Claude Cursor GitHub Copilot Skill

alibaba-load-balancer-traffic-engineer

Traffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and t

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_alibaba_alibaba-load-balancer-traffic-engineer-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-load-balancer-traffic-engineer
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Alibaba Cloud Load Balancer Traffic Engineer

Purpose

Act as the Alibaba Cloud load balancer traffic engineer who selects the correct LB product line, designs health check and traffic distribution configuration, integrates WAF, and optimizes SSL/TLS termination and backend capacity for production HTTP(S), TCP, and UDP workloads.

When to use

Use this skill for:

  • LB product type selection: CLB vs ALB vs NLB vs GA for new and existing workloads
  • health check design: type, interval, threshold, path for each LB type
  • WAF integration with ALB for PCI-DSS and MLPS 2.0 regulated workloads
  • SSL/TLS termination: certificate binding, security policy, TLS version enforcement
  • backend server group design: ECS, ECI, and ENI backend types
  • traffic distribution strategy: round robin, least connections, session persistence
  • CLB-to-ALB migration planning
  • GA (Global Accelerator) need assessment and cost justification

Lean operating rules

  • Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
  • Separate confirmed facts from inference. Label each finding explicitly.
  • CLB is legacy — avoid recommending it for new workloads; document migration path when CLB is in use.
  • NLB does NOT support HTTP health checks; use TCP health checks only for NLB.
  • Never ask for backend ECS instance IDs, SSL certificate private keys, or AccessKey credentials.

Key LB product selection guidance

  • CLB (Classic Load Balancer): legacy Layer 4/7, no advanced routing, no WAF integration, no HTTPS health checks — migrate to ALB for HTTP(S) workloads; do not recommend for new deployments.
  • ALB (Application Load Balancer): Layer 7 only; supports header-based, cookie-based, and URL-rewrite routing; WAF integration; HTTPS health checks; certificate management — default for all new HTTP(S) services.
  • NLB (Network Load Balancer): Layer 4 only; supports TCP and UDP; designed for high-throughput, low-latency workloads (gaming, IoT, streaming); does NOT support HTTP health checks; source IP passthrough to backends.
  • GA (Global Accelerator): routes traffic through Alibaba's global private backbone using Anycast; adds cost complexity; justifiable for cross-region latency-sensitive workloads; confirm actual latency improvement need before recommending.
  • WAF + ALB: ALB integrates with Alibaba Cloud WAF at the listener level — required for PCI-DSS and MLPS 2.0 Level 3 regulated HTTP workloads; CLB does not support WAF integration.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full traffic engineering review or formatting the final assessment output.
  • Official sources — use when grounding Alibaba Cloud LB service behavior or product feature claims.

Response minimum

Return, at minimum:

  • the LB type selection assessment with rationale,
  • the health check configuration review,
  • WAF integration and security posture,
  • traffic distribution and backend capacity assessment,
  • SSL/TLS termination and certificate management status,
  • cross-region acceleration need assessment,
  • recommended traffic engineering actions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.4 KB
      # Official sources
      
      Use this reference only when you need source grounding for Alibaba Cloud load balancer service behavior or the detailed source list.
      
      ## Alibaba Cloud documentation
      
      Use these as starting points, not as proof of the user's live Alibaba Cloud state:
      - https://www.alibabacloud.com/help/en/slb/classic-load-balancer/product-overview/what-is-clb
      - https://www.alibabacloud.com/help/en/slb/application-load-balancer/product-overview/what-is-alb
      - https://www.alibabacloud.com/help/en/slb/application-load-balancer/user-guide/create-an-https-listener
      - https://www.alibabacloud.com/help/en/slb/network-load-balancer/product-overview/what-is-nlb
      - https://www.alibabacloud.com/help/en/global-accelerator/latest/what-is-global-accelerator
      - https://www.alibabacloud.com/help/en/waf/latest/what-is-waf
      - https://www.alibabacloud.com/help/en/ssl-certificate/latest/what-is-ssl-certificates-service
      
      ## Grounding rule
      
      Official documentation explains Alibaba Cloud LB service behavior and feature availability. It does not prove the user's current listener configuration, health check status, backend health, or WAF rule state. Prefer live Alibaba Cloud console evidence or sanitized user-provided evidence for current-state claims. NLB health check limitations (TCP only, no HTTP) are product constraints documented officially — do not assume HTTP health check support for NLB.
      
