Sheet 04

API Gateway & Edge Layer

Edge routing, rate limiting token bucket, JWT auth verification, and WebSocket / SSE connection sizing.

Sized Gateway Pods9 Pods (N+1 in 3 AZs)

Pod Sizing & Capacity

Peak RPS Target6,667 req/s
Effective RPS / Pod (60% CPU)1800 req/s
Raw Pods Needed4 pods
Multi-AZ Allocation (3 AZs)9 pods
Total Gateway vCPUs36 cores

JWT & Cryptography

JWT Verifications6,667 ops/s
Crypto Verification CPU3.3 dedicated cores
JWKS Public Key Cache1 KB in RAM
Gateway Overhead Added3.5 ms
WAF Rules Evaluated20 rules / req

WebSocket & SSE Sizing

WebSocket Sockets (5% PCU)20,000 conns
SSE Streams (10% PCU)40,000 streams
WS Socket Buffer RAM1250 MB
Rate Limit Redis Ops13,333 ops/s
Sliding Window RAM381.5 MB

Multi-Tier Token Bucket Rate Limit Policy

TierRate LimitWindow StrategyBurst HeadroomTarget Workload
Anonymous10 RPM60s sliding15 reqPublic catalog browsing
Authenticated User100 RPM60s sliding150 reqOrder checkout, account
Premium / API Partner500 RPM60s sliding1000 reqMerchant inventory sync

API Gateway Formulas & Derivations

1. Effective RPS / Instance

Gateway_RPS_Capacity × (Gateway_CPU_Util_Target / 100)

2. Raw Gateway Instances

CEIL(Peak_RPS / Gateway_Effective_RPS)

3. Total Sized Pods (N+1 Multi-AZ)

(CEIL(Raw_Pods / 3) + 1) × 3 AZs

4. Gateway Latency Added (ms)

Gateway_Overhead_ms + (SSL_Handshake_ms × SSL_Rate_Pct / 100)

5. Rate Limiter Redis Ops/s

Peak_RPS × 2 (Token bucket lookup + increment)

6. JWT Verification CPU Cost (cores)

Peak_RPS × 0.5ms / 1000

7. WebSocket Socket Buffer RAM (MB)

WS_Concurrent × 64 KB / 1024