Rate Limiter diagram template
A distributed rate limiter at the gateway with shared counters and a rules store.
About this design
A rate limiter protects a service from both abuse and accidents, and the interesting question is where the counters live. This design checks every request at the API gateway, before any application code runs, using a shared Redis instance so that all gateway nodes agree on how many calls a key has made. The limiter reads its rules, such as requests per minute per API key, from a small configuration store that operators can edit without a deploy. Counters use a sliding window or token bucket depending on whether bursts are acceptable, and each check is a single atomic script so two nodes cannot both let the last request through. Rejected calls get an HTTP 429 with a retry hint. Talk through what to do when Redis is unreachable, since failing open keeps the product alive and failing closed protects the backend, and make that an explicit decision rather than an accident.
Diagram as text
This is the source of the diagram, in the ArchBoard diagram DSL. Paste it into Tools, Diagram from text to rebuild or change it.
title "Distributed rate limiter"
direction LR
client "API clients" -> gateway kong "API gateway" -> ratelimiter limiter "Limiter check"
[api-gateway x2]
limiter -> cache redis "Counters"
limiter -> db postgres "Rules"
api-gateway -> service backend "Backend service"
monitor prometheus "Metrics"
limiter -> metricsRelated guides
More interview classics templates
URL Shortener
A read-heavy link shortener with a CDN, cache and key generator in front of a database.
Pastebin Service
Store and share text snippets with object storage for content and a database for metadata.
Notification System
Fan out email, SMS and push notifications through a queue with per-channel workers.