Tutorial: Building with CleaveDB
Rate Limiting (LIMIT)
To protect cluster resources against scraping, runaway background loops, or denial-of-service traffic, CleaveDB provides role-based query throttling via LIMIT.
Setting query quotas per minute
Specify the query volume, time window (per minute), and target role:
LIMIT 100 QUERIES PER MINUTE FOR "viewer"If an authenticated user with role viewer exceeds 100 queries within any rolling 60-second window, subsequent requests are rejected immediately with a 429 Rate limit exceeded error.
Strict throttling and complete blocks
You can assign different allowances for administrative or unauthenticated roles:
-- Restrict heavy administrative actions:
LIMIT 5 QUERIES PER MINUTE FOR admin
-- Block guest requests entirely:
LIMIT 0 QUERIES PER MINUTE FOR "guest"Setting the quota to 0 prevents any query execution for that role.
Connection-level enforcement
Rate limits are tracked in memory by the server's connection worker. Both TCP client sockets and persistent WebSocket connection loops check quota buckets prior to AST parsing, ensuring blocked queries consume virtually zero engine CPU.
