- Home
- Skills
- DevOps & Cloud
- Edge Infrastructure and CDN Architect
Edge Infrastructure and CDN Architect
Architects global edge infrastructure: Anycast routing, CDN caching tiers, edge workers, origin shielding, and sync.
$9
Works with the AI tools you already use
Edge Infrastructure and CDN Architect
Example session with this skill installed
Architect the global edge computing, CDN caching, and origin shielding architecture for our Retail Media Platform.
- Subject: Global Edge Delivery Platform (run-id: retail-edge-arch-001) serving 45 million international e-commerce shoppers across 180 Points of Presence (PoPs).
- Deciders: Lead Edge Infrastructure Architect (Marcus Vance) and Chief Information Security Officer (David O'Reilly).
- Scale & Traffic: Peak 85,000 edge HTTP requests/sec; origin shield offload target >= 92%; global p95 time-to-first-byte (TTFB) <= 45 ms.
- Tension: Marketing team proposed routing dynamic personalized shopping cart API calls to edge worker caches indefinitely with a 1-hour TTL to maximize global performance; David O'Reilly and Marcus Vance strictly reject caching authenticated personalized state at edge nodes without explicit user keying, mandating a strict two-tier caching hierarchy (Tier 1: Anycast Edge Worker cache with 60s TTL for anonymous catalogs; Tier 2: Dedicated Origin Shield in AWS us-east-1), cryptographic edge JWT validation, and synchronous pass-through for mutating checkout mutations.
Write the edge architecture overview under docs/.
- Read your context and instructions
- Compiled the edge infrastructure
Wrote docs/architecture/edge-infrastructure-architect/00-overview/edge-infrastructure-architect-overview.md. Complete edge infrastructure architecture specifying Anycast BGP routing, 180-PoP tiered caching, edge V8 isolate workers, origin shielding, and sub-45ms TTFB enforcement.
---
skill: edge-infrastructure-architect
---
# Edge Infrastructure Architecture: Global Retail Media Platform [EDGE-RET-001]
## Summary
This specification establishes the globally distributed edge computing, CDN caching, and origin shielding architecture for the Retail Media Platform under run ID `retail-edge-arch-001`. It serves 45 million international shoppers across 180 Edge Points of Presence (PoPs), sustaining 85,000 peak requests/second with a global p95 Time-To-First-Byte (TTFB) budget <= 45 ms. It decisively resolves the data leakage and stale pricing risks of un-scoped edge caching by rejecting long-lived edge caching of personalized cart states. The architecture enforces BGP Anycast ingress routing, lightweight V8 edge isolate compute for JWT authentication, a strict 2-tier caching hierarchy with a 92% origin shield offload ratio, and deterministic dynamic pass-through for checkout mutations.
## Detailed Description
Operating a low-latency global storefront requires terminating TLS connections close to end-users while protecting core centralized database clusters from thundering-herd traffic spikes. Attempting to serve personalized carts from generic edge caches risks cross-tenant session leaks and stale inventory displays.
