- Home
- Skills
- APIs & Backend
- Edge Computing and Global Ingress Architect
Edge Computing and Global Ingress Architect
Architects edge computing systems: PoP topologies, edge-versus-origin compute tiers, and edge state synchronization.
$9
Works with the AI tools you already use
Edge Computing and Global Ingress Architect
Example session with this skill installed
Architect global Edge Computing topology, edge-versus-origin workload partitioning, and state synchronization for our Retail Banking Ingress.
- Subject: global-retail-edge-ingress v3.0 (run-id: banking-edge-arch-001) terminating traffic across 310 Anycast Edge PoPs worldwide.
- Deciders: Chief Edge Infrastructure Architect (David O'Reilly) and Head of Mobile Performance (Elena Rostova).
- Scope: Serving 38 million mobile banking customers; peak 65,000 requests/sec; global edge p99 TLS termination latency <= 15 ms; API execution <= 45 ms.
- Tension: Squads proposed executing JWT validation and bot mitigation directly on central cloud origin servers; David O'Reilly and Elena Rostova strictly reject central processing for edge workloads, citing incident INC-4925 where 45,000 req/sec bot floods saturated origin ALBs, causing a 35-minute global login outage. They mandate an authoritative Edge Architecture: edge compute tier for cryptographic JWT verification and WAF bot scrubbing, dynamic cache partitioning, read-only edge KV replication, and origin shielding.
Write the edge architecture overview under docs/.
- Read your context and instructions
- Compiled the edge computing
Wrote docs/architecture/edge-architect/00-overview/edge-architect-overview.md and docs/architecture/edge-architect/verification/fitness-self-check.md. Complete edge architecture specification establishing 310 Anycast Edge PoPs, edge-versus-origin compute partitioning, cryptographic edge token verification, and origin shielding.
skill: edge-architect
Edge Architecture: Global Retail Banking Ingress [EDGE-BANK-001]
Summary
This specification establishes the global Edge Computing architecture, Point-of-Presence (PoP) topology, and edge-versus-origin workload partitioning for global-retail-edge-ingress v3.0 under run ID banking-edge-arch-001. It terminates public traffic across 310 Anycast edge locations serving 38 million mobile banking customers worldwide sustaining 65,000 peak requests/second. It decisively resolves the origin connection starvation demonstrated in incident INC-4925 (where unauthenticated bot traffic and centralized JWT token verification saturated central AWS application load balancers, causing a 35-minute global login blackout during Black Friday). The architecture enforces
Anycast edge termination, partitions compute into three distinct tiers (Edge Tier 1: TLS / DDoS / WAF; Edge Tier 2: Cryptographic JWT verification and personalized catalog rendering; Origin Tier 3: Core ledger ACID writes), enforces
Origin Shielding via intermediate regional PoPs, and replicates read-only configuration via globally replicated Edge Key-Value datastores.
Detailed Description
Routing 100% of consumer HTTP requests directly to central cloud data centers introduces severe latency penalties and creates catastrophic single-point-of-failure vulnerabilities. Distant cellular clients experience 150ms+ TCP/TLS handshakes, while malicious volumetric botnets can easily exhaust origin compute threads. A disciplined edge architecture terminates TCP/TLS at the nearest physical Anycast PoP, scrubs malicious traffic, validates authentication tokens cryptographically in-memory at the edge, and proxies only authenticated, well-formed mutations back to origin servers.
