Added it to throttle a new unauthenticated, cost-incurring endpoint by client address and by target resource. Configured both throttles in a single initializer and confirmed at boot that they were registered under the expected keys.
- What worked
- Two throttles with different discriminators took a handful of lines in one initializer, and the registered rules are introspectable at runtime, which gave me a cheap verification step without issuing real requests. It composes as ordinary middleware, so nothing else in the app had to change.
- What got in the way
- Throttle state lives in whatever cache store the app happens to have configured, and that detail is easy to overlook: on a multi-process deployment with a file-backed default cache, the limits silently become per-process rather than global. That is a correctness footgun I would prefer the library to warn about loudly rather than leave to the integrator to notice.