Resilience Patterns
JustAPI incorporates enterprise resilience primitives directly in the Rust engine.
Circuit Breakers
Section titled “Circuit Breakers”Automatically stop calling a failing service when errors exceed a threshold:
app.enable_circuit_breaker( failure_threshold=5, # Open after 5 consecutive failures reset_timeout_ms=30000, # Try again after 30 seconds)States:
- Closed — Normal operation, requests pass through
- Open — Requests fail fast with 503
- Half-Open — Probe request allowed; success → Closed, failure → Open
Request Coalescing
Section titled “Request Coalescing”Deduplicate concurrent identical requests so only one hits the backend:
app.enable_request_coalescing( headers=["accept"], # Consider these headers for dedup keys)When 100 identical requests arrive simultaneously:
- Only 1 request reaches the handler
- The response is shared across all 100 callers
- Saves backend resources on cacheable/read-only endpoints
Rate Limiting
Section titled “Rate Limiting”Global Rate Limiter
Section titled “Global Rate Limiter”app.enable_rate_limiter(max_requests=1000, window_seconds=60)Per-IP Rate Limiter
Section titled “Per-IP Rate Limiter”app.enable_ip_rate_limiter(max_requests=100, window_seconds=60)Exceeding limits returns 429 Too Many Requests with Retry-After header.
Bulkhead Pattern
Section titled “Bulkhead Pattern”Limit concurrent requests to prevent resource exhaustion:
app.enable_bulkhead(max_concurrent=100)When the limit is exceeded, requests receive 503 Service Unavailable.
Timeout Middleware
Section titled “Timeout Middleware”Cancel requests that exceed the time limit:
app.enable_timeout(seconds=30)Returns 504 Gateway Timeout when exceeded.
Graceful Degradation
Section titled “Graceful Degradation”app.enable_fallback_middleware( fallback_response={"status": "degraded", "message": "Please try again later"},)Graceful Shutdown
Section titled “Graceful Shutdown”JustAPI handles SIGINT/SIGTERM automatically:
- Stop accepting new connections
- Drain in-flight requests (with configurable timeout)
- Call plugin
on_shutdown()hooks - Close database connections
- Exit cleanly
Panic Model
Section titled “Panic Model”In production, Rust panics abort the process (not unwind). The supervisor (Docker, systemd, K8s) restarts the process immediately:
[profile.release]panic = "abort"This avoids undefined behavior across the PyO3 FFI boundary during panics.
Configuration Summary
Section titled “Configuration Summary”app = JustAPIApp()
# Resilienceapp.enable_circuit_breaker(failure_threshold=5, reset_timeout_ms=30000)app.enable_request_coalescing(headers=["accept"])app.enable_rate_limiter(max_requests=1000, window_seconds=60)app.enable_ip_rate_limiter(max_requests=100, window_seconds=60)app.enable_bulkhead(max_concurrent=100)app.enable_timeout(seconds=30)See Also
Section titled “See Also”- Production Checklist — Production deployment
- Security — Security policy and OWASP compliance
- Observability — Monitoring resilience signals