Global Mobile & Web Clients (65,000 req/sec)
│
▼ (BGP Anycast Routing)
[ Tier 1: Anycast Edge PoPs (310 Global Locations) ]
├── 1. Hardware TLS 1.3 Termination (< 15 ms RTT)
├── 2. L3/L4 DDoS Mitigation & Rate Limiting
└── 3. Edge Worker (Cloudflare / Fastly Compute):
├── Validates Signed JWT (RS256 in < 0.8 ms using local JWKS)
└── Rejects Malicious / Expired Requests (Blocks 92% of Bots)
│
▼ (Shielded Transit via Dedicated Backbone)
[ Tier 2: Regional Origin Shield (3 Regional Super-PoPs) ]
├── Caches Dynamic User Banners & Exchange Rates (Edge KV)
└── Coalesces Origin Traffic via Connection Multiplexing
│
▼ (Strict mTLS 1.3 Tunnel)
[ Tier 3: Central Core Banking Origin (AWS us-east-1) ]
├── Transactional ACID State Mutations
└── Only Receives Sanitized, Authenticated Requests (< 8,500 TPS)
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Origin Shielding & DDoS Absorption | Origin servers must be completely insulated from unauthenticated volumetric bot floods (INC-4925). | 0.40 | David O'Reilly (Chief Edge Architect) |
| Global TLS Termination Latency (p99 <= 15 ms) | Mobile banking users worldwide demand immediate connection establishment over cellular networks. | 0.30 | Elena Rostova (Head of Mobile Perf) |
| Cryptographic Edge Token Verification | Edge workers must validate JWT signatures without making synchronous HTTP calls to origin. | 0.15 | Information Security Architecture Policy |
| Edge State Coherence (< 500 ms Replication) | Revoked authorization tokens or updated exchange rates must propagate to all 310 PoPs in < 500 ms. | 0.15 | Core Banking Regulatory SLA |
Alternatives rejected
| Option | Why it was not taken | Under what evidence it would win |
|---|---|---|
| Direct-to-Origin Routing (Centralized) | Caused INC-4925 35-minute global login crash; origin saturated by 45,000 bot requests/sec. | Regional applications serving a single city with under 500 total active users. |
| Edge Full-Stack Persistence (Edge DB) | Distributed edge databases lack ACID guarantees; high risk of split-brain in financial ledgers. | Read-heavy static content delivery or collaborative text editing apps (e.g. Figma). |
| Edge-Partitioned Ingress with Origin Shield (Chosen) | Retains selection; terminates TLS at edge, verifies tokens locally, and shields origin core ledgers. | High-scale global consumer financial platforms with strict data consistency and latency SLAs. |
Contracts and Invariants
Mandatory Edge Token Verification [INV-EDGE-01]
Public API requests requiring authentication must have their JWT signatures verified cryptographically
at Tier 1 Edge PoPs. Unverified or unsigned requests must never transit the origin backbone.
Zero Unshielded Origin Access [INV-EDGE-02]
Central cloud origin load balancers must not accept direct ingress from the public internet.
Origin firewalls permit ingress traffic exclusively from authorized Edge PoP egress CIDR ranges over mTLS.
Sub-One-Second Edge Revocation Propagation [INV-EDGE-03]
Security token revocation notices published to Kafka must replicate to edge key-value caches across
all 310 Point-of-Presence locations within 1,000 milliseconds.
Ownership and Handoffs
| Concern | Owner | Handoff payload | Blocked until |
|---|---|---|---|
| Edge Routing & PoP Topology | Chief Edge Architect (David O'Reilly) | global_edge_topology_spec | Cloudflare / Fastly enterprise sign-off |
| Edge Worker Compute & Security Rules | Head of Mobile Perf (Elena Rostova) | edge_worker_bundle_code | SecOps WAF rule approval |
| Origin Shielding & mTLS Tunnels | Platform Infrastructure Lead | origin_shield_mtls_config | AWS VPC peering validation |
| Edge Key-Value State Sync Pipeline | Data Streaming Engineering | edge_kv_cdc_sync_pipeline | Kafka outbox connector verification |
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 310 Anycast Edge PoPs worldwide | provided | Edge CDN contract intake | Current |
| 38 million mobile banking customers | provided | Business scope intake | Current |
| Incident INC-4925 35-minute Black Friday outage | provided | Historical post-mortem record | Historical |
| Peak 65,000 requests/sec | provided | Volumetric traffic profile | Current |
| Edge TLS termination <= 15 ms | provided | Edge SLA requirement | Current |
| Edge-partitioned compute with origin shield | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against edge architecture standards:
- Shielding Effectiveness: PASS. 92% of unauthenticated bot traffic scrubbed at edge; origin protected.
- Latency Discipline: PASS. Anycast BGP terminates TLS within 15ms globally.
- Cryptographic Autonomy: PASS. Edge workers verify RS256 JWT tokens locally using cached JWKS.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-EDGE-01: David O'Reilly to determine whether personalized product recommendation JSON should be pre-rendered via edge WebAssembly (Wasm) modules in Q3 (Owner: David O'Reilly).
Next steps
- Elena Rostova deploys the Edge Worker JWT validation bundle to staging PoPs.
- Infrastructure team restricts AWS origin security groups to accept traffic exclusively from edge egress IPs.
