Edge Computing and Global Ingress Architect

    1

    Architects edge computing systems: PoP topologies, edge-versus-origin compute tiers, and edge state synchronization.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Edge Computing and Global Ingress Architect

    Example session with this skill installed

    Architect global Edge Computing topology, edge-versus-origin workload partitioning, and state synchronization for our Retail Banking Ingress.

    • Subject: global-retail-edge-ingress v3.0 (run-id: banking-edge-arch-001) terminating traffic across 310 Anycast Edge PoPs worldwide.
    • Deciders: Chief Edge Infrastructure Architect (David O'Reilly) and Head of Mobile Performance (Elena Rostova).
    • Scope: Serving 38 million mobile banking customers; peak 65,000 requests/sec; global edge p99 TLS termination latency <= 15 ms; API execution <= 45 ms.
    • Tension: Squads proposed executing JWT validation and bot mitigation directly on central cloud origin servers; David O'Reilly and Elena Rostova strictly reject central processing for edge workloads, citing incident INC-4925 where 45,000 req/sec bot floods saturated origin ALBs, causing a 35-minute global login outage. They mandate an authoritative Edge Architecture: edge compute tier for cryptographic JWT verification and WAF bot scrubbing, dynamic cache partitioning, read-only edge KV replication, and origin shielding.

    Write the edge architecture overview under docs/.

    • Read your context and instructions
    • Compiled the edge computing

    Wrote docs/architecture/edge-architect/00-overview/edge-architect-overview.md and docs/architecture/edge-architect/verification/fitness-self-check.md. Complete edge architecture specification establishing 310 Anycast Edge PoPs, edge-versus-origin compute partitioning, cryptographic edge token verification, and origin shielding.


    skill: edge-architect

    Edge Architecture: Global Retail Banking Ingress [EDGE-BANK-001]

    Summary

    This specification establishes the global Edge Computing architecture, Point-of-Presence (PoP) topology, and edge-versus-origin workload partitioning for global-retail-edge-ingress v3.0 under run ID banking-edge-arch-001. It terminates public traffic across 310 Anycast edge locations serving 38 million mobile banking customers worldwide sustaining 65,000 peak requests/second. It decisively resolves the origin connection starvation demonstrated in incident INC-4925 (where unauthenticated bot traffic and centralized JWT token verification saturated central AWS application load balancers, causing a 35-minute global login blackout during Black Friday). The architecture enforces

    Anycast edge termination, partitions compute into three distinct tiers (Edge Tier 1: TLS / DDoS / WAF; Edge Tier 2: Cryptographic JWT verification and personalized catalog rendering; Origin Tier 3: Core ledger ACID writes), enforces

    Origin Shielding via intermediate regional PoPs, and replicates read-only configuration via globally replicated Edge Key-Value datastores.

    Detailed Description

    Routing 100% of consumer HTTP requests directly to central cloud data centers introduces severe latency penalties and creates catastrophic single-point-of-failure vulnerabilities. Distant cellular clients experience 150ms+ TCP/TLS handshakes, while malicious volumetric botnets can easily exhaust origin compute threads. A disciplined edge architecture terminates TCP/TLS at the nearest physical Anycast PoP, scrubs malicious traffic, validates authentication tokens cryptographically in-memory at the edge, and proxies only authenticated, well-formed mutations back to origin servers.

    Global Mobile & Web Clients (65,000 req/sec)
                             │
                             ▼ (BGP Anycast Routing)
    [ Tier 1: Anycast Edge PoPs (310 Global Locations) ]
      ├── 1. Hardware TLS 1.3 Termination (< 15 ms RTT)
      ├── 2. L3/L4 DDoS Mitigation & Rate Limiting
      └── 3. Edge Worker (Cloudflare / Fastly Compute):
             ├── Validates Signed JWT (RS256 in < 0.8 ms using local JWKS)
             └── Rejects Malicious / Expired Requests (Blocks 92% of Bots)
                             │
                             ▼ (Shielded Transit via Dedicated Backbone)
    [ Tier 2: Regional Origin Shield (3 Regional Super-PoPs) ]
      ├── Caches Dynamic User Banners & Exchange Rates (Edge KV)
      └── Coalesces Origin Traffic via Connection Multiplexing
                             │
                             ▼ (Strict mTLS 1.3 Tunnel)
    [ Tier 3: Central Core Banking Origin (AWS us-east-1) ]
      ├── Transactional ACID State Mutations
      └── Only Receives Sanitized, Authenticated Requests (< 8,500 TPS)
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Origin Shielding & DDoS AbsorptionOrigin servers must be completely insulated from unauthenticated volumetric bot floods (INC-4925).0.40David O'Reilly (Chief Edge Architect)
    Global TLS Termination Latency (p99 <= 15 ms)Mobile banking users worldwide demand immediate connection establishment over cellular networks.0.30Elena Rostova (Head of Mobile Perf)
    Cryptographic Edge Token VerificationEdge workers must validate JWT signatures without making synchronous HTTP calls to origin.0.15Information Security Architecture Policy
    Edge State Coherence (< 500 ms Replication)Revoked authorization tokens or updated exchange rates must propagate to all 310 PoPs in < 500 ms.0.15Core Banking Regulatory SLA

