Home/Labs/Cache Stampede Defense Arena
All 280 Labs
INTERACTIVE LAB🦓

Cache Stampede & Thundering Herd Defenses Lab (Interactive)

Expire a viral hot key, fire thousands of concurrent misses, and count the identical queries your defense lets through. Stage a stampede against the database and measure mutex locking, stale-while-revalidate, and XFetch probabilistic early refresh against none.

Cache Stampede Defense Arena

Expire a viral hot key, unleash the burst, and count exactly how many identical queries hit the database.

Defense Strategy

XFetch rule (β=1, δ=40ms)
recompute if −β·δ·ln(r) > TTL_remaining
r=0.01 → refresh window ≈ 184 ms before expiry
DB queries from burst
0
coalesced by defense
DB busy time (1s window)
—
pool = 100 conns
Stale reads served
—
staleness is the price of safety
Event log

› Key homepage:breaking_news is warm, serving 10k+ QPS from Redis at 0.5ms. TTL countdown has started.

› Meltdown math: time_to_clear = ⌈misses ÷ 100 pool slots⌉ × 40ms

Without protection, TTL expiry on a hot key is a self-inflicted DDoS on your own database — the misses are perfectly synchronized.

How It Works Under the Hood

When a hot key serving 10,000 QPS expires, every in-flight request discovers the miss in the same millisecond and fires the same expensive SQL at the primary: pool exhaustion, timeouts, cascading outage. Distributed mutexes (SET lock NX PX) let exactly one worker rebuild while others sleep or serve stale. Stale-while-revalidate returns the old value instantly behind one background refetch. XFetch, from the 2015 VLDB paper and Vimeo’s production fleet, uses -β·δ·ln(random) against remaining TTL so a lucky reader refreshes probabilistically before expiry — the key never actually dies.

Core Architectural Principles

  • Stampede math: N concurrent misses × heavy-query time queues against the pool; crash when backlog exceeds the timeout budget.
  • Mutex single-flight admits exactly 1 DB query per expiry; waiters pay ~50ms sleep for strict protection.
  • XFetch refreshes before TTL hits zero using computation time δ, giving zero user-visible misses at the cost of tracking δ.
Interview Round Script

Any design with TTLs on hot keys must answer "what happens at expiry?" out loud: "10,000 QPS on one expiring key is a self-inflicted DDoS — I’d guard with SET NX single-flight, and layer XFetch or stale-while-revalidate for zero-latency refresh." Naming the VLDB probabilistic-early-expiration paper and Vimeo’s deployment signals production-level cache experience.

Key Trade-Offs

Strict mutexes protect the database but add waiter latency, while stale-serving tricks hide latency at the price of brief untruthfulness.

Related Curriculum Chapter

Cache Stampede & Thundering Herd Defenses

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs