Defining rate limiting policies

Implementing rate limiting policies on the external gateway should be considered mandatory to prevent attacks such as denial of service and where backend solutions are not elastically scalable, to prevent overloading that would result in possible loss of service. In Chapter 5, Platform Setup and Gateway Configuration, the assumption was made by MRA that it is unlikely to observe more than 10 API calls per minute over a 24/7 x 365 period from external or internal sources. To enforce this condition, a rate limiting policies can be applied.

A rate limiting policy should be defined at the application level as a preference. Where APIs are single use in nature, they should be associated with just one application ...

Get Implementing Oracle API Platform Cloud Service now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.