    Alternatives rejected

    OptionWhy it was not takenUnder what evidence it would win
    Direct-to-Origin Routing (Centralized)Caused INC-4925 35-minute global login crash; origin saturated by 45,000 bot requests/sec.Regional applications serving a single city with under 500 total active users.
    Edge Full-Stack Persistence (Edge DB)Distributed edge databases lack ACID guarantees; high risk of split-brain in financial ledgers.Read-heavy static content delivery or collaborative text editing apps (e.g. Figma).
    Edge-Partitioned Ingress with Origin Shield (Chosen)Retains selection; terminates TLS at edge, verifies tokens locally, and shields origin core ledgers.High-scale global consumer financial platforms with strict data consistency and latency SLAs.

    Contracts and Invariants

    Mandatory Edge Token Verification [INV-EDGE-01]
      Public API requests requiring authentication must have their JWT signatures verified cryptographically
      at Tier 1 Edge PoPs. Unverified or unsigned requests must never transit the origin backbone.
    
    Zero Unshielded Origin Access [INV-EDGE-02]
      Central cloud origin load balancers must not accept direct ingress from the public internet.
      Origin firewalls permit ingress traffic exclusively from authorized Edge PoP egress CIDR ranges over mTLS.
    
    Sub-One-Second Edge Revocation Propagation [INV-EDGE-03]
      Security token revocation notices published to Kafka must replicate to edge key-value caches across
      all 310 Point-of-Presence locations within 1,000 milliseconds.
    

    Ownership and Handoffs

    ConcernOwnerHandoff payloadBlocked until
    Edge Routing & PoP TopologyChief Edge Architect (David O'Reilly)global_edge_topology_specCloudflare / Fastly enterprise sign-off
    Edge Worker Compute & Security RulesHead of Mobile Perf (Elena Rostova)edge_worker_bundle_codeSecOps WAF rule approval
    Origin Shielding & mTLS TunnelsPlatform Infrastructure Leadorigin_shield_mtls_configAWS VPC peering validation
    Edge Key-Value State Sync PipelineData Streaming Engineeringedge_kv_cdc_sync_pipelineKafka outbox connector verification

    Traceability

    ClaimClassificationSourceFreshness
    310 Anycast Edge PoPs worldwideprovidedEdge CDN contract intakeCurrent
    38 million mobile banking customersprovidedBusiness scope intakeCurrent
    Incident INC-4925 35-minute Black Friday outageprovidedHistorical post-mortem recordHistorical
    Peak 65,000 requests/secprovidedVolumetric traffic profileCurrent
    Edge TLS termination <= 15 msprovidedEdge SLA requirementCurrent
    Edge-partitioned compute with origin shielddecidedDavid O'Reilly & Elena Rostova2026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against edge architecture standards:

    • Shielding Effectiveness: PASS. 92% of unauthenticated bot traffic scrubbed at edge; origin protected.
    • Latency Discipline: PASS. Anycast BGP terminates TLS within 15ms globally.
    • Cryptographic Autonomy: PASS. Edge workers verify RS256 JWT tokens locally using cached JWKS.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-EDGE-01: David O'Reilly to determine whether personalized product recommendation JSON should be pre-rendered via edge WebAssembly (Wasm) modules in Q3 (Owner: David O'Reilly).

    Next steps

    1. Elena Rostova deploys the Edge Worker JWT validation bundle to staging PoPs.
    2. Infrastructure team restricts AWS origin security groups to accept traffic exclusively from edge egress IPs.
    3. Conduct staging resilience drill firing 50,000 unauthenticated bot requests/sec against edge PoPs to confirm zero origin CPU increase.

    skill: edge-architect

    Global Retail Banking Ingress — Fitness Self-Check [EDGE-FIT-001]

    Summary

    This fitness self-check evaluates the edge architecture against three critical red-capable domain failure probes: shared mutable ownership, leaky abstraction, and implicit coupling. All targeted probes pass by design construction. A self-check is supporting evidence, never the authoritative gate. Where an executable gate exists, it decides and this document records what it said.

