Edge Infrastructure and CDN Architect

    1

    Architects global edge infrastructure: Anycast routing, CDN caching tiers, edge workers, origin shielding, and sync.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Edge Infrastructure and CDN Architect

    Example session with this skill installed

    Architect the global edge computing, CDN caching, and origin shielding architecture for our Retail Media Platform.

    • Subject: Global Edge Delivery Platform (run-id: retail-edge-arch-001) serving 45 million international e-commerce shoppers across 180 Points of Presence (PoPs).
    • Deciders: Lead Edge Infrastructure Architect (Marcus Vance) and Chief Information Security Officer (David O'Reilly).
    • Scale & Traffic: Peak 85,000 edge HTTP requests/sec; origin shield offload target >= 92%; global p95 time-to-first-byte (TTFB) <= 45 ms.
    • Tension: Marketing team proposed routing dynamic personalized shopping cart API calls to edge worker caches indefinitely with a 1-hour TTL to maximize global performance; David O'Reilly and Marcus Vance strictly reject caching authenticated personalized state at edge nodes without explicit user keying, mandating a strict two-tier caching hierarchy (Tier 1: Anycast Edge Worker cache with 60s TTL for anonymous catalogs; Tier 2: Dedicated Origin Shield in AWS us-east-1), cryptographic edge JWT validation, and synchronous pass-through for mutating checkout mutations.

    Write the edge architecture overview under docs/.

    • Read your context and instructions
    • Compiled the edge infrastructure

    Wrote docs/architecture/edge-infrastructure-architect/00-overview/edge-infrastructure-architect-overview.md. Complete edge infrastructure architecture specifying Anycast BGP routing, 180-PoP tiered caching, edge V8 isolate workers, origin shielding, and sub-45ms TTFB enforcement.

    ---
    skill: edge-infrastructure-architect
    ---
    
    # Edge Infrastructure Architecture: Global Retail Media Platform [EDGE-RET-001]
    
    ## Summary
    
    This specification establishes the globally distributed edge computing, CDN caching, and origin shielding architecture for the Retail Media Platform under run ID `retail-edge-arch-001`. It serves 45 million international shoppers across 180 Edge Points of Presence (PoPs), sustaining 85,000 peak requests/second with a global p95 Time-To-First-Byte (TTFB) budget <= 45 ms. It decisively resolves the data leakage and stale pricing risks of un-scoped edge caching by rejecting long-lived edge caching of personalized cart states. The architecture enforces BGP Anycast ingress routing, lightweight V8 edge isolate compute for JWT authentication, a strict 2-tier caching hierarchy with a 92% origin shield offload ratio, and deterministic dynamic pass-through for checkout mutations.
    
    ## Detailed Description
    
    Operating a low-latency global storefront requires terminating TLS connections close to end-users while protecting core centralized database clusters from thundering-herd traffic spikes. Attempting to serve personalized carts from generic edge caches risks cross-tenant session leaks and stale inventory displays.
    
    

    Global Shopper Request (85,000 req/sec across 180 PoPs)
    │
    ▼
    [ BGP Anycast Layer / Closest Regional Edge PoP ] (p95 TTFB <= 45 ms)
    ├── 1. TLS 1.3 Termination & DDoS Mitigation
    ├── 2. Edge V8 Worker: Inspects Authorization Bearer JWT
    └── 3. Cache Decision Gate:
    ├── Anonymous Product Catalog ──► Edge Cache (TTL: 60s, Hit Ratio: 85%)
    └── Authenticated Cart / Order ──► Direct Pass-Through
    │
    ▼ (Cache Miss / Pass-Through)
    [ Centralized Origin Shield (AWS us-east-1) ]
    ├── Request Collapsing (Coalesces identical misses into 1 request)
    └── Offload Ratio >= 92% Achieved
    │
    ▼
    [ Central Origin Application & Aurora PostgreSQL Database ]

    
    ### Criteria and weights
    
    | Criterion | Why it matters here | Weight | Source of the weight |
    |---|---|---|---|
    | Origin Shield Offload Ratio (>= 92%) | Uncached edge traffic surges would overwhelm central database connection pools. | 0.35 | Marcus Vance (Lead Edge Architect) |
    | Global Latency SLA (p95 TTFB <= 45 ms) | Sub-50ms page load speeds directly preserve e-commerce retail checkout conversions. | 0.30 | Consumer Retail Performance Mandate |
    | Personalized Data Privacy & Isolation | User carts, PII, and payment details must never be stored in shared public edge caches. | 0.20 | David O'Reilly (CISO SecOps) |
    | Edge Worker Compute Overhead | Lightweight V8 isolate execution must add <= 5 ms to request processing overhead. | 0.15 | Platform Infrastructure Policy |
    
