Distributed Rate Limiting in Go: GCRA, Redis, and the Pitfalls Nobody Warns You About
Every production rate limiter has two layers. The first layer is the algorithm: token bucket, leaky bucket, fixed window, sliding
Every production rate limiter has two layers. The first layer is the algorithm: token bucket, leaky bucket, fixed window, sliding
# POST 1: Transactional Outbox (Slot 10 backend) You update a row in your database, then publish an event to
Continue readingThe Transactional Outbox Pattern in Go: Reliable Events Without Dual Writes
A request fails at 2 AM. The on-call engineer greps through logs looking for a trace ID, finds seventeen lines
Continue readingStructured Logging in Go With slog: Handlers, Sampling, and Dynamic Levels
PgBouncer has quietly become mandatory infrastructure for PostgreSQL at scale. If you run more than a few hundred client connections
Getting a request into your system is the easy part. The hard question arrives at hop two: when the order
Here is a failure mode that shows up in every system with more than two backends: round robin distributes requests
Continue readingLoad Balancing Beyond Round Robin: Least Outstanding Requests and Consistent Hashing
Server-Side Request Forgery (SSRF) keeps topping real-world breach reports for a simple reason: modern applications are glued together with outbound
Continue readingSSRF Defense in Go: Why URL Validation Fails and How to Fix It at the Dial Layer
Goroutines are famously cheap. You can scatter a hundred thousand of them across a program without thinking twice, and the
Continue readingInside the Go Scheduler: G, M, P, Work Stealing, and Preemption
You open your tracing backend to debug a slow checkout request and find five disconnected traces instead of one. Five
At 02:14 on a Sunday, an alert fires: payment success rate dropped four percent. You run kubectl logs across a