HyperEdge Gateway

Zero-Lock Distributed API Rate Limiter & Global Mesh Proxy

Role: Lead Architect & Systems Engineer•Timeline: 2025 - 2026•Category: Edge Infrastructure & Networking
Global P99 Latency
4.2ms
-82% vs AWS ALB
Infrastructure Cost
$240/mo
-88% cost reduction
Synthetic DDoS Absorption
45 Gbps
Zero dropped legit requests
Concurrent Edge Nodes
330+ PoPs
100% active-active

System Specifications

Architecture Pattern
Hierarchical Multi-Region Edge Proxy
Target Throughput
120,000 req/sec peak
Latency Profile
2.8ms global median
Availability SLA
99.999%
Storage Subsystem
Cloudflare D1 + Durable Objects Local Caches
Compute Runtime
Cloudflare Workers (V8 Isolate mesh)

The Engineering Challenge

Traditional rate-limiting architectures require centralized Redis instances that introduce 40-120ms roundtrip hops across cross-continental traffic, creating latency spikes and centralized single-points-of-failure under burst traffic.

The Architectural Solution

Designed a two-tiered token bucket architecture using Cloudflare Durable Objects as regional master synchronizers and worker-local in-memory bloom filters for fast-path 0ms verification. Non-malicious requests proceed with zero cross-region hops.

Implementation Details

Implemented sliding-window counter algorithm with cryptographic client fingerprinting.
Constructed autonomous mesh failover to local memory fallback if regional sync experiences packet loss.
Integrated live telemetry streaming into ClickHouse & Cloudflare D1 for real-time traffic visualization.
Benchmarked against 10M synthetic requests with zero memory leaks in V8 isolate lifecycle.
Technologies Used
Cloudflare WorkersDurable ObjectsTypeScriptCloudflare D1WebAssemblyRustClickHouse
edge-limiter.tstypescript
export async function verifyRateLimit(request: Request, env: Env): Promise<RateLimitResult> {
  const clientIp = request.headers.get('cf-connecting-ip') || '127.0.0.1';
  const colo = request.cf?.colo || 'DEF';
  
  // Fast path: In-memory local token cache
  const localTokens = getLocalBucket(clientIp);
  if (localTokens > 0) {
    decrementLocalBucket(clientIp);
    return { allowed: true, remaining: localTokens - 1, source: 'local-fastpath' };
  }

  // Coordinated path: Durable Object regional coordinator
  const id = env.LIMITER_DO.idFromName(colo + ':' + getIpSubnet(clientIp));
  const stub = env.LIMITER_DO.get(id);
  const response = await stub.fetch(request.url, { method: 'POST', body: JSON.stringify({ ip: clientIp }) });
  
  return await response.json<RateLimitResult>();
}

Technical Discussion (0)

Live on D1
Add Architectural Feedback / Question

Planning a Similar Distributed System?

Available for architecture advisory and technical design reviews.

Consult with Khaled →