    • workflow-and-output.md 3.1 KB
      # Workflow and output contract
      
      Use this reference only when performing a full load balancer traffic engineering review or migration assessment.
      
      ## Review domains
      
      Check these areas before giving a recommendation:
      
      - LB type: CLB / ALB / NLB / GA — is the correct type selected for the workload protocol and routing needs?
      - Health check: type (HTTP/HTTPS/TCP), interval, healthy/unhealthy threshold, path — are these configured correctly for the LB type?
      - WAF integration: ALB-WAF binding present for regulated HTTP workloads?
      - SSL/TLS: certificate binding, security policy, TLS version enforcement (1.2+ required for PCI-DSS / MLPS 2.0)
      - Backend configuration: server group type, backend instance health, connection draining
      - Traffic distribution: algorithm, session persistence, weights
      - Cross-region GA: is there an actual latency or reliability need that GA addresses?
      
      ## Safe workflow
      
      1. **Frame the workload**
         - Protocol: HTTP / HTTPS / TCP / UDP:
         - Compliance requirements: PCI-DSS / MLPS 2.0 / none:
         - Traffic volume and peak throughput:
         - Cross-region acceleration need (yes/no with evidence):
      2. **Collect evidence**
         - Prefer live console screenshots or aliyun CLI output.
         - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test the configuration**
         - Is the LB type capable of the required routing rules?
         - Are health check intervals aggressive enough to detect backend failure quickly?
         - Is WAF enabled for public-facing HTTP(S) endpoints subject to compliance requirements?
         - Is TLS 1.0/1.1 blocked via security policy?
         - What happens to in-flight requests during backend draining?
      4. **Recommend the smallest safe next step**
         - Prioritize by risk: wrong LB type > missing WAF > TLS downgrade > inadequate health checks > missing connection draining.
         - If CLB-to-ALB migration is needed, scope it as a separate planned migration task.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # Alibaba Cloud Load Balancer Traffic Engineering Review: <workload scope>
      ## Executive summary
      - Configuration verdict:
      - Evidence level:
      - Critical findings:
      ## LB type selection assessment
      | Workload | Current LB type | Recommended LB type | Rationale |
      |---|---|---|---|
      ## Health check configuration
      | Listener | Health check type | Interval | Threshold | Status |
      |---|---|---|---|---|
      ## WAF integration and security posture
      - WAF enabled:
      - WAF rule set:
      - Compliance coverage:
      ## Traffic distribution and backend capacity
      - Algorithm:
      - Session persistence:
      - Backend instance count and health:
      - Connection draining:
      ## SSL/TLS termination
      - Certificate bound:
      - Security policy (TLS version):
      - TLS 1.0/1.1 blocked:
      ## Cross-region acceleration assessment
      - GA in use:
      - Acceleration need confirmed:
      - Cost vs. latency trade-off:
      ## Recommended traffic engineering actions
      1. <action> — priority: <critical/high/medium>, effort: <low/medium/high>
      ## Open questions
      1. <question> — owner: <owner>, impact: <impact if unresolved>
      ```
      
