Why Spring Cloud Gateway Rate Limiting Fails to Protect Downstream Services
The article analyzes five reasons why Spring Cloud Gateway's Redis-based token bucket rate limiting fails to protect downstream services during traffic bursts, including QPS vs. concurrency confusion, burstCapacity spikes, multi-route quota multiplication, KeyResolver fallback flaws, and Redis bottleneck fail-open behavior, then recommends tightening burst limits, adding downstream concurrency isolation with Sentinel/Resilience4j, and hardening KeyResolver configuration.