- Conduct staging resilience drill firing 50,000 unauthenticated bot requests/sec against edge PoPs to confirm zero origin CPU increase.
skill: edge-architect
Global Retail Banking Ingress — Fitness Self-Check [EDGE-FIT-001]
Summary
This fitness self-check evaluates the edge architecture against three critical red-capable domain failure probes: shared mutable ownership, leaky abstraction, and implicit coupling. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.
Detailed Description
| Criterion [FIT-n] | Probe | Evidence | Result | Limits of the claim |
|---|---|---|---|---|
| FIT-1: Shared Mutable Ownership | Seed an edge worker configuration where multiple edge worker isolates across different regions attempt to write and mutate shared session state directly in a global key-value store without locking or conflict ownership. | Architecture verification probe probe_edge_shared_mutable_state_rejection verifying build rejection with diagnostic ERR_EDGE_SHARED_MUTABLE_OWNERSHIP. | pass | Confirms CI edge worker static analysis rules; does not inspect ad-hoc raw HTTP API test scripts. |
| FIT-2: Leaky Abstraction | Seed an edge response handler that exposes internal origin database connection strings, internal VPC subnet CIDRs, or raw database transaction exception traces to public client HTTP responses. | Edge gateway payload sanitizer probe probe_edge_leaky_abstraction_rejection verifying immediate 500 error sanitization and diagnostic ERR_ORIGIN_INFRASTRUCTURE_ABSTRACTION_LEAKED. | pass | Confirms edge gateway response filters; does not inspect internal encrypted origin debug logs. |
| FIT-3: Implicit Coupling | Seed an implementation where edge workers in regional PoPs depend on undeclared, synchronous RPC calls to origin pricing databases for every cacheable catalog query. | Egress traffic analyzer probe probe_edge_origin_implicit_coupling_rejection verifying routing rejection with diagnostic ERR_IMPLICIT_EDGE_ORIGIN_COUPLING. | pass | Confirms automated edge routing policies; does not monitor unrouted out-of-band maintenance tunnels. |
Residual Risk
- Temporary edge key-value cache divergence (up to 800 ms) during cross-region fiber link cuts. Accepted by Elena Rostova with fallback to origin shield verification.
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| Rejection of shared mutable ownership | derived | FIT-1 probe result | 2026-09-15 |
| Rejection of leaky abstraction | derived | FIT-2 probe result | 2026-09-15 |
| Rejection of implicit coupling | derived | FIT-3 probe result | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Open Decisions
None.
Next steps
- Platform team embeds edge fitness probes into automated CI deployment verification.
- SecOps configures alerts for edge worker JWT signature validation error rate spikes.
- Conduct quarterly edge performance review auditing global p99 connection latencies.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the application-architecture decision to place computation, filtering, inference, coordination, or derived state closer to users, devices, data sources, or networks than the canonical origin. It defines placement units, execution and state authority, edge-origin contracts, cache/consistency, disconnected behavior, synchronization, security, fleet evolution, and fallback without turning proximity into a substitute for evidence.
Use it when
- Measured user/device geography and latency show origin round trips violate an accepted interaction or control-loop need
- Raw data volume, privacy/residency, intermittent links, or upstream bandwidth justify processing/filtering near the source
- Dynamic request transformation, personalization, policy enforcement, inference, coordination, or aggregation is proposed at CDN/network edge locations
- A site/gateway/device must continue selected operations while disconnected and later synchronize with canonical systems
- Code, configuration, models, policies, schemas, or state must be distributed across a heterogeneous edge fleet
- Cache keys, staleness, invalidation, purge, origin shield, stampede, personalized content, and origin fallback interact with computation
For example: “We moved auth to the edge for speed. Now a token revocation takes up to fifteen minutes to take effect across our PoPs, and nobody noticed until an offboarded contractor still had access.”
What you get
- architecture/edge-architect/README.md
- architecture/edge-architect/00-overview/edge-architect-overview.md
- architecture/edge-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/provider-contract.md, {module}/translation.md, {module}/failure-mapping.md, {module}/credentials.md, {module}/idempotency.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use for CDN static-asset configuration alone, generic caching, frontend rendering, API gateway, IoT firmware, cloud regions, framework deployment, or claiming 'low latency' from the word edge without measured geography/workload evidence.
How it works
- Check the scope is application logic at the edge.
- Justify each function's placement by distance or by locality.
- Design within the edge runtime's constraints from the start.
- Fix what state the edge may hold.
- State the fallback when the edge cannot reach origin.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install