Magnus Mårtensson
Microsoft Regional Director, Azure MVP, CEO Loftysoft
Avirag Jain
Director & CTO R Systems
Mahesh Chand
Founder C# Corner, CEO Mindcracker
Chris Gali
CEO & Co-Founder Graphite
Subinder Khurana
Chief Architect StoryProcess, Founder NASSCOM DeepTech Club
Bryan Rishforth
Investor, Chairman Graphite
Bryn Everson
Director Biz Dev Graphite
Raj Tiwari
Digital Transformation Leader, Futurist and Visionary
Joseph Guadagno
Microsoft MVP, Lead Quicken Loans
Nikita Sachdev
Entrepreneur, Blockchain Enthusiast & Advisor, Social Media Influencer
Doug Wagner
COO & Founder Adapt Technical Group
Ritesh Modi
Architect, Senior Evangelist, Cloud Architect
Crystal Wenrick
Director Communications Mindcracker
Allen O’Neill
Microsoft MVP, Consulting Engineer/Architect
Praveen Kumar
CEO MCN Solutions
Chris Love
Founder Love2Dev, Microsoft MVP, Author
Sanjay Vyas
Microsoft Regional Director, Microsoft MVP, Founder & CEO SkillLabs Technologies
Veena Sarda
Deep Learning Consultant, Author
Sekhar Srinivasan
C# Corner MVP, Microsoft Certified Trainer, Pluralsight Author
Lalit Bansal
Founder & CEO - EIY SYS
Navdeep Garg
CEO Revinfotech
Prakash Tripathi
Tech Manager/Leader, Microsoft MVP, Blogger
Bhavna Jain
Breakthrough Consultant
Naveen Sharma
Enterprise Architect, Leadership Coach, Author
Vidya Vrat Agarwal
Principal Architect, Microsoft MVP, Author
Sheetal Agarwal
Founder Clownselors, Medical Clown, Trainer
Abhishek Kant
Founder GTM Catalyst
Vishnu Saran
Founder & CEO VoiceQube
Sandeep Soni
Founder & CEO Deccansoft, Microsoft Certified Trainer
Parveen Malik
AVP InfoSec & Vulnerability Management, Information Security Expert
Nitin Pandit
Microsoft MVP, Developer Evangelist, Author
Niloshima Srivastava
C# Corner MVP, Tech Architect, Trainer, Blogger
Bala Chirtsabesan
Senior Software Engineer at Microsoft, Author
Manoj Mittal
Sr. Technical Architect, C# Corner MVP, Author
Chandni Di
Co-Founder Voice of Slum
Vithal Wadje
Technical Lead, Microsoft MVP, Author
Shivam Ahuja
Founder SkillCircle, Business Mentor
Chervine Bhiwoo
Solution Architect, Microsoft MVP, Author
Saurabh Jain
Vice President Paytm, Founder Fun2Do Labs, Author
Vinay Solanki
Head IoT at Lenovo, Founder IoT-NCR
Anshu kumari
Founder Blockchainkids, Inventor, Trainer
Amit Singal
CEO Startup Buddy
Dev Pratap
Co-Founder & CEO Voice of Slum
Amey Vartak
Technology Consultant, Full Stack Developer, C# Corner MVP, Author
Viswanatha Swamy
Principal Software Engineer, C# Corner MVP, Author
Sanket Verma
Research Engineer @ Ballistics (Forensics) and Chair, PyData Delhi
Sourabh Somani
Lead Developer, Microsoft MVP, Author
Abhishek Mishra
Software Architect, C# Corner MVP, Author
Siddharth Vaghasia
Technical Consultant, C# Corner MVP, Blogger
Bassam Alugili
Senior Software Specialist, Database Expert
S Ravi Kumar
Solution Architect, C# Corner MVP, Author
Sundaram Subramanian
Full Stack Developer, C# Corner MVP, Speaker
Deepesh Somani
Solution Architect, Microsoft MVP, Author
Debasis Saha
Technical Project Manager, C# Corner MVP, Blogger, Author
Vipul Jain
Software Architect, C# Corner MVP, Author
Akshay Patel
Technical Architect, Microsoft Certified Trainer, C# Corner MVP, Author
Stephen Simon
RPA Developer, Evangelist, Author
Vivek Sharma
Founder Kingster636, AR/VR Specialist
Jeetendra Gund
Technical Lead, C# Corner MVP, Author
Sujal Beniwal
AI Enthusiast, Student
M Viknaraj
Microsoft MVP, Azure Architect, Author
Prasham Sabadra
Software Architect, C# Corner MVP, Trainer, Author
Aakash Maurya
Senior Developer, C# Corner MVP, Speaker
Ankit Sharma
Senior Software Engineer, C# Corner MVP, Author
Mangesh Gaherwar
Team Lead, C# Corner MVP, Author
Viral Jain
Technical Consultant, C# Corner MVP, Author
Bhasker Das
Solution Architect, Evangelist
Manish Dwivedi
Associate Project Manager
Ck Nitin
Programmer, Author
