v3.0.0
Every connector now has its own token bucket, so the burst goes out at once and the rest of a backlog is spaced one over the configured requests per second apart instead of escaping in one batch. A 429 carrying Retry-After pauses every send on that connector rather than just the message that was throttled, capped by max_retry_after_seconds so a hostile header cannot stall a worker.
Sustained 5xx responses, timeouts, and connection errors feed a per-connector circuit breaker, which is a different signal from being throttled, so 429 never opens it. Once open the worker stops polling and keeps extending the visibility timeout on anything it is already holding, which means an outage cannot hand a message to a second consumer or burn receive count into the dead-letter queue. After the recovery window one probe decides whether polling resumes or the breaker opens again.
Rate limit waits, honoured Retry-After responses, breaker state, opens, and paused seconds are all on /metrics and in the worker's stop log line. The fakes gained an outage fault that fails every call with 503 until it is cleared, which is how the new LocalStack tests reproduce a downstream being down.
Tests are 129 unit and 17 LocalStack plus terraform: the bucket holds its rate over a window at three different rate and burst settings, six real sends at five per second arrive across a one second window, an outage pauses the worker so it consumes nothing and then drains cleanly once cleared, and a message held across a pause is never redelivered even though the queue's visibility timeout is shorter than the pause.