Distributed Rate Limiter
Enforce a per-key request limit across a fleet of enforcers — accurately, in under a millisecond, without becoming the outage.01Clarifications
What would you ask before drawing a single box?
Ambiguity you would resolve with the interviewer: scope, scale, who uses it, what counts as done.
Enter to send · Shift+Enter for a new line
About Distributed Rate Limiter
Enforce a per-key request limit across a fleet of enforcers — accurately, in under a millisecond, without becoming the outage.
- Difficulty
- intermediate
- Time
- about 35 minutes
- Stages
- 10
- Topic
- System Design Fundamentals
How this problem is worked
Ten stages, from the questions you would ask an interviewer to the trade-offs you would defend. Each asks one question, and the simulator runs the architecture you draw against the requirements you wrote.
- 01ClarificationsWhat would you ask before drawing a single box?
- 02Functional reqsWhat must this system actually do?
- 03Non-functionalWhat must it promise about speed, uptime and correctness?
- 04Capacity estimationHow much load and data does this have to hold?
- 05API designWhat does the outside world call, and what comes back?
- 06Data modelWhat gets stored, and what is it looked up by?
- 07Use-case breakdownHow does each requirement actually get served?
- 08High-level designWhich components handle a request, and in what order?
- 09Deep divesWhich part breaks first, and what do you do about it?
- 10Trade-offsWhat did this design cost, and what breaks at 10×?
Primary sources for this problem
- Stripe — Scaling your API with rate limiters (token bucket on Redis, fail-open)
- Cloudflare — How we built rate limiting to millions of domains (sliding-window counter)
- GitHub — Sharded, replicated rate limiter in Redis (replica-expiry gotcha)
- Envoy — Global rate limiting + Lyft `ratelimit` service (local + global)
- Figma — An alternative approach to rate limiting (sliding-window counter, hot key)
- Google SRE Book — Handling Overload (adaptive throttling, criticality)
- IETF draft-ietf-httpapi-ratelimit-headers (RateLimit / RateLimit-Policy)
- redis-cell — GCRA rate limiting as one command (CL.THROTTLE)
Build the primitives this design leans on
Each one is an animated curriculum that constructs the system from scratch.
More in System Design Fundamentals
The four primitives every later problem assumes — unique IDs, rate limits, caching a read-heavy endpoint, and making a retry safe.
Browse the full problem catalog, or see what the simulator does and does not model.