Rohit Gupta
Technical Trainer, Author
Manish Tewatia
Full-stack Marketer, UX Designer
Bhavya Gaur
Technical Illustrator
Rohit Tomar
SEO/SMO Expert
Web Track
Cloud & Data Track
Dev Track
Registration & Breakfast
Future of Desktop Apps with JS (ElectronJs)
Nitin Pandit
Building Serverless Microservices Using Microsoft Azure
Vithal Wadje
Innovating RPA: A Robot for Every Person
Stephen Simon
Managing Cloud Storage Accounts using Logic Apps
Viknaraj Manogararajah
Data visualization using Python
Sekhar Srinivasan
Going Cross platform with AR Foundation
Vivek Sharma
Keynote
Managing your Azure dependencies in ASP.NET Core apps using VS
Bala Chirtsabesan
Securing Applications on Intelligent Azure
Abhishek Mishra
Getting started with Blazor the Framework of Future
S Ravi Kumar
Lunch
Build Progressive Web Apps using Angular 9
Debasis Saha
Build and deploy to any platform using Azure DevOps
Chervine Bhiwoo
Deep Dive in Azure Service Bus
Akshay Patel
Build a Native Mobile Application using React Native and JavaScript
Joseph Guadagno
Making sense of Web Job, Web Job SDK and Functions in Azure
Prakash Tripathi
CloudFront Distribution in AWS
Viral Jain
Tea Break
Introduction to PowerBI
Aakash Maurya
Build Advanced SPFx solutions with React and Graph API
Siddharth Vaghasia
Build Business Intelligence Analyst (BIA) Skills
Sundaram Subramanian
Deep dive of Power Platform – AI BUILDER
Prasham Sabadra
Panel 1
What's new in SharePoint development
Vipul Jain
Build a SSO (Single Sign On) based Native JavaScript application with Microsoft Identity within 10 minutes
Manoj Mittal
Panel 2
Applications and working of AI
Veena Sarda
Deploying serverless API's with .Net core 3.0 on AWS & Azure
Amey Vartak
Panel 3
Blockchain with .NET Core (Ark)
Anshu Kumari
Closing Note & Prize Distribution
Dev Track
Cloud Track
Architecture Track
Emerging Tech Track
Registration & Breakfast
Creating Full-Stack Web Apps Using Server-Side Blazor
Ankit Sharma
Real time face recognition with MS Cognitive Services
Niloshima Srivastava
Building Scalable APIs with GraphQL
Jeetendra Gund
Future of development with AI and Blockchain
Navdeep Garg
Debugging Tips and Tricks with Visual Studio 2019
Joseph Guadagno
Azure Containers
Abhishek Kant
Enterprise Architecture
Naveen Sharma
Bot Framework - learn it fast and look like a boss!
Allen O’Neill
Keynote
.Net Core & C# 8 Performance
David McCarter
Working with Azure kubernetes services
Ritesh Modi
Becoming an Architect
Vidyavrat Agarwal
Why Techies Need to Learn Product Management
Saurabh Jain
Lunch
Build a rules engine in .Net Core
Sanjay Vyas
Building CI and CD Pipeline using Azure DevOps
Sandeep Soni
Entity Framework Core - Tips and Tricks, Performance Optimization, and Tuning
Bassam Alugili
Hacking your way into Data Science
Sanket Verma
Speed up your .Net Core Website
Sourabh Somani
Azure
Magnus Mårtensson
Demystifying Open Distro for Elasticsearch
Suman Debnath
Future of Data
Shivam Ahuja
Tea Break
gRPC with C# and .Net Core
Mangesh Gaherwar
Panel 1
Essentials of Cloud security
Parveen Malik
Power platform and Dynamics 365
Deepesh Somani
Microservices - the gRPC Way
Viswanatha Swamy
Panel 2
Reserved
Reserved
Closing Note & Prize Distribution
Practical rate limiting patterns for ASP.NET Core APIs
Public-facing APIs hosted in Australian data centres often experience sharp traffic spikes between 9am and 11am AEST, when Sydney and Melbourne offices start their day and queued batch jobs finally fire off accumulated requests. A well-tuned rate limiter keeps these bursts from overwhelming downstream services, throttles abusive clients, and gives backend teams predictable load. For organisations bound by the Privacy Act 1988, predictable throughput also reduces the chance of cascading failures that could trigger a notifiable data breach.