Global Shopper Request (85,000 req/sec across 180 PoPs)
│
▼
[ BGP Anycast Layer / Closest Regional Edge PoP ] (p95 TTFB <= 45 ms)
├── 1. TLS 1.3 Termination & DDoS Mitigation
├── 2. Edge V8 Worker: Inspects Authorization Bearer JWT
└── 3. Cache Decision Gate:
├── Anonymous Product Catalog ──► Edge Cache (TTL: 60s, Hit Ratio: 85%)
└── Authenticated Cart / Order ──► Direct Pass-Through
│
▼ (Cache Miss / Pass-Through)
[ Centralized Origin Shield (AWS us-east-1) ]
├── Request Collapsing (Coalesces identical misses into 1 request)
└── Offload Ratio >= 92% Achieved
│
▼
[ Central Origin Application & Aurora PostgreSQL Database ]
### Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Origin Shield Offload Ratio (>= 92%) | Uncached edge traffic surges would overwhelm central database connection pools. | 0.35 | Marcus Vance (Lead Edge Architect) |
| Global Latency SLA (p95 TTFB <= 45 ms) | Sub-50ms page load speeds directly preserve e-commerce retail checkout conversions. | 0.30 | Consumer Retail Performance Mandate |
| Personalized Data Privacy & Isolation | User carts, PII, and payment details must never be stored in shared public edge caches. | 0.20 | David O'Reilly (CISO SecOps) |
| Edge Worker Compute Overhead | Lightweight V8 isolate execution must add <= 5 ms to request processing overhead. | 0.15 | Platform Infrastructure Policy |
### Comparison
| Architecture Candidate | Ingress Routing Model | Edge Compute Engine | Origin Protection | Evaluation |
|---|---|---|---|---|
| Option A: Geo-DNS to Central Cloud | Latency-based DNS routing | None (Centralized compute) | None | Rejected: Fails 45ms TTFB SLA in APAC/EU; massive origin load. |
| Option B: Distributed Micro-Datacenters | Direct regional clusters | Full K8s per region | Complex cross-region DB sync | Rejected: Exorbitant operational and database consistency costs. |
| Option C: BGP Anycast CDN + Origin Shield (Chosen) | Anycast across 180 PoPs | V8 serverless edge isolates | Dedicated Origin Shield in us-east-1 | Selected: Sub-45ms latency, 92% origin offload, zero data sync lag. |
### Result
Option C is selected. BGP Anycast routes traffic to the nearest of 180 PoPs; edge workers authenticate requests and serve cached assets; the Origin Shield protects central databases.
---
### Required Mechanisms
#### 1. Anycast Routing & Edge PoP Topology [MC-AT-01]
- **Ingress Layer**: BGP Anycast routing over dual Tier-1 transit providers across 180 edge PoPs globally.
- **Edge PoP Architecture**:
- Hardware: NVMe-backed edge caching proxy nodes running Cloudflare / Fastly V8 isolate engines.
- Connection Termination: TLS 1.3 with 0-RTT session resumption and HTTP/3 (QUIC) enabled.
#### 2. Tiered Caching & Origin Shielding Hierarchy [MC-TC-01]
- **Tier 1 (Regional Edge PoP)**:
- Caches anonymous catalog items, static media, and pre-rendered storefront layouts.
- Cache Key: `URI_PATH + HASH(Accept-Language, Currency)`.
- Max TTL: 60 seconds for catalog JSON; 24 hours for immutable product images.
- **Tier 2 (Origin Shield - AWS us-east-1)**:
- Sits directly in front of the central Kubernetes origin clusters.
- Request Collapsing: If 500 edge PoPs request `product_1234` simultaneously, Origin Shield issues exactly 1 query to the origin and broadcasts the response to all 500 edges.
- Offload Guarantee: Maintains >= 92% offload efficiency under peak load.
#### 3. Edge Worker Authentication & Gating [MC-EW-01]
- Edge workers execute within a 128 MB V8 isolate sandbox (CPU limit: 10 ms).
- **Edge JWT Verification**:
- Validates asymmetric Ed25519 signatures using public JWKS cached in memory (TTL: 1 hour).
- Validated claims inject internal header `X-Edge-Authenticated-User: <user_id>`.
- Expired or forged tokens fail at the edge with HTTP 401 in < 8 ms, saving origin compute.
#### 4. Dynamic Pass-Through & Invalidation Protocol [MC-DP-01]
- **Bypass Rule**: Requests matching methods `POST`, `PUT`, `PATCH`, `DELETE` or path pattern `/v1/checkout/*` bypass all edge caches unconditionally.
- **Purge Synchronization**: When product catalogs update, an event emitter dispatches global purge API calls (`purge_by_tag: ["catalog_electronics"]`), purging matching objects across all 180 PoPs in <= 150 ms.
---
### Invariants and Contracts
Zero Personalized Data Caching [INV-EDG-01]
Edge nodes are strictly prohibited from caching responses containing the `Set-Cookie` header
or matching authenticated user path `/v1/cart/*`. Personal data must route to origin.
