System Design Basics for Backend Developers · レッスン

サーキットブレーカーとグレースフルデグラデーション

サーキットブレーカーで障害の連鎖を防ぎ、依存先に障害が起きてもシステムを有用な状態に保つグレースフルデグラデーションを学びます。

レッスン 4/413 ステップ

「サーキットブレーカーとグレースフルデグラデーション」はCoddyKit上の無料System Design Basics for Backend Developersレッスンです。 これはレッスン4/4です。 下記で完全なレッスンを無料で読むことができます。その後、ブラウザ内の組み込みコードエディタと24時間対応のAIチューターでハンズオン演習できます。 これはSystem Design Basics for Backend Developers学習パスの一部であり、ウェブとCoddyKitアプリ全体で進捗が同期されます。 System Design Basics for Backend Developersコースには全4レッスンが含まれています。

このレッスンの一部はまだ翻訳されておらず、英語で表示されています。

The Cascading Failure Problem

In a system of dependent services, one slow service can drag down everything that calls it. Threads pile up waiting, queues fill, and the failure cascades across the whole system.

High availability means containing failures, not just preventing them.

What a Circuit Breaker Does

A circuit breaker wraps calls to a dependency. When failures cross a threshold, it opens and fails fast instead of waiting on a dead service.

  • Stops wasting threads on doomed calls
  • Gives the failing service time to recover

The Three States

A circuit breaker has three states:

  • Closed: calls flow normally, failures are counted
  • Open: calls fail immediately without hitting the dependency
  • Half-open: a few trial calls test whether the dependency recovered
CLOSED --(too many failures)--> OPEN
OPEN --(timeout elapsed)--> HALF_OPEN
HALF_OPEN --(trial succeeds)--> CLOSED
HALF_OPEN --(trial fails)--> OPEN

A Simple Breaker in Code

Here is the core idea: count failures, trip when a threshold is reached, and refuse calls while open.

class Breaker:
    def __init__(self, limit):
        self.fails = 0
        self.limit = limit
        self.open = False
    def call(self, ok):
        if self.open:
            return 'rejected'
        if ok:
            self.fails = 0
            return 'success'
        self.fails += 1
        if self.fails >= self.limit:
            self.open = True
        return 'failure'

b = Breaker(3)
for ok in [False, False, False, True]:
    print(b.call(ok))

Timeouts Are Essential

A breaker only helps if calls have timeouts. Without a timeout, a hung dependency holds a thread forever and failures are never counted. Always set aggressive, explicit timeouts on remote calls.

Retries and Backoff

Retries can help with transient errors but can also amplify an overload. Use exponential backoff with jitter and cap the retry count. Combine with a circuit breaker so retries stop entirely when the circuit is open.

import random
delay = 1
for attempt in range(4):
    wait = delay + random.uniform(0, delay)
    print('attempt', attempt, 'wait', round(wait, 2))
    delay *= 2

Graceful Degradation

Graceful degradation means the system still does something useful when a dependency is down, instead of returning an error.

  • Serve stale cached data
  • Hide a non-critical feature
  • Return a sensible default

Fallbacks

When the breaker is open, route to a fallback. For a product page, if the recommendations service is down, show a generic best-sellers list instead of failing the whole page.

def get_recommendations(breaker):
    if breaker.open:
        return ['bestseller-1', 'bestseller-2']
    return ['personalized-1', 'personalized-2']

Bulkheads

The bulkhead pattern isolates resources so one failing dependency cannot consume all threads or connections. Give each downstream dependency its own bounded pool — like watertight compartments in a ship.

Load Shedding

Under extreme load, it is better to reject some requests quickly than to slow down for everyone. Load shedding drops low-priority traffic to protect critical paths and keep latency bounded.

Putting It Together

Resilient services layer these patterns: tight timeouts, circuit breakers, bulkheads to isolate, fallbacks for degradation, and load shedding under pressure. Together they turn a potential outage into a minor, contained blip.

Quick Check

Test your understanding of circuit breakers.

Recap

You learned to contain failures for high availability:

  • Circuit breakers fail fast and cycle through closed, open, and half-open
  • Timeouts and capped backoff retries prevent overload amplification
  • Graceful degradation and fallbacks keep the system useful
  • Bulkheads and load shedding isolate and protect critical paths
無料で開始

AI チューターと学ぶ System Design Basics for Backend Developers — 無料

ブラウザでリアルコードを書いて実行し、24/7 の AI チューターから瞬時にサポートを受け、ウェブまたはアプリで続きから学習できます。

コース
12
レッスン
48

よくある質問

「サーキットブレーカーとグレースフルデグラデーション」レッスンは無料ですか?

はい。「サーキットブレーカーとグレースフルデグラデーション」の完全なテキストはこのウェブで無料で読めます。インタラクティブに演習し(組み込みコードエディタと24時間対応のAIチューター)、System Design Basics for Backend Developersコースの残りをアンロックするには、CoddyKit PROにアップグレードしてください。 System Design Basics for Backend Developersコースには全4レッスンが含まれています。

「サーキットブレーカーとグレースフルデグラデーション」で何を学びますか?

サーキットブレーカーで障害の連鎖を防ぎ、依存先に障害が起きてもシステムを有用な状態に保つグレースフルデグラデーションを学びます。 ブラウザで直接実行するハンズオンコードでSystem Design Basics for Backend Developersを演習し、24時間対応のAIチューターがレッスンを進める中での質問に答えます。

System Design Basics for Backend Developersを始めるのに経験は必要ですか?

事前経験は必要ありません。CoddyKitのSystem Design Basics for Backend Developersは初級者から上級者向けに構成されているため、ここから始めるか最初から始めて、自分のペースで進むことができます。 これはレッスン4/4です。

「サーキットブレーカーとグレースフルデグラデーション」レッスンにはどのくらい時間がかかりますか?

ほとんどのCoddyKitレッスンは約5~10分かかります。各レッスンはコンパクトでインタラクティブなので、着実に進歩し、ウェブとアプリ全体で正確に前回の場所から再開できます。

このSystem Design Basics for Backend Developersレッスンでコードを書いて実行できますか?

はい。すべてのSystem Design Basics for Backend Developersレッスンに組み込みコードエディタが含まれているため、ブラウザでリアルコードを書いて実行し、即座のAIフィードバックを取得できます。ローカル設定は不要です。

このコースのすべてのレッスン

  1. 冗長化とフェイルオーバーの仕組み
  2. ディザスタリカバリ計画
  3. 監視、アラート、ロギング
  4. サーキットブレーカーとグレースフルデグラデーション
← System Design Basics for Backend Developersに戻る