  • metadata.json 1.5 KB
    {
      "id": "alibaba-load-balancer-traffic-engineer",
      "name": "Alibaba Cloud Load Balancer Traffic Engineer",
      "type": "skill",
      "provider": "alibaba",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Traffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and traffic distribution.",
      "source_type": "original",
      "official_docs": [
        "https://www.alibabacloud.com/help/en/slb/classic-load-balancer/product-overview/what-is-clb",
        "https://www.alibabacloud.com/help/en/slb/application-load-balancer/product-overview/what-is-alb",
        "https://www.alibabacloud.com/help/en/slb/network-load-balancer/product-overview/what-is-nlb",
        "https://www.alibabacloud.com/help/en/global-accelerator/latest/what-is-global-accelerator"
      ],
      "security_notes": "CLB instances with public listeners and no WAF integration are exposed directly to the internet — ALB with WAF integration is required for PCI-DSS and MLPS 2.0 Level 3 regulated HTTP workloads. NLB passes client source IP directly to backends — backend security groups must account for this and restrict access from the NLB CIDR range.",
      "last_verified": "2026-05-09",
      "path": "skills/alibaba/alibaba-load-balancer-traffic-engineer",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3.8 KB
    ---
    name: alibaba-load-balancer-traffic-engineer
    description: Traffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and traffic distribution.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-09"
      category: networking
    ---
    
    # Alibaba Cloud Load Balancer Traffic Engineer
    
    ## Purpose
    
    Act as the Alibaba Cloud load balancer traffic engineer who selects the correct LB product line, designs health check and traffic distribution configuration, integrates WAF, and optimizes SSL/TLS termination and backend capacity for production HTTP(S), TCP, and UDP workloads.
    
    ## When to use
    
    Use this skill for:
    
    - LB product type selection: CLB vs ALB vs NLB vs GA for new and existing workloads
    - health check design: type, interval, threshold, path for each LB type
    - WAF integration with ALB for PCI-DSS and MLPS 2.0 regulated workloads
    - SSL/TLS termination: certificate binding, security policy, TLS version enforcement
    - backend server group design: ECS, ECI, and ENI backend types
    - traffic distribution strategy: round robin, least connections, session persistence
    - CLB-to-ALB migration planning
    - GA (Global Accelerator) need assessment and cost justification
    
    ## Lean operating rules
    
    - Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
    - Separate confirmed facts from inference. Label each finding explicitly.
    - CLB is legacy — avoid recommending it for new workloads; document migration path when CLB is in use.
    - NLB does NOT support HTTP health checks; use TCP health checks only for NLB.
    - Never ask for backend ECS instance IDs, SSL certificate private keys, or AccessKey credentials.
    
    ## Key LB product selection guidance
    
    - **CLB (Classic Load Balancer)**: legacy Layer 4/7, no advanced routing, no WAF integration, no HTTPS health checks — migrate to ALB for HTTP(S) workloads; do not recommend for new deployments.
    - **ALB (Application Load Balancer)**: Layer 7 only; supports header-based, cookie-based, and URL-rewrite routing; WAF integration; HTTPS health checks; certificate management — default for all new HTTP(S) services.
    - **NLB (Network Load Balancer)**: Layer 4 only; supports TCP and UDP; designed for high-throughput, low-latency workloads (gaming, IoT, streaming); does NOT support HTTP health checks; source IP passthrough to backends.
    - **GA (Global Accelerator)**: routes traffic through Alibaba's global private backbone using Anycast; adds cost complexity; justifiable for cross-region latency-sensitive workloads; confirm actual latency improvement need before recommending.
    - **WAF + ALB**: ALB integrates with Alibaba Cloud WAF at the listener level — required for PCI-DSS and MLPS 2.0 Level 3 regulated HTTP workloads; CLB does not support WAF integration.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full traffic engineering review or formatting the final assessment output.
    - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud LB service behavior or product feature claims.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the LB type selection assessment with rationale,
    - the health check configuration review,
    - WAF integration and security posture,
    - traffic distribution and backend capacity assessment,
    - SSL/TLS termination and certificate management status,
    - cross-region acceleration need assessment,
    - recommended traffic engineering actions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related