Subsystem 01
Edge security proxy
Anycast DDoS absorption, TLS termination and WAF rules
Typical stack
Cloudflare Enterprise / AWS WAF
Reference architecture
Protect backend APIs from scraping, credential stuffing and volumetric DDoS attacks with token-bucket rate limiting at the edge.
Design constraints
Targets for the scenario this reference is sized for. A real engagement starts by replacing them with your own numbers.
Component topology
Subsystems with separate responsibilities, clear contracts between them and storage that scales on its own. The stack named for each is typical, not mandatory.
Stack topology
Edge rate-limiting and DDoS mitigation architecture
Illustrative reference architecture
Edge security proxy
Anycast DDoS absorption, TLS termination and WAF rules
Cloudflare Enterprise / AWS WAF
Rate-limiting gateway
Checks token-bucket allowances and rejects excess traffic with HTTP 429
Envoy Proxy / Traefik
Distributed counter store
In-memory sliding-window counters
Redis Cluster / Upstash
Security analytics (SIEM)
Bot detection and IP reputation scoring
Datadog Security / CloudWatch
Subsystem 01
Anycast DDoS absorption, TLS termination and WAF rules
Typical stack
Cloudflare Enterprise / AWS WAF
Subsystem 02
Checks token-bucket allowances and rejects excess traffic with HTTP 429
Typical stack
Envoy Proxy / Traefik
Subsystem 03
In-memory sliding-window counters
Typical stack
Redis Cluster / Upstash
Subsystem 04
Bot detection and IP reputation scoring
Typical stack
Datadog Security / CloudWatch
Data lifecycle
A client sends a request with Authorization: Bearer <key> to the API gateway.
Cloudflare WAF checks IP reputation and passes clean requests to the Envoy gateway.
Envoy runs a Lua script and Redis pipeline that evaluates the sliding window in a single round trip.
Over the tier limit, the gateway returns HTTP 429 Too Many Requests with a Retry-After header.
Allowed requests pass to the backend service, and Redis increments the counter with an automatic TTL.
Reliability and resilience
Failure mode 01
Mitigation
Fail open (allow requests) when Redis takes longer than a 5 ms timeout, so the limiter can't cause an outage.
Failure mode 02
Mitigation
Fingerprinting heuristics (JA4 TLS fingerprints, canvas hashes) throttle bots even as their IPs change.
Failure mode 03
Mitigation
Sliding-window logs with jitter, so clients don't all retry on the minute boundary.
Questions
A token bucket allows short bursts while holding an average rate. A sliding window prevents the spike that fixed one-minute windows allow at their boundary.
Every 429 carries a Retry-After header, and every response carries the widely used X-RateLimit-Limit, X-RateLimit-Remaining and X-RateLimit-Reset headers, or the IETF draft RateLimit headers if your clients support them.
Send us your requirements, expected load and budget. We'll reply within one business day with an honest read on the design, and on whether we're the right team to build it.