[graphql-stream] Cap concurrent subscriptions with a configurable max_subscribers limit [23/n] - #27787
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
519e4f5 to
d3a5e41
Compare
d3a5e41 to
ebcb2a5
Compare
|
amnn
left a comment
There was a problem hiding this comment.
Would consider allowing requests to wait a little bit for a semaphore token, but broadly looks good, thanks @tpham-mysten
ebcb2a5 to
9e11fc9
Compare
|
Thanks @amnn! Doing this on the GraphQL server side is probably not the right place, mainly because it's tricky to decide which request we should hold. From the infra side, I think the per-IP rate limit should be partially sufficient to prevent it. |
|
I think if we take the view that we should not be hitting this limit under normal operation, and we can rely on health checks and auto-scaling, then I can get behind this (but then we should probably set a more generous upper limit at this layer and leave the more conservative limit for the gateway to enforce). |
Description
Subscriptions currently open without any aggregate limit, so a burst of subscribers can drive server CPU and memory unbounded. This adds a configurable
max_subscribers(default 1024): each subscription claims a slot from a shared semaphore held for its lifetime by the lifecycle guard, and a subscription opened while all slots are taken is refused with aresource_exhaustederror so the client can retry later. Refusals are counted bygraphql_subscription_rejected{type, reason}.Guard creation moves out of the driver
stream!bodies up to the resolver, so admission happens once at connect time before any work begins.Test plan
New
rejects_at_capacityunit test covers admission, the at-capacity refusal and its metric, and slot release on drop. Existing subscription lib tests cover the guard threaded through the drivers.Stack
Release notes
Check each box that your change affects. If none of the boxes relate to your changes, release notes aren't required.
For each box you select, include information after the relevant heading that describes the impact of your changes that a user might notice and any actions they must take to implement updates.