FuzeFEATUREDLoad test at 75 users: a fail-closed JWT revocation check logged out valid users
ADOPTED
Load test at 75 users: a fail-closed JWT revocation check logged out valid users
Question
Method
Result
Numbers
- authenticated 401 rate at 75 users before fixgaps.md section 13; commit 764e2c6 message. Author-reported; no raw output committed.
- about 38% (approximate as written)
- failures at 75 users after fixgaps.md@764e2c6 line 401. Fail-open and pool 50 were applied together.
- 0 failures across 595 requests
- Redis pool sizegit show 764e2c6 -- backend/utils/redis_utils.py
- 20 to 50 connections
- median latency at 25 usersgaps.md section 13 (author-reported)
- under 100 ms, 0% failures
- median latency at 75 usersgaps.md section 13 (author-reported, laptop Docker VM of about 3.8 GB)
- 2-5 s
Evidence
- commit764e2c6 ↗run_production.py: fail-open check with a comment quoting the 38% figure. redis_utils.py: max_connections 20 to 50.
- filelocustfile.py@764e2c6 ↗Load script using pre-minted JWTs.
- docgaps.md@764e2c6 ↗Section 13 with the method and both runs.
- fileseed_loadtest_data.py@764e2c6 ↗NUM_USERS = 10, BOOKMARKS_PER_USER = 40; mints JWTs with create_access_token.
How this was checked: Read the run_production.py and redis_utils.py diffs, the locustfile and gaps.md section 13. Not re-run: needs Docker (daemon not running here) and Postgres+Redis. No regression test pins the fail-open behaviour (no 'revoked_jti' in tests). Numbers are from a laptop VM, so only the shape transfers to real hosting; the fail-open choice trades some revocation enforcement during Redis trouble for availability. Attribution: Commits 764e2c6, a74c00c and 491a221 carry a 'Co-Authored-By: Claude Sonnet 5' trailer, and gaps.md is an AI-written first-person document (it addresses the repository owner as 'you').
Recorded at the time (a document or commit message states it) · reasons are stated in the repository · commit 764e2c6