← Microservices: design boundaries and operate distributed systems
03 / 6 · 40 MIN

Resilience and load

Bound extra work caused by failures and latency.

Concept and mechanism

A remote call can end at the client while the server continues execution. Before retrying a write, understand the idempotency contract and how to query the result. Timeouts should reflect the overall deadline and the work they actually cover, including connection establishment where applicable. Retries at multiple layers multiply attempts. In an exercise with three layers, each permits two total attempts including the initial one: persistent failure can produce eight calls to the final dependency. The calculation assumes retries at every layer and is not a configuration recommendation. Attempt limits, increasing delays, and jitter address related but different problems.

Guided application

In a fictional APS incident, a slow dependency consumes every connection and blocks unrelated functions. A bulkhead separates capacity by dependency or work class, with limits that respect total resources. A circuit breaker can suspend calls likely to fail; half-open allows controlled attempts to assess recovery. It does not repair the dependency or independently determine whether an alternative result is valid for the business. An old report may be acceptable when freshness is shown; authorization based on an outdated limit may not be. Agree degradation behavior with the business owner and measure completed operations, queues, latency, and rejections.

IN PRACTICE

Two attempts per layer across three layers can produce 2×2×2=8 final calls.

Common pitfalls

Timeout as cancellation; jitter as a limit; circuit breaker as repair; fallback as always correct.

Related topics: Boundaries and contracts · Data and distributed transactions · Messages and queues

Take this idea with you

Protect deadlines and capacity without hiding business outcomes.

Create account

Reference: Timeouts retries and backoff with jitter · Microservice architecture patterns and scoped platform examples; primary guidance consulted 2026-09-30