A circuit breaker rejects calls while a dependency is unhealthy; a fallback must not fabricate successful business state.
Spring Cloud Circuit Breaker: make fallback obey the original data contract
Separate availability from truth
If the stock ledger is unavailable, a receipt page can show a clearly marked cached estimate if that is an accepted read contract. A reservation command cannot claim success from cached stock. Return a typed unavailable result or error and leave inventory unchanged. Spring Cloud Circuit Breaker supports blocking and reactive implementations, but the chosen implementation and fallback policy must be tested with the actual client. Atomic writes solve a different problem.
Set the reset path
Opening the breaker reduces calls to a failing dependency; it does not reduce load already admitted elsewhere. Define a per-call timeout, minimum sample size, open interval and half-open probe budget. Measure fallback frequency separately from total 2xx traffic. A fallback that produces an ordinary success response can hide a persistent outage from both users and alerts.
Boundary sketch
if (ledgerUnavailable) {
return new ReceiptAvailability(
receiptId, null, "temporarily unavailable");
}
return new ReceiptAvailability(receiptId, availableUnits, "current");Cost and verification
Failure detection and state tracking add small in-process overhead. The main cost is a possible delay before half-open probes restore traffic after recovery. This sketch is not executed by the current Spring source kit; verify it against the chosen dependencies and deployment.
Common Mistakes
- Do not return a successful reservation from a stale cache.
- Do not hide fallback responses under ordinary success metrics.
- Do not treat an open circuit as proof that a remote database transaction rolled back.
Read next
Spring Cloud client retries: distinguish a safe read from an uncertain write, Spring Boot liveness versus readiness: do not restart on every dependency outage, Spring transactional outbox: commit a receipt and event row together, Spring HTTP retries: only replay a command with a defined identity.
Related boundary
Spring Cloud Gateway circuit breaker: a fallback is an API response contract