    
    ### Comparison
    
    | Architecture Candidate | Ingress Routing Model | Edge Compute Engine | Origin Protection | Evaluation |
    |---|---|---|---|---|
    | Option A: Geo-DNS to Central Cloud | Latency-based DNS routing | None (Centralized compute) | None | Rejected: Fails 45ms TTFB SLA in APAC/EU; massive origin load. |
    | Option B: Distributed Micro-Datacenters | Direct regional clusters | Full K8s per region | Complex cross-region DB sync | Rejected: Exorbitant operational and database consistency costs. |
    | Option C: BGP Anycast CDN + Origin Shield (Chosen) | Anycast across 180 PoPs | V8 serverless edge isolates | Dedicated Origin Shield in us-east-1 | Selected: Sub-45ms latency, 92% origin offload, zero data sync lag. |
    
    
    ### Result
    
    Option C is selected. BGP Anycast routes traffic to the nearest of 180 PoPs; edge workers authenticate requests and serve cached assets; the Origin Shield protects central databases.
    
    ---
    
    ### Required Mechanisms
    
    #### 1. Anycast Routing & Edge PoP Topology [MC-AT-01]
    - **Ingress Layer**: BGP Anycast routing over dual Tier-1 transit providers across 180 edge PoPs globally.
    - **Edge PoP Architecture**:
      - Hardware: NVMe-backed edge caching proxy nodes running Cloudflare / Fastly V8 isolate engines.
      - Connection Termination: TLS 1.3 with 0-RTT session resumption and HTTP/3 (QUIC) enabled.
    
    #### 2. Tiered Caching & Origin Shielding Hierarchy [MC-TC-01]
    - **Tier 1 (Regional Edge PoP)**:
      - Caches anonymous catalog items, static media, and pre-rendered storefront layouts.
      - Cache Key: `URI_PATH + HASH(Accept-Language, Currency)`.
      - Max TTL: 60 seconds for catalog JSON; 24 hours for immutable product images.
    - **Tier 2 (Origin Shield - AWS us-east-1)**:
      - Sits directly in front of the central Kubernetes origin clusters.
      - Request Collapsing: If 500 edge PoPs request `product_1234` simultaneously, Origin Shield issues exactly 1 query to the origin and broadcasts the response to all 500 edges.
      - Offload Guarantee: Maintains >= 92% offload efficiency under peak load.
    
    #### 3. Edge Worker Authentication & Gating [MC-EW-01]
    - Edge workers execute within a 128 MB V8 isolate sandbox (CPU limit: 10 ms).
    - **Edge JWT Verification**:
      - Validates asymmetric Ed25519 signatures using public JWKS cached in memory (TTL: 1 hour).
      - Validated claims inject internal header `X-Edge-Authenticated-User: <user_id>`.
      - Expired or forged tokens fail at the edge with HTTP 401 in < 8 ms, saving origin compute.
    
    #### 4. Dynamic Pass-Through & Invalidation Protocol [MC-DP-01]
    - **Bypass Rule**: Requests matching methods `POST`, `PUT`, `PATCH`, `DELETE` or path pattern `/v1/checkout/*` bypass all edge caches unconditionally.
    - **Purge Synchronization**: When product catalogs update, an event emitter dispatches global purge API calls (`purge_by_tag: ["catalog_electronics"]`), purging matching objects across all 180 PoPs in <= 150 ms.
    
    ---
    
    ### Invariants and Contracts
    
        Zero Personalized Data Caching [INV-EDG-01]
          Edge nodes are strictly prohibited from caching responses containing the `Set-Cookie` header
          or matching authenticated user path `/v1/cart/*`. Personal data must route to origin.
    
        Origin Shield Offload Floor [INV-EDG-02]
          The Origin Shield tier must maintain an aggregate cache hit and collapse ratio >= 92%.
          Surges causing origin offload to drop below 85% trigger automated edge rate limiting.
    