Rate limiting sits at the edge of an ASP.NET Core pipeline, where each incoming request is evaluated against a policy before any expensive work begins. Since .NET 7, the framework ships with a Microsoft.AspNetCore.RateLimiting middleware that supports several algorithms out of the box. This removes the historical need to pull in third-party libraries such as AspNetCoreRateLimit and keeps configuration declarative.
Australian developers working on fintech APIs in Brisbane or government portals in Canberra frequently need to combine rate limits with strong authentication and audit logging. The Australian Cyber Security Centre's Essential Eight guidance recommends rate limiting as a mitigation against brute-force and denial-of-service attempts, which makes the feature a practical checkbox for security accreditation. When the limiter rejects a request, the platform also needs a graceful response path that integrates cleanly with OpenTelemetry traces and existing Application Insights dashboards.
This article walks through choosing an algorithm, wiring the middleware into a typical Program.cs, partitioning limits per tenant, returning standards-compliant 429 responses, and finally observing the limiter in production. Code samples target .NET 8 and assume a hosted service running on Linux behind a reverse proxy, which is the common pattern for workloads deployed in Sydney or Perth regions of Azure.
Understanding rate limiting algorithms
The RateLimiter abstraction in ASP.NET Core supports four algorithms, each with different trade-offs around memory usage, fairness, and burst handling. Picking the right one is the foundation of a robust policy, because misconfigured limits either block legitimate traffic or fail to protect the backend during incidents.
A fixed window counter allows N requests per window of T seconds, resetting at the boundary. It is the cheapest to implement but suffers from boundary effects: a client can send N requests at second 59 and another N at second 60, effectively doubling the limit across two seconds. For low-stakes public endpoints in regional SaaS products, the simplicity often wins.
A sliding window refines the fixed approach by tracking the previous window's count and weighting it against the current window. Memory grows with the window size, but the boundary spike disappears. Token bucket replenishes tokens at a steady rate and allows controlled bursts up to the bucket capacity, which fits well for APIs serving a mix of human users and scheduled bots. Concurrency limiting caps the number of in-flight requests rather than the request rate, ideal for protecting a slow downstream like a SQL Server pool or an Azure SQL elastic database in Australia East.
| Algorithm | Memory per key | Burst behaviour | Best fit |
|---|---|---|---|
| Fixed window | Constant | High at boundary | Public read endpoints |
| Sliding window | Linear in window | Smooth | Mixed traffic APIs |
| Token bucket | Constant | Configurable burst | APIs with batch jobs |
| Concurrency | Constant | None | Slow DB or external calls |
For most Australian SaaS products, a combination works best: a token bucket on authentication endpoints to absorb login storms, and a sliding window on per-user API keys to enforce monthly quotas.
Configuring the built-in middleware in Program.cs
The middleware lives in the Microsoft.AspNetCore.RateLimiting namespace and is registered through builder.Services.AddRateLimiter(...). A typical setup uses the named policy pattern, which lets different controllers or minimal API groups opt into different limits using [EnableRateLimiting("policyName")] or RequireRateLimiting.
builder.Services.AddRateLimiter(options =>
{
options.RejectionStatusCode = StatusCodes.Status429TooManyRequests;
options.OnRejected = async (context, token) =>
{
context.HttpContext.Response.Headers.RetryAfter =
((int)context.Lease.TryGetMetadata(MetadataName.RetryAfter)
?.TotalSeconds ?? 1).ToString();
await context.HttpContext.Response.WriteAsJsonAsync(new
{
error = "rate_limited",
message = "Too many requests, slow down."
