
ArokoDB — Embedded Vector Database
Embedded vector search engine delivering <12ms recall across 100k 768-dim vectors using Rust and mmap storage.
P99 Proxy Latency Overhead
1.8 ms
Max Sustainable RPS (Single Node)
28,500 RPS
Memory Footprint at 10k Connections
85 MB
Works on
Built with
01 / The Problem & Hard Constraints
Standard reverse proxies like NGINX are exceptional for static routing, but adding dynamic bot mitigation, payload inspection, and distributed rate-limiting often introduces unacceptable latency.
02 / Architecture & Core Design Decisions
03 / Deep Technical Challenges & Solutions
The Challenge: Thread Blocking on Malicious Payload Inspection. Running Regex-based WAF (Web Application Firewall) rules on incoming JSON payloads was causing CPU spikes, blocking the async event loop, and starving healthy connections.
The Solution: Bounded Execution and Streaming Parsers. Instead of loading the entire payload into memory to run Regex, I implemented a streaming JSON state machine. The shield inspects the byte stream in chunks as it arrives over the socket. If a malicious signature (e.g., SQL injection vectors or buffer overflow padding) is detected in the stream, the socket is immediately terminated (TCP RST) before the rest of the payload is even downloaded, saving massive CPU cycles and memory bandwidth.
04 / Post-Mortem & Next Steps
Benchmarks
Simulated load-test metrics using wrk2 on a 4-core, 8GB instance.
| Metric | Standard API Gateway (e.g., Kong DB-less) | Eruption (Rust + Async Sync) |
|---|---|---|
| P99 Proxy Latency Overhead | 4.5 ms | 1.8 ms |
| Max Sustainable RPS (Single Node) | ~14,000 RPS | 28,500 RPS |
| Memory Footprint at 10k Connections | ~350 MB | 85 MB |
| Rate-Limit Evaluation Time | 1.2 ms (Redis Block) | 0.05 ms (L1 Atomic Cache) |