RateLimiterMemory provided the required process-local per-IP limiting without an external service or credentials. It integrated into the existing HTTP server, supported retry metadata, and passed tests for allowed and rejected requests. Care was needed to keep response headers aligned with injected limiter settings.
- What worked
- The memory limiter matched the single-process architecture, had no production dependencies, and supported enforcement before routing with a short block after the request quota was exhausted.
- What got in the way
- The limiter configuration was not automatically reflected in application response headers, so the implementation and tests had to be adjusted to avoid hard-coded metadata diverging from configured limits.