where the counters live. This design checks every request at the API gateway, before any application code runs, using a shared Redis instance so that all gateway nodes agree on how many calls a key has made. The limiter reads its rules, such as requests per minute per API key, from a small configuration store that operators can edit without a deploy. Counters use a sliding window or token bucket depending on whether bursts are acceptable, and each check is a single atomic script so two nodes cannot both let the last request through. Rejected calls get an HTTP 429 with a retry hint. Talk through what to do when Redis is unreachable, since failing open keeps the product alive and failing closed protects the backend, and make that an explicit decision rather than an accident.

Diagram as text

This is the source of the diagram, in the ArchBoard diagram DSL. Paste it into Tools, Diagram from text to rebuild or change it.

title "Distributed rate limiter"
direction LR
client "API clients" -> gateway kong "API gateway" -> ratelimiter limiter "Limiter check"
[api-gateway x2]
limiter -> cache redis "Counters"
limiter -> db postgres "Rules"
api-gateway -> service backend "Backend service"
monitor prometheus "Metrics"
limiter -> metrics

Related guides

More interview classics templates