System Design Basics for Backend Developers · 课时

熔断器与优雅降级

学习熔断器如何防止级联故障,以及优雅降级如何让系统在依赖项发生故障时仍保持可用。

第 4 / 4 课13 个步骤

熔断器与优雅降级 是 CoddyKit 上的免费 System Design Basics for Backend Developers 课时。 这是第 4 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 System Design Basics for Backend Developers 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 System Design Basics for Backend Developers 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

The Cascading Failure Problem

In a system of dependent services, one slow service can drag down everything that calls it. Threads pile up waiting, queues fill, and the failure cascades across the whole system.

High availability means containing failures, not just preventing them.

What a Circuit Breaker Does

A circuit breaker wraps calls to a dependency. When failures cross a threshold, it opens and fails fast instead of waiting on a dead service.

  • Stops wasting threads on doomed calls
  • Gives the failing service time to recover

The Three States

A circuit breaker has three states:

  • Closed: calls flow normally, failures are counted
  • Open: calls fail immediately without hitting the dependency
  • Half-open: a few trial calls test whether the dependency recovered
CLOSED --(too many failures)--> OPEN
OPEN --(timeout elapsed)--> HALF_OPEN
HALF_OPEN --(trial succeeds)--> CLOSED
HALF_OPEN --(trial fails)--> OPEN

A Simple Breaker in Code

Here is the core idea: count failures, trip when a threshold is reached, and refuse calls while open.

class Breaker:
    def __init__(self, limit):
        self.fails = 0
        self.limit = limit
        self.open = False
    def call(self, ok):
        if self.open:
            return 'rejected'
        if ok:
            self.fails = 0
            return 'success'
        self.fails += 1
        if self.fails >= self.limit:
            self.open = True
        return 'failure'

b = Breaker(3)
for ok in [False, False, False, True]:
    print(b.call(ok))

Timeouts Are Essential

A breaker only helps if calls have timeouts. Without a timeout, a hung dependency holds a thread forever and failures are never counted. Always set aggressive, explicit timeouts on remote calls.

Retries and Backoff

Retries can help with transient errors but can also amplify an overload. Use exponential backoff with jitter and cap the retry count. Combine with a circuit breaker so retries stop entirely when the circuit is open.

import random
delay = 1
for attempt in range(4):
    wait = delay + random.uniform(0, delay)
    print('attempt', attempt, 'wait', round(wait, 2))
    delay *= 2

Graceful Degradation

Graceful degradation means the system still does something useful when a dependency is down, instead of returning an error.

  • Serve stale cached data
  • Hide a non-critical feature
  • Return a sensible default

Fallbacks

When the breaker is open, route to a fallback. For a product page, if the recommendations service is down, show a generic best-sellers list instead of failing the whole page.

def get_recommendations(breaker):
    if breaker.open:
        return ['bestseller-1', 'bestseller-2']
    return ['personalized-1', 'personalized-2']

Bulkheads

The bulkhead pattern isolates resources so one failing dependency cannot consume all threads or connections. Give each downstream dependency its own bounded pool — like watertight compartments in a ship.

Load Shedding

Under extreme load, it is better to reject some requests quickly than to slow down for everyone. Load shedding drops low-priority traffic to protect critical paths and keep latency bounded.

Putting It Together

Resilient services layer these patterns: tight timeouts, circuit breakers, bulkheads to isolate, fallbacks for degradation, and load shedding under pressure. Together they turn a potential outage into a minor, contained blip.

Quick Check

Test your understanding of circuit breakers.

Recap

You learned to contain failures for high availability:

  • Circuit breakers fail fast and cycle through closed, open, and half-open
  • Timeouts and capped backoff retries prevent overload amplification
  • Graceful degradation and fallbacks keep the system useful
  • Bulkheads and load shedding isolate and protect critical paths
免费开始

用 AI 导师学习 System Design Basics for Backend Developers — 免费

在浏览器中编写并运行真实代码,获得全天候 AI 导师的即时帮助,并在网页或应用中继续学习。

课程
12
课程
48

常见问题解答

「熔断器与优雅降级」课时是免费的吗?

是的 — 「熔断器与优雅降级」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 System Design Basics for Backend Developers 课程的其余内容,请升级到 CoddyKit PRO。 System Design Basics for Backend Developers 课程共包含 4 节课。

「熔断器与优雅降级」这节课中我会学到什么?

学习熔断器如何防止级联故障,以及优雅降级如何让系统在依赖项发生故障时仍保持可用。 你通过在浏览器中直接运行的动手代码来练习 System Design Basics for Backend Developers,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 System Design Basics for Backend Developers 需要有经验吗?

无需任何先前经验。CoddyKit 上的 System Design Basics for Backend Developers 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 4 节课,共 4 节。

「熔断器与优雅降级」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 System Design Basics for Backend Developers 课中编写并运行代码吗?

能。每节 System Design Basics for Backend Developers 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. 冗余与故障转移机制
  2. 灾难恢复规划
  3. 监控、告警与日志记录
  4. 熔断器与优雅降级
← 返回 System Design Basics for Backend Developers