← Middleware: understand and operate the chain
07 / 12 · 20 MIN

Retries, idempotency, and limits

Recognize when repetition helps and when it amplifies a failure.

Understand the concept

A timeout means the caller did not receive a response within its limit; it does not prove the remote operation failed. Before repeating an operation with side effects, consider how to detect an already completed execution. An idempotency key needs a validity, storage, and associated-result contract. For eligible transient failures, limit attempts and total time. Backoff spaces retries and jitter reduces client synchronization.

Apply and decide

Exercise: a chain has three layers and each can send up to three attempts per received request. If all retry, one initial action can generate up to 3 × 3 × 3 = 27 attempts at the final service. Budget retries across the whole path, not just per component. Distinguish transient errors from invalid input or missing authorization. For an unknown operation state, query or reconcile the operation before creating a new one.

Workplace application

After an instruction-submission timeout, the remote result can be uncertain. Retain operation identity and query status under the contract. For eligible transient failures, combine limits, an overall deadline, backoff, and jitter. If several layers retry, calculate the multiplication effect. Do not use retries to bypass format or authorization rejection; the same request remains invalid.

IN PRACTICE

A payment API does not respond, but the request may have been recorded. A new key on every attempt may create distinct operations. The consumer must preserve operation identity and follow the service’s idempotency and status-query contract.

Common pitfalls

Retrying deterministic failures; creating a new identity for each attempt.

Related topics: Measure the service and locate degradation · Map the request path

Take this idea with you

A timeout does not prove absence of effects; a retry needs limits and safe semantics.

Create account

Reference: Addressing cascading failures · DR Middleware 2026.4; HotSpot JDK 25; JDBC 25; PostgreSQL 18; RabbitMQ 4.3; OpenSSL 3.5; explicitly scoped runtime references