}, token);
};
options.AddPolicy("per-user", httpContext =>
{
var userId = httpContext.User.Identity?.Name ?? "anonymous";
return RateLimitPartition.GetTokenBucketLimiter(userId, _ => new TokenBucketRateLimiterOptions
{
TokenLimit = 60,
ReplenishmentPeriod = TimeSpan.FromMinutes(1),
TokensPerPeriod = 30,
QueueLimit = 0,
AutoReplenishment = true
});
});
});
The call to app.UseRateLimiter() must come after UseAuthentication and UseAuthorization so the partition key can read the authenticated user. Placing it before authentication would force the limiter to key on IP address alone, which is awkward for users behind carrier-grade NAT on the NBN in regional areas such as Tamworth or Cairns. The policy is then applied per endpoint with .RequireRateLimiting("per-user") inside a MapGet or MapPost chain.
Partitioning limits per client and endpoint
Partitioning is what turns a single global cap into a fair per-tenant or per-IP policy. The RateLimitPartition factory exposes keyed limiters, and the key is computed from the incoming HttpContext. Common keys include the authenticated subject, an API key header, an Azure AD app registration, or the remote IP address with httpContext.Connection.RemoteIpAddress.
For B2B APIs sold to Australian retailers, partitioning by API key is the standard contract. A starter plan might get 60 requests per minute while an enterprise SKU gets 600. The same pattern works for the federal government's data.gov.au style portals, where each agency receives its own quota. When the limiter is keyed on IP, developers in shared office spaces such as Sydney's WeWork buildings need to be careful: a noisy neighbour can exhaust the IP's quota and starve the rest of the floor.
Endpoint-specific limits are useful for expensive operations. A POST /reports endpoint that runs an Azure Synapse query in Australia Southeast might warrant a tighter concurrency limit than a GET /health probe. Combining endpoint and client partitions is straightforward by composing policies or applying the [EnableRateLimiting] attribute at the action level, while a global policy covers the rest of the surface.
Responding with 429 and Retry-After headers
A rejected request should never look like a server crash. The HTTP standard reserves 429 Too Many Requests for this scenario and recommends a Retry-After header in seconds or as an HTTP-date. Clients built on HttpClient in .NET 8 respect this header automatically when used with Polly's retry strategy, which simplifies resilience on both ends.
Beyond the header, returning a structured JSON body with an error code and a human-readable message helps integrators diagnose the problem. Logging the rejection at warning level with the partition key, the rejected policy name, and the lease metadata produces a trail that supports the Office of the Australian Information Commissioner's expectations around reasonable technical safeguards. Some teams in Melbourne and Adelaide go further and emit a custom metric for rate_limit_rejections_total keyed by tenant, which feeds straight into an Azure Monitor alert when the rate climbs during an incident.
For partner integrations written in older .NET Framework, a plain text body remains a safer fallback. The OnRejected callback shown earlier lets the response be tailored per policy, so anonymous traffic can receive a minimal response while authenticated clients get richer details.
Observability and tuning in production
Limits that work on a developer's laptop rarely survive contact with real traffic. Once the middleware is live, three signals guide tuning: the 429 rejection rate per partition, the queue length of the token bucket, and p95 latency of the protected endpoint. Each is exposed through RateLimiter statistics and can be wired into OpenTelemetry using a custom Meter.
Application Insights in the Australia East region captures these metrics alongside dependency calls, which makes it easy to correlate a spike in rejections with a slow Cosmos DB query. When tuning, raising the TokenLimit is rarely the right first move; instead, look at whether the partition key is too coarse. If every authenticated user shares a single bucket because the NameIdentifier claim is missing, the policy degrades to a global cap and legitimate users get blocked. Adding structured logging for httpContext.User.Identity.IsAuthenticated at the partition factory surfaces this during a post-incident review.
Finally, write a load test in k6 or NBomber that targets the Australian endpoints from a region close to Australia Central to verify behaviour under realistic latency. A limit that looks generous locally may still be too tight when round-trip time pushes requests into the next replenishment window. Adjusting the policy, redeploying, and comparing the next day's dashboard closes the loop and keeps the API fair for everyone from a solo founder in Hobart to a national retailer's integration team in Parramatta. A streaming workload like building a media streaming app with .NET Core and Azure Media Services can apply the same patterns to protect its ingest endpoints from encoder bursts.
1, CBD, Maharaj Surajmal Road, Near Yamuna Sports Complex, Delhi, 110032
GENERAL QUERIES
Manish Tewatia
manish@csharpcon.com
+91-9718-431-042
TICKET QUERIES
Atul Gupta
conference@csharpcon.com
+91-9910-125-804