Origin Shield Offload Floor [INV-EDG-02]
The Origin Shield tier must maintain an aggregate cache hit and collapse ratio >= 92%.
Surges causing origin offload to drop below 85% trigger automated edge rate limiting.
Sub-Fifty Millisecond TTFB Ceiling [INV-EDG-03]
The global p95 Time-To-First-Byte for cached catalog read requests across North America,
Europe, and East Asia must not exceed 45 ms.
## Explicit Unknowns
- Trans-Pacific fiber optic cable cut latency degradation when routing Asian traffic to us-east-1 (G-1).
- Edge V8 isolate cold-start latency variations during unexpected PoP failovers (G-2).
## Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 45 million international shoppers | provided | Scale intake | Current |
| 180 Points of Presence (PoPs) globally | provided | Infrastructure scope | Current |
| Peak 85,000 edge requests/sec | provided | Traffic profile intake | Current |
| Origin shield offload target >= 92% | decided | Marcus Vance (Lead Edge Architect) | 2026-09-15 |
| Global p95 TTFB budget <= 45 ms | provided | Performance SLA constraint | Current |
| Rejection of long-lived personalized edge caching | decided | David O'Reilly (CISO SecOps) | 2026-09-15 |
## Verification
No validator was supplied, so no command was run.
Reviewer self-check against edge infrastructure standards:
- **Topology Completeness**: PASS. Anycast BGP + 180 PoPs + Origin Shield hierarchy specified.
- **Shielding Efficacy**: PASS. Request collapsing and two-tier caching ensure >= 92% origin offload.
- **Privacy Gating**: PASS. Explicit invariant prohibits caching authenticated cart or cookie data.
- **Format Integrity**: PASS. Follows native Markdown rules from `rule_markdown.md`.
## Open Decisions
- `DEC-EDG-01`: Marcus Vance to determine whether Cloudflare Workers KV or Fastly KV Store should be standardized for edge customer geolocation overrides (Owner: Marcus Vance).
## Next steps
1. Marcus Vance configures Terraform manifests for Cloudflare / Fastly CDN edge distribution and Origin Shielding.
2. SecOps deploys edge worker script validating asymmetric Ed25519 JWT signatures at edge PoPs.
3. Conduct global synthetic latency benchmark verifying p95 TTFB <= 45 ms across 30 international sampling locations.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the infrastructure boundary for fleets of geographically or physically distributed compute sites/nodes that must continue bounded operation away from a reliable central control plane. It integrates placement, autonomy, synchronization, hardware, trust, updates and recovery without absorbing CDN, IoT application, networking, cloud or edge-function implementation.
Use it when
- Sites/fleets/nodes/devices and hosted workloads need stable identities and ownership
- Central control and local authority must remain safe through disconnection and reconnection
- Connectivity has explicit online, degraded, intermittent, partitioned and recovery modes
- Configuration/data/state synchronize bidirectionally with version, ordering and conflict semantics
- Workload placement depends on latency, bandwidth, privacy, hardware, energy and local dependencies
- Heterogeneous hardware/OS/runtime versions need capability discovery and compatibility
For example: “Our news site is slow in Asia and our egress bill is huge. We put a CDN in front and the hit rate is 6% because every page has a personalised header.”
What you get
- architecture/edge-infrastructure-architect/README.md
- architecture/edge-infrastructure-architect/00-overview/edge-infrastructure-architect-overview.md
- architecture/edge-infrastructure-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/topology.md, {module}/provisioning.md, {module}/networking.md, {module}/secrets.md, {module}/cost.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to configure a CDN/PoP route, write an edge function, deploy one IoT gateway/device app, optimize on-device ML, design a cloud region, or troubleshoot networking.
How it works
- Check the driver is distance or locality.
- Establish what may be served from the edge.
- Fix cache keys and invalidation at the edge.
- Decide what runs at the edge versus at origin.
- State the failure behaviour when the edge cannot reach origin.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-diagram.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install