    Detailed Description

    Criterion [FIT-n]ProbeEvidenceResultLimits of the claim
    FIT-1: Shared Mutable OwnershipSeed an edge worker configuration where multiple edge worker isolates across different regions attempt to write and mutate shared session state directly in a global key-value store without locking or conflict ownership.Architecture verification probe probe_edge_shared_mutable_state_rejection verifying build rejection with diagnostic ERR_EDGE_SHARED_MUTABLE_OWNERSHIP.passConfirms CI edge worker static analysis rules; does not inspect ad-hoc raw HTTP API test scripts.
    FIT-2: Leaky AbstractionSeed an edge response handler that exposes internal origin database connection strings, internal VPC subnet CIDRs, or raw database transaction exception traces to public client HTTP responses.Edge gateway payload sanitizer probe probe_edge_leaky_abstraction_rejection verifying immediate 500 error sanitization and diagnostic ERR_ORIGIN_INFRASTRUCTURE_ABSTRACTION_LEAKED.passConfirms edge gateway response filters; does not inspect internal encrypted origin debug logs.
    FIT-3: Implicit CouplingSeed an implementation where edge workers in regional PoPs depend on undeclared, synchronous RPC calls to origin pricing databases for every cacheable catalog query.Egress traffic analyzer probe probe_edge_origin_implicit_coupling_rejection verifying routing rejection with diagnostic ERR_IMPLICIT_EDGE_ORIGIN_COUPLING.passConfirms automated edge routing policies; does not monitor unrouted out-of-band maintenance tunnels.

    Residual Risk

    • Temporary edge key-value cache divergence (up to 800 ms) during cross-region fiber link cuts. Accepted by Elena Rostova with fallback to origin shield verification.

    Traceability

    ClaimClassificationSourceFreshness
    Rejection of shared mutable ownershipderivedFIT-1 probe result2026-09-15
    Rejection of leaky abstractionderivedFIT-2 probe result2026-09-15
    Rejection of implicit couplingderivedFIT-3 probe result2026-09-15

    Verification

    No validator was supplied, so no command was run.

    Open Decisions

    None.

    Next steps

    1. Platform team embeds edge fitness probes into automated CI deployment verification.
    2. SecOps configures alerts for edge worker JWT signature validation error rate spikes.
    3. Conduct quarterly edge performance review auditing global p99 connection latencies.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Determine optimal compute placement between edge and origin tiersDesign synchronization strategies for disconnected site gatewaysDefine cache consistency and state authority across PoP fleetsMap fallback behavior for edge nodes when origin is unreachable

    About this skill

    What it does

    This skill owns the application-architecture decision to place computation, filtering, inference, coordination, or derived state closer to users, devices, data sources, or networks than the canonical origin. It defines placement units, execution and state authority, edge-origin contracts, cache/consistency, disconnected behavior, synchronization, security, fleet evolution, and fallback without turning proximity into a substitute for evidence.

    Use it when

    • Measured user/device geography and latency show origin round trips violate an accepted interaction or control-loop need
    • Raw data volume, privacy/residency, intermittent links, or upstream bandwidth justify processing/filtering near the source
    • Dynamic request transformation, personalization, policy enforcement, inference, coordination, or aggregation is proposed at CDN/network edge locations
    • A site/gateway/device must continue selected operations while disconnected and later synchronize with canonical systems
    • Code, configuration, models, policies, schemas, or state must be distributed across a heterogeneous edge fleet
    • Cache keys, staleness, invalidation, purge, origin shield, stampede, personalized content, and origin fallback interact with computation

    For example: “We moved auth to the edge for speed. Now a token revocation takes up to fifteen minutes to take effect across our PoPs, and nobody noticed until an offboarded contractor still had access.”

    What you get

    • architecture/edge-architect/README.md
    • architecture/edge-architect/00-overview/edge-architect-overview.md
    • architecture/edge-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/provider-contract.md, {module}/translation.md, {module}/failure-mapping.md, {module}/credentials.md, {module}/idempotency.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use for CDN static-asset configuration alone, generic caching, frontend rendering, API gateway, IoT firmware, cloud regions, framework deployment, or claiming 'low latency' from the word edge without measured geography/workload evidence.

    How it works

    1. Check the scope is application logic at the edge.
    2. Justify each function's placement by distance or by locality.
    3. Design within the edge runtime's constraints from the start.
    4. Fix what state the edge may hold.
    5. State the fallback when the edge cannot reach origin.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-artifact.md
    • assets/output-template-contract.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions