---
title: "Multi-Tier Distributed Rate Limiter with Sliding Window Counter | Distributed Systems Architecture Canon"
description: "High-throughput edge rate limiting architecture combining local memory token buckets with Redis sliding-window log coordination to enforce multi-tenant quotas with sub-millisecond overhead."
image: "https://tinycto.tv/assets/distributed-systems/distributed_systems_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/distributed-systems/architectures/distributed-token-bucket-rate-limiter"
locale: "en"
---

# Multi-Tier Distributed Rate Limiter with Sliding Window Counter (`arch-distributed-token-bucket-rate-limiter`)

> **Architectural Pillar**: FLOW_BACKPRESSURE | **Archetype**: REACTIVE_FLOW_CONTROL
> **PACELC**: PA/EL | **Consensus Protocol**: None

High-throughput edge rate limiting architecture combining local memory token buckets with Redis sliding-window log coordination to enforce multi-tenant quotas with sub-millisecond overhead.

### 3 Maturity Target Configurations

#### 1. Initial Target: 10,000 checks/sec

- **Guarantees**: Redis Atomic Lua Script Rate Limiting
- **Infrastructure Topology**: API Gateway calls Redis Lua script on each request.
- **Operational Trade-Off**: Redis single-thread bottleneck limits total cluster rate-check throughput.

#### 2. Scaled Target: 120,000 checks/sec

- **Guarantees**: Two-Tier Local Token Leases + Redis Sliding Window Log
- **Infrastructure Topology**: Envoy sidecars cache batches of tokens locally; periodically sync aggregate usage with Redis Cluster.
- **Operational Trade-Off**: Slight potential over-burst (1-2%) if multiple pods consume their local batch simultaneously.

#### 3. Ultra-Scale Target: 2,000,000 checks/sec

- **Guarantees**: Kernel eBPF Token Bucket Filter with Hardware Offload
- **Infrastructure Topology**: Packets dropped directly at the Linux network driver level (XDP) before reaching TCP stack if IP/token is exceeded.
- **Operational Trade-Off**: Requires direct eBPF kernel program development and maintenance.

### Handled Failure Modes

- `DS-FAIL-08: Thundering Herd Cache Stampede`
- `DS-FAIL-11: Unbounded In-Flight Queue Exhaustion`


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Multi-Tier Distributed Rate Limiter with Sliding Window Counter",
  "description": "High-throughput edge rate limiting architecture combining local memory token buckets with Redis sliding-window log coordination to enforce multi-tenant quotas with sub-millisecond overhead.",
  "inLanguage": "en",
  "url": "https://tinycto.tv/distributed-systems/architectures/distributed-token-bucket-rate-limiter"
}
```
