The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →A rate limiter controls how much request traffic a caller can send over time. A token bucket is a practical way to express that policy: its capacity sets the allowed burst, its refill rate sets how quickly capacity returns, and each request consumes a defined token cost. Before writing the limiter, decide who shares a budget, what traffic is acceptable, and what response clients receive when the budget runs out.
Define the policy before choosing an algorithm
A limiter is only as useful as the policy it enforces. Specify these choices before implementing it:
As an Amazon Associate I earn from qualifying purchases.
- Identity: Which requests share a budget? The limiter’s key might be an authenticated principal, API key, account, or IP address, but these identify different things and are not interchangeable. Requests with the same key share the same budget.
- Sustained rate: How quickly should request capacity be restored?
- Burst allowance: How many requests may arrive together after capacity has accumulated?
- Request cost: Does each request consume one token, or should expensive operations consume more?
- Exhaustion behavior: What response should the client receive when it has insufficient budget?
These choices define what the limiter means in your system; the algorithm implements them.
Free tools Windows power users keep installed
One-click scans. No signup required.
How fixed windows and token buckets differ
Fixed-window counter
A fixed-window counter counts requests during a clock-aligned interval and resets when the next interval begins. That reset creates a boundary effect: a caller may use much of its allowance just before the boundary and then use the new window’s allowance immediately after it. A nominal per-window limit therefore does not by itself prevent a short burst that straddles the reset.
#1 Best Overall
- In-Movie Experience!
- Feature-Length Documentary The Matrix Revisited
- Behind The Matrix Documentary Gallery: 7 Featurettes
- Take The Red Pills Documentary Gallery: 2 Featurettes
- Follow The White Rabbit Documentary Gallery: 9 Featurettes
Token bucket
A token bucket stores a finite budget of tokens. It gains tokens over time up to its capacity, and each request removes its configured cost. If the bucket cannot cover a request, that request is denied. Unlike a fixed-window reset, this model provides a bounded burst allowance alongside ongoing replenishment.
Capacity and refill rate answer separate questions. Capacity sets the largest stored burst the bucket can permit; refill rate sets how quickly it recovers after use. Setting capacity above the refill rate permits temporary bursts, but the bucket needs time to replenish before the same burst is available again. A token bucket does not guarantee one exact rate over every arbitrary time interval: observed behavior also depends on its parameters, the key used for accounting, the implementation, and how multiple instances coordinate.
Translate the policy into Spring Cloud Gateway
Spring Cloud Gateway’s RequestRateLimiter filter delegates decisions to a RateLimiter. The current Spring Cloud Reference Documentation describes a Redis implementation based on token buckets; using it requires the reactive Redis starter. Its documented settings map to the policy this way:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute| Setting | Meaning | Policy decision |
|---|---|---|
replenishRate |
Requests per second restored to the bucket | Choose the sustained replenishment rate. |
burstCapacity |
Maximum request capacity the bucket can hold | Choose the maximum accumulated burst. |
requestedTokens |
Token cost charged per request; the documented default is 1 | Choose how much capacity each operation consumes. |
For example, the reference illustrates settings such as a replenish rate of 10 and a burst capacity of 20. These are configuration examples, not universal recommendations or performance results. Choose values based on the traffic and work your service is willing to accept.
Choose a meaningful key
Gateway uses a configurable KeyResolver to select the key used for accounting. The documented default resolves the authenticated principal name. That choice makes requests associated with the same principal share a budget; it is not automatically a per-IP or per-API-key policy. The reference also shows a resolver that reads a user query parameter and explicitly warns that it is not recommended for production.
Decide what denial means to clients
When the limiter denies a request, Spring Cloud Gateway returns HTTP 429 - Too Many Requests by default. Make sure your client-facing behavior matches your API contract, and ensure clients can distinguish a rate-limit denial from an application error.
Rank #4
- Complete 5-Film Franchise Collection: Features all four live-action feature films (The Matrix, The Matrix Reloaded, The Matrix Revolutions, and The Matrix Resurrections) alongside the animated prequel anthology The Animatrix.
- High-Definition Video & Audio: Presented in 1080p Full HD widescreen with high-impact English Dolby Atmos and Dolby TrueHD audio options.
- Over 10 Hours of Cyberpunk Action: Delivers 653 total minutes of visual effects, martial arts, and iconic sci-fi storytelling created by the Wachowskis.
- 5-Disc Box Set with Original Slipcover: Includes 5 high-capacity BD-50 Blu-ray discs housed in collectible original outer slipcover packaging.
- Region-Free Compatibility: Fully unlocked and playable on standard Blu-ray players worldwide.
Choose an approach for the deployment you have
A local in-process limiter and a shared limiter raise different questions, especially when requests can reach more than one application instance. The available documentation establishes how Gateway’s Redis-backed limiter is configured, but does not establish a universally best design for coordination or backend-failure behavior. Compare the options against the requirements you can verify for your own system:
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors| Decision axis | What to establish |
|---|---|
| Burst allowance | What maximum bucket capacity should one identity be able to accumulate? |
| Sustained rate | How quickly should the budget replenish? |
| Per-request cost | Should all requests cost one token, or should expensive work consume more? |
| Key selection | Which identity should share a budget, and can clients safely control that value? |
| Coordination across instances | How will requests reaching different instances share or diverge in their accounting? |
| Backend failure | What should happen to traffic if a shared limiter’s backing service is unavailable? |
| Operational complexity | What additional infrastructure, configuration, and monitoring does the choice require? |
Do not assume a shared store automatically answers the coordination or outage questions. Confirm those behaviors for the specific limiter and deployment before relying on them.
Best Value
Reference and scope
Spring Cloud’s current reference documentation describes RequestRateLimiter, the Redis token-bucket settings, key resolution, and the default denial status. Because the URL points to the current reference, configuration details may change with Spring Cloud versions; check the documentation matching the version you deploy. The title’s DEV Community page, “Building a Rate Limiter: Lessons from The Matrix”, appeared in search results with a fixed-window versus token-bucket comparison and a Python-like example, but the page itself was not accessible for verification here.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




