wtf( )unctionsystem design, drawn
← all problemsResilienceHard

Finishing work nobody is waiting for

A checkout service feeds an unbounded in-memory queue. During a flash sale, latency climbs to forty seconds, clients give up at five and retry, the queue reaches two hundred thousand entries, and the pod is killed for running out of memory. Then it happens again.

Every request in that queue is being processed for a client who left. The capacity is going to work whose result nobody will read.

Bound what the service will accept.
Components — tap one, then tap a slot on the diagram
!The pod has been killed for running out of memory three times this hour.

Outside every boundary: Clients (give up at 5s, retry), Checkout (FAILED: out of memory), Database (the real ceiling), an empty slot for the at the door Connections: Clients calls at the door (step 1) at the door calls Checkout — bounded in flight (step 2) Checkout calls Database (step 3)

Clientsgive up at 5s, retry
Checkoutout of memory
Databasethe real ceiling