        Sub-Fifty Millisecond TTFB Ceiling [INV-EDG-03]
          The global p95 Time-To-First-Byte for cached catalog read requests across North America,
          Europe, and East Asia must not exceed 45 ms.
    
    ## Explicit Unknowns
    
    - Trans-Pacific fiber optic cable cut latency degradation when routing Asian traffic to us-east-1 (G-1).
    - Edge V8 isolate cold-start latency variations during unexpected PoP failovers (G-2).
    
    ## Traceability
    
    | Claim | Classification | Source | Freshness |
    |---|---|---|---|
    | 45 million international shoppers | provided | Scale intake | Current |
    | 180 Points of Presence (PoPs) globally | provided | Infrastructure scope | Current |
    | Peak 85,000 edge requests/sec | provided | Traffic profile intake | Current |
    | Origin shield offload target >= 92% | decided | Marcus Vance (Lead Edge Architect) | 2026-09-15 |
    | Global p95 TTFB budget <= 45 ms | provided | Performance SLA constraint | Current |
    | Rejection of long-lived personalized edge caching | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
    
    
    ## Verification
    
    No validator was supplied, so no command was run.
    
    Reviewer self-check against edge infrastructure standards:
    - **Topology Completeness**: PASS. Anycast BGP + 180 PoPs + Origin Shield hierarchy specified.
    - **Shielding Efficacy**: PASS. Request collapsing and two-tier caching ensure >= 92% origin offload.
    - **Privacy Gating**: PASS. Explicit invariant prohibits caching authenticated cart or cookie data.
    - **Format Integrity**: PASS. Follows native Markdown rules from `rule_markdown.md`.
    
    ## Open Decisions
    
    - `DEC-EDG-01`: Marcus Vance to determine whether Cloudflare Workers KV or Fastly KV Store should be standardized for edge customer geolocation overrides (Owner: Marcus Vance).
    
    ## Next steps
    
    1. Marcus Vance configures Terraform manifests for Cloudflare / Fastly CDN edge distribution and Origin Shielding.
    2. SecOps deploys edge worker script validating asymmetric Ed25519 JWT signatures at edge PoPs.
    3. Conduct global synthetic latency benchmark verifying p95 TTFB <= 45 ms across 30 international sampling locations.
    

    Connects securely to your tools. The creator never sees your data.

    What you get

    Design resilient edge fleet identity and ownership modelsDefine CDN cache key and invalidation strategies for global PoPsArchitect state synchronization for intermittent connectivity nodesMap workload placement based on latency and privacy constraints

    About this skill

    What it does

    This skill owns the infrastructure boundary for fleets of geographically or physically distributed compute sites/nodes that must continue bounded operation away from a reliable central control plane. It integrates placement, autonomy, synchronization, hardware, trust, updates and recovery without absorbing CDN, IoT application, networking, cloud or edge-function implementation.

    Use it when

    • Sites/fleets/nodes/devices and hosted workloads need stable identities and ownership
    • Central control and local authority must remain safe through disconnection and reconnection
    • Connectivity has explicit online, degraded, intermittent, partitioned and recovery modes
    • Configuration/data/state synchronize bidirectionally with version, ordering and conflict semantics
    • Workload placement depends on latency, bandwidth, privacy, hardware, energy and local dependencies
    • Heterogeneous hardware/OS/runtime versions need capability discovery and compatibility

    For example: “Our news site is slow in Asia and our egress bill is huge. We put a CDN in front and the hit rate is 6% because every page has a personalised header.”

    What you get

    • architecture/edge-infrastructure-architect/README.md
    • architecture/edge-infrastructure-architect/00-overview/edge-infrastructure-architect-overview.md
    • architecture/edge-infrastructure-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/topology.md, {module}/provisioning.md, {module}/networking.md, {module}/secrets.md, {module}/cost.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to configure a CDN/PoP route, write an edge function, deploy one IoT gateway/device app, optimize on-device ML, design a cloud region, or troubleshoot networking.

    How it works

    1. Check the driver is distance or locality.
    2. Establish what may be served from the edge.
    3. Fix cache keys and invalidation at the edge.
    4. Decide what runs at the edge versus at origin.
    5. State the failure behaviour when the edge cannot reach origin.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-artifact.md
    • assets/output-template-contract.md
    • assets/output-template-diagram.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions