Circuit breaker
Also called: breaker, fail fast.
A wrapper around calls to another service that counts failures and, past a threshold, stops calling it for a while and fails fast instead (open). After a wait it lets a few test calls through (half-open), and if they succeed, normal calls resume (closed).
The payments API is down. After 3 failed calls in a row the breaker opens: calls fail fast for 5 seconds, then one test call goes through.
Closed Calls go through. 0 of 3 failures.
Say it in a prompt
Wrap calls to the payments API in a circuit breaker: 2-second timeout; open when 50% of the last 20 calls fail or time out; while open, fail fast for 30 seconds with a 'try again soon' error; then go half-open and allow 3 test calls, closing if all succeed and opening again if any fails. Seen on
- Netflix Hystrix: Opens the circuit when request volume and error percentage pass their thresholds, short-circuits calls for a sleep window, then lets a single test request through (half-open).
- Resilience4j: Its CircuitBreaker has CLOSED, OPEN and HALF_OPEN states; by default it opens at a 50% failure rate, waits 60 seconds, then allows 10 calls in half-open.
You might describe it as
- stop calling the service that keeps timing out
- fail fast when the other API is down
- one broken service drags everything down with it
Not to be confused with
- Graceful degradation
A circuit breaker decides to stop calling a failing service; graceful degradation decides what the user sees instead.
- Rate limiting
A circuit breaker protects you from a dependency that is failing; rate limiting protects your service from callers sending too much.
- Health check
A circuit breaker is the caller deciding to stop calling a dependency that keeps failing; a health check is the platform testing each copy of a service and sending it no traffic while it fails.