CtrlK
BlogDocsLog inGet started
Tessl Logo

web-infra-foundation

Provider-agnostic web infrastructure: DNS architecture, SSL/TLS certificate lifecycle, CDN and edge optimization, backup and disaster recovery, domain lifecycle. [EXPLICIT] Cross-cuts Firebase/Vercel/Hostinger. Trigger: 'dns', 'ssl', 'tls', 'cdn', 'backup', 'disaster recovery', 'rto', 'rpo', 'domain'.

SKILL.md
Quality
Evals
Security

Web Infrastructure Foundation

"The platform changes; DNS, certs, CDN and backups don't." [INFERENCE]

TL;DR

Covers the provider-agnostic web-infrastructure concerns that sit beneath any of Firebase/Vercel/Hostinger: DNS architecture, SSL/TLS certificate lifecycle, CDN/edge caching, backup & disaster recovery (RTO/RPO), serverless patterns, and domain lifecycle. Use alongside a platform skill, not instead of it. [EXPLICIT]

When to use

  • Designing DNS (records, DNSSEC, health-check failover). [EXPLICIT]
  • Planning SSL/TLS issuance, renewal, HSTS, pinning. [EXPLICIT]
  • Tuning CDN cache headers, purge, geo-routing. [EXPLICIT]
  • Defining backup/DR: RTO/RPO, PITR, failover drills. [EXPLICIT]
  • Managing domain registration/renewal/transfer. [EXPLICIT]

Sub-capabilities (resource map)

CapabilityReference
DNS architecturereferences/dns-architecture.md
SSL/TLS lifecyclereferences/ssl-management.md
CDN/edgereferences/cdn-configuration.md
Backup & DRreferences/backup-strategy.md, references/disaster-recovery.md
Serverless patternsreferences/serverless-patterns.md
Domain lifecyclereferences/domain-management.md

Procedure

  1. Map the requirement to one capability; open its references/ playbook. [EXPLICIT]
  2. DNS/SSL before traffic: records correct, certs auto-renewing, HSTS set. [DOC]
  3. CDN: define cache-control + purge strategy; never cache authenticated responses. [INFERENCE]
  4. DR: write explicit RTO/RPO; test restore, not just backup. [DOC]
  5. Validate against the playbook checklist before cutover. [EXPLICIT]

Quality Criteria

  • DNS has failover and (where applicable) DNSSEC. [DOC]
  • Certificates auto-renew; expiry monitored. [DOC]
  • CDN never caches private/authenticated responses. [INFERENCE]
  • DR plan states RTO/RPO and the restore is tested. [DOC]
  • Claims evidence-tagged. [EXPLICIT]

Anti-Patterns

  • Backups that were never test-restored. [DOC]
  • Manual cert renewal (expiry outage). [INFERENCE]
  • Caching Set-Cookie/authenticated payloads at the CDN. [DOC]

Contract

  • Aceptación: DNS+SSL listos antes del tráfico; CDN sin cachear privado; DR con RTO/RPO y restore probado; dominio en regla. [EXPLICIT]
  • Límites: concierne infra transversal; no reemplaza la skill de plataforma (Firebase/Vercel/Hostinger). [EXPLICIT]
  • Casos borde: propagación DNS 24–48h → ventana de cutover; cert pinning mal hecho → outage al rotar. [DOC]
  • Supuestos: acceso al registrar/CDN/DNS provider del usuario. [SUPUESTO]
  • Trade-off: rigor de infra (failover, DR drills) cuesta setup pero evita outages caros. [EXPLICIT]

Related Skills

  • firebase-platform, vercel-platform, hostinger-platform — the platforms this underpins. [EXPLICIT]
  • observability-operations — monitoring/alerting for the infra it defines. [EXPLICIT]

Packet

Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · assets/ recursos estáticos.

Repository
JaviMontano/claude-plugins
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.