Interactive noteSystemsOct 2026 · 7 min

Backpressure is a contract

Every queue will be full one day. Backpressure is deciding, in advance, what happens then, and telling the producer.

Scroll to advance. The figure keeps running while you read.

{{ t.k }}
Fig. 3.4
{{ statLabel }} {{ stat }}
01 · Two speeds

A producer creates 120 jobs a second. The consumer finishes 100. On a dashboard both look healthy.

02 · The gap

Twenty jobs a second stay behind. After an hour that is 72,000 jobs, and every new job waits behind all of them. Latency grows without anything failing.

03 · Unbounded is a lie

An unbounded queue doesn't remove the limit. It moves it to memory, and then to the moment the process is killed and everything in it is lost at once.

04 · Bound it

Give the queue a capacity. In the figure it holds 8. When it is full, something has to give, and choosing what is the contract.

05 · Option 1: block

The producer waits until there is room. Its own callers slow down, and the pressure travels upstream to someone who can do something about it.

06 · Option 2: shed

Reject new work with 429 or 503 and a Retry-After header. The caller finds out now, instead of after a 30-second timeout.

07 · Option 3: drop

Throw away the oldest or the newest, or sample. Fine for metrics and logs. Never for payments. The data decides which option is allowed.

08 · The contract

Every queue has to answer two questions: how deep can I get, and what happens when I'm full? If nobody wrote the answers down, they get decided during the incident.

Three things to keep
boundedor the limit is just hidden in memory.
upstreamis where pressure can actually be handled.
2answers, written down before the incident.
← A deadlock, slowly Found a mistake? Tell me and I'll fix it. Next: Where old rows go →