HttpClient and Resilient Outbound Calls
Use HttpClientFactory, timeouts, cancellation, retries, circuit breakers, and idempotency deliberately while preserving diagnostics and connection reuse.
Manage HTTP connection lifetimes
Classify transient and permanent failures
Apply bounded resilience policies
The short answer
Reuse managed HttpClient handlers through HttpClientFactory, set explicit timeouts, pass cancellation, and retry only transient failures when the operation is safe to repeat. Bound every resilience policy and preserve the final failure context.
Build the runtime mental model
HttpClient sends requests through handlers that manage connection pools and DNS behavior. Creating and disposing a client per request can exhaust sockets; keeping one unmanaged handler forever can retain stale DNS. The factory coordinates lifetimes.
Advanced C# work improves when you separate language syntax, runtime behavior, and application policy. Write down which layer owns the guarantee in this lesson. Then identify the observable evidence—a compiler rejection, test result, generated query, trace, or measurement—that would prove the model correct.
Design the boundary deliberately
A timeout limits waiting; cancellation represents caller intent. Retries need exponential delay and jitter, a maximum attempt count, and an idempotency analysis. Circuit breakers stop hammering a failing dependency and allow controlled probes.
The starter isolates one part of the mental model so it can run in the browser. The exercise moves the same rule into a current local .NET project where packages, framework hosting, diagnostics, and multi-file tests are available.
using System;
using System.Net;
class Program
{
static bool IsTransient(HttpStatusCode status)
{
int code = (int)status;
return code == 408 || code == 429 || code >= 500;
}
static void Main()
{
Console.WriteLine(IsTransient(HttpStatusCode.ServiceUnavailable));
Console.WriteLine(IsTransient(HttpStatusCode.BadRequest));
}
}Expected output
True False
Diagnose failure and misuse
Retrying validation failures, authentication failures, or non-idempotent writes can amplify damage. Layered retries multiply traffic. Calling EnsureSuccessStatusCode before reading a useful error contract can discard domain context.
Classify each failure as a contract violation, transient operational failure, permanent dependency response, concurrency conflict, or programmer defect. That classification determines whether to reject, retry, compensate, cancel, or fail fast. A generic catch-and-continue policy destroys the information needed to make that decision.
| Question | Evidence to inspect | Decision |
|---|---|---|
| Is the input valid? | Validation result and boundary examples | Reject with a stable contract |
| Is the failure transient? | Typed status, exception, and policy context | Retry only when bounded and safe |
| Is state still consistent? | Invariant and transaction outcome | Commit, compensate, or abort |
| Is performance acceptable? | Representative latency and allocation data | Keep simple or optimize one cause |
Apply the concept in production
Record dependency name, method, route template, status, duration, attempt count, and trace context without logging secrets. Test timeouts, cancellation, malformed success bodies, retry exhaustion, and circuit transitions with a fake handler.
Finish by making the result operable. Add structured diagnostics at the boundary, propagate cancellation, avoid sensitive data, and record SDK and dependency versions. Test the public behavior instead of private implementation details. If a framework or provider performs translation, serialization, concurrency, or I/O, include at least one test against the real production technology.
A senior-level review should be able to answer four questions: what contract is promised, who owns lifetime and cleanup, how failures become visible, and what evidence supports the design. If any answer depends on “the framework probably handles it,” inspect the documentation or runtime behavior and turn the assumption into a checked decision.
Quick knowledge check
Answer before you reveal.
01Why should not every failed request be retried?
Many failures are permanent or the operation is unsafe to repeat; indiscriminate retries add load and can duplicate side effects.
02What must happen before adding complexity to this design?
State the requirement, preserve a correct baseline, collect evidence, and explain how the proposed mechanism improves a specific quality.
Exercise
Practice challenge
Build a typed API client with timeout, cancellation, bounded retry for safe operations, structured diagnostics, and deterministic fake-handler tests.
Requirements
- The implementation states its contract and ownership boundary explicitly
- Automated checks cover the successful path and at least two meaningful failures
- Diagnostics expose failure context without secrets or swallowed exceptions
- The project documents required SDK, packages, setup, run, and test commands
Optional extension: Measure or load-test the critical path and record whether the evidence justifies another optimization or abstraction.
Open in C# compilerLesson checkpoint
One small step locks it in
Mark this lesson complete, then keep the momentum going.
Clear up the details
Frequently asked questions
When should I use httpclient and resilient outbound calls?
Use it when its explicit tradeoff solves a measured requirement or clarifies an owned boundary. Keep the simpler design when the additional mechanism does not improve correctness, operability, or changeability.
Does the browser compiler cover the complete production setup?
No. It runs the focused starter program. Framework, package, database, benchmark, and multi-project work requires a current local .NET SDK and the project commands described in the exercise.
What evidence should I keep after the exercise?
Keep the acceptance cases, automated tests, diagnostic or benchmark output where relevant, and a short decision note describing the chosen boundary and rejected alternative.