Circuit Breaker Lab (Interactive)
Send request batches through CLOSED, OPEN, and HALF-OPEN while tuning failure threshold, window, and wait time. A real state machine: sliding-window failure-rate evaluation trips the breaker, a live cooldown countdown gates HALF-OPEN probe success, and fast-fail returns instantly while OPEN.
Resilience4j-style Circuit Breaker FSM
Tune failure-rate threshold, sliding window and reset timeout; drive batches against a downstream whose health you control.
› CLOSED: monitoring a sliding window of the last 50 calls.
How It Works Under the Hood
A circuit breaker is a three-state finite machine protecting callers from hung dependencies. CLOSED counts failures in a sliding window and trips to OPEN when the failure rate crosses the threshold; OPEN rejects every request immediately with a fallback, stopping thread, socket, and memory buildup against the dying service. After the wait duration it admits a bounded set of HALF-OPEN probes: pass them and the breaker heals to CLOSED, fail them and it reopens. Tuning is a balance — a sensitive breaker trips on transient jitter, a lazy one lets the downstream collapse consume your thread pool first.
Core Architectural Principles
- Failure-rate threshold over a sliding request window decides when CLOSED flips to OPEN.
- OPEN fast-fails every batch; a real-time cooldown counts down before HALF-OPEN admits limited probes.
- Half-open probe success rate decides recovery to CLOSED or relapse to OPEN, with every trip logged.
Describe the three states and transitions precisely, then add the details that separate seniors: trip on failure rate not consecutive count to avoid flapping, count only requests after the window fills, and fast-fail must return a fallback, not just an error. Pair the breaker with bulkheads and note HALF-OPEN should admit a small capped probe volume.
Instant caller protection and self-healing recovery versus false trips on jitter and the risk of probing a wounded service.