Sheet 12

Traffic Spikes, Autoscaling & DDoS

Side-by-side scenario modeling, auto-scaling cooldown math, and priority load-shedding hierarchy.

Load Shed Threshold67,050 req/s (90% Cap)

Side-by-Side Scenario Comparison Matrix

Computed live across all 5 models
MetricNormal Flash Sale Black Friday Cyber Monday DDoS
Spike Multiplier1x5x10x15x100x
Peak API RPS6,66733,33366,667100,000666,667
Gateway Pods (N+1 AZ)9 pods12 pods27 pods39 pods24 pods
Total App Fleet Pods29 pods32 pods47 pods59 pods44 pods
Kafka Brokers3 nodes3 nodes3 nodes3 nodes3 nodes
Actual Database QPS4,800 QPS10,800 QPS30,000 QPS43,200 QPS24,000 QPS
Monthly Infra Cost$16,472$23,629$42,531$54,644$28,078

Graceful Degradation: 5-Tier Priority Load Shedding Ladder

P1 (NEVER shed)

Payment processing, Order placement, Auth verification

Sheds at: Never (100% Guaranteed)
P2 (Shed last)

Cart modifications, Checkout reviews, Inventory reserve

Sheds at: 95% Cluster Capacity
P3 (Standard)

Search auto-complete, Recommendations, Related items

Sheds at: 80% Cluster Capacity
P4 (Non-critical)

Customer reviews, Q&A sections, Image high-res zoom

Sheds at: 70% Cluster Capacity
P5 (Shed first)

Real-time analytics, Personalized banners, Audit tracking

Sheds at: 60% Cluster Capacity

7-Layer Deep DDoS Defense Architecture

L1: Edge Scrubbing

CloudFront & Cloudflare Anycast DDoS absorption (100+ Tbps capacity)

L2: AWS WAF

Rate-based rules (e.g. 2000 req/5min per IP), SQLi/XSS managed rule sets

L3: L4 Network LB

SYN flood absorption, connection limits, TLS termination offload

L4: API Gateway

Redis token bucket rate limiter (10/100/500 RPM tiers)

L5: Service Mesh

Envoy circuit breakers per backend service with outlier detection

L6: Bulkheads

Max concurrent thread pools isolating Payment from Search traffic

L7: DB Connection Pools

PgBouncer strict max client bounds to fail fast instead of queueing