Ch. 10 · Microservices

Microservice Circuit Breakers and Failure Isolation

Microservice Circuit Breakers and Failure Isolation. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Circuit breakers temporarily stop calls likely to fail, allowing bounded recovery probes. They complement deadlines and concurrency limits rather than replacing them.

Before you start

You should understand HTTP, database transactions and the difference between one process and independently failing services. Draw the participants and message direction before choosing a pattern. Include timeout, duplicate delivery and recovery in the model instead of considering only successful requests.

The practical goal is to reason through this situation: Repeated upstream failures open the circuit and produce a controlled fallback. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Bound individual calls

Timeouts and concurrency limits protect resources before breaker decisions matter.

Step 2: Define opening criteria

Track failures under a measured policy rather than one unexplained error.

Step 3: Probe recovery carefully

Permit limited half-open attempts and choose safe fallback semantics.

Worked scenario

Repeated upstream failures open the circuit and produce a controlled fallback.

A partner is failing quickly, so the breaker temporarily rejects new calls. After a delay, a small number of probes test recovery. Returning cached availability may be acceptable for browsing but unsafe for a purchase decision; fallback correctness must be defined per operation.

Common mistake

A breaker without a timeout still allows individual calls to hang.

Verify the behavior

Test hanging calls, repeated failures, half-open limits and recovery.

Interview exercise

Choose recovery behavior.

Answer and reasoning

Use limited half-open probes, measure actual failures and avoid a fallback that conceals incorrect or stale critical data.

Continue learning

Compare the scenario with the Microservices interview questions and test your understanding with the Microservices MCQs. For terminology and implementation details, consult the reference material.

More in Microservices

read ✓Microservices · hard

Microservices Anti-Corruption Layer

Protect a service's domain model from a foreign or legacy model with a translation layer at the boundary.

~2 min readread →
read ✓Microservices · hard

Microservices API Versioning and Evolution

Evolve service APIs without breaking consumers using additive changes, explicit versioning and consumer-driven contracts.

~2 min readread →
read ✓Microservices · hard

Microservices Backend for Frontend

Use a per-client BFF to aggregate services and shape responses, without letting it become a shared god service.

~2 min readread →
esc