alibaba-load-balancer-traffic-engineer
Traffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and t
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-load-balancer-traffic-engineer
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud Load Balancer Traffic Engineer
Purpose
Act as the Alibaba Cloud load balancer traffic engineer who selects the correct LB product line, designs health check and traffic distribution configuration, integrates WAF, and optimizes SSL/TLS termination and backend capacity for production HTTP(S), TCP, and UDP workloads.
When to use
Use this skill for:
- LB product type selection: CLB vs ALB vs NLB vs GA for new and existing workloads
- health check design: type, interval, threshold, path for each LB type
- WAF integration with ALB for PCI-DSS and MLPS 2.0 regulated workloads
- SSL/TLS termination: certificate binding, security policy, TLS version enforcement
- backend server group design: ECS, ECI, and ENI backend types
- traffic distribution strategy: round robin, least connections, session persistence
- CLB-to-ALB migration planning
- GA (Global Accelerator) need assessment and cost justification
Lean operating rules
- Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation.
- Separate confirmed facts from inference. Label each finding explicitly.
- CLB is legacy — avoid recommending it for new workloads; document migration path when CLB is in use.
- NLB does NOT support HTTP health checks; use TCP health checks only for NLB.
- Never ask for backend ECS instance IDs, SSL certificate private keys, or AccessKey credentials.
Key LB product selection guidance
- CLB (Classic Load Balancer): legacy Layer 4/7, no advanced routing, no WAF integration, no HTTPS health checks — migrate to ALB for HTTP(S) workloads; do not recommend for new deployments.
- ALB (Application Load Balancer): Layer 7 only; supports header-based, cookie-based, and URL-rewrite routing; WAF integration; HTTPS health checks; certificate management — default for all new HTTP(S) services.
- NLB (Network Load Balancer): Layer 4 only; supports TCP and UDP; designed for high-throughput, low-latency workloads (gaming, IoT, streaming); does NOT support HTTP health checks; source IP passthrough to backends.
- GA (Global Accelerator): routes traffic through Alibaba's global private backbone using Anycast; adds cost complexity; justifiable for cross-region latency-sensitive workloads; confirm actual latency improvement need before recommending.
- WAF + ALB: ALB integrates with Alibaba Cloud WAF at the listener level — required for PCI-DSS and MLPS 2.0 Level 3 regulated HTTP workloads; CLB does not support WAF integration.
References
Load these only when needed:
- Workflow and output contract — use when executing the full traffic engineering review or formatting the final assessment output.
- Official sources — use when grounding Alibaba Cloud LB service behavior or product feature claims.
Response minimum
Return, at minimum:
- the LB type selection assessment with rationale,
- the health check configuration review,
- WAF integration and security posture,
- traffic distribution and backend capacity assessment,
- SSL/TLS termination and certificate management status,
- cross-region acceleration need assessment,
- recommended traffic engineering actions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 1.4 KB
# Official sources Use this reference only when you need source grounding for Alibaba Cloud load balancer service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live Alibaba Cloud state: - https://www.alibabacloud.com/help/en/slb/classic-load-balancer/product-overview/what-is-clb - https://www.alibabacloud.com/help/en/slb/application-load-balancer/product-overview/what-is-alb - https://www.alibabacloud.com/help/en/slb/application-load-balancer/user-guide/create-an-https-listener - https://www.alibabacloud.com/help/en/slb/network-load-balancer/product-overview/what-is-nlb - https://www.alibabacloud.com/help/en/global-accelerator/latest/what-is-global-accelerator - https://www.alibabacloud.com/help/en/waf/latest/what-is-waf - https://www.alibabacloud.com/help/en/ssl-certificate/latest/what-is-ssl-certificates-service ## Grounding rule Official documentation explains Alibaba Cloud LB service behavior and feature availability. It does not prove the user's current listener configuration, health check status, backend health, or WAF rule state. Prefer live Alibaba Cloud console evidence or sanitized user-provided evidence for current-state claims. NLB health check limitations (TCP only, no HTTP) are product constraints documented officially — do not assume HTTP health check support for NLB. -
workflow-and-output.md 3.1 KB
# Workflow and output contract Use this reference only when performing a full load balancer traffic engineering review or migration assessment. ## Review domains Check these areas before giving a recommendation: - LB type: CLB / ALB / NLB / GA — is the correct type selected for the workload protocol and routing needs? - Health check: type (HTTP/HTTPS/TCP), interval, healthy/unhealthy threshold, path — are these configured correctly for the LB type? - WAF integration: ALB-WAF binding present for regulated HTTP workloads? - SSL/TLS: certificate binding, security policy, TLS version enforcement (1.2+ required for PCI-DSS / MLPS 2.0) - Backend configuration: server group type, backend instance health, connection draining - Traffic distribution: algorithm, session persistence, weights - Cross-region GA: is there an actual latency or reliability need that GA addresses? ## Safe workflow 1. **Frame the workload** - Protocol: HTTP / HTTPS / TCP / UDP: - Compliance requirements: PCI-DSS / MLPS 2.0 / none: - Traffic volume and peak throughput: - Cross-region acceleration need (yes/no with evidence): 2. **Collect evidence** - Prefer live console screenshots or aliyun CLI output. - Otherwise inspect IaC, sanitized user evidence, or official Alibaba Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test the configuration** - Is the LB type capable of the required routing rules? - Are health check intervals aggressive enough to detect backend failure quickly? - Is WAF enabled for public-facing HTTP(S) endpoints subject to compliance requirements? - Is TLS 1.0/1.1 blocked via security policy? - What happens to in-flight requests during backend draining? 4. **Recommend the smallest safe next step** - Prioritize by risk: wrong LB type > missing WAF > TLS downgrade > inadequate health checks > missing connection draining. - If CLB-to-ALB migration is needed, scope it as a separate planned migration task. ## Output contract Return this structure: ```markdown # Alibaba Cloud Load Balancer Traffic Engineering Review: <workload scope> ## Executive summary - Configuration verdict: - Evidence level: - Critical findings: ## LB type selection assessment | Workload | Current LB type | Recommended LB type | Rationale | |---|---|---|---| ## Health check configuration | Listener | Health check type | Interval | Threshold | Status | |---|---|---|---|---| ## WAF integration and security posture - WAF enabled: - WAF rule set: - Compliance coverage: ## Traffic distribution and backend capacity - Algorithm: - Session persistence: - Backend instance count and health: - Connection draining: ## SSL/TLS termination - Certificate bound: - Security policy (TLS version): - TLS 1.0/1.1 blocked: ## Cross-region acceleration assessment - GA in use: - Acceleration need confirmed: - Cost vs. latency trade-off: ## Recommended traffic engineering actions 1. <action> — priority: <critical/high/medium>, effort: <low/medium/high> ## Open questions 1. <question> — owner: <owner>, impact: <impact if unresolved> ```
-
-
metadata.json 1.5 KB
{ "id": "alibaba-load-balancer-traffic-engineer", "name": "Alibaba Cloud Load Balancer Traffic Engineer", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Traffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and traffic distribution.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/slb/classic-load-balancer/product-overview/what-is-clb", "https://www.alibabacloud.com/help/en/slb/application-load-balancer/product-overview/what-is-alb", "https://www.alibabacloud.com/help/en/slb/network-load-balancer/product-overview/what-is-nlb", "https://www.alibabacloud.com/help/en/global-accelerator/latest/what-is-global-accelerator" ], "security_notes": "CLB instances with public listeners and no WAF integration are exposed directly to the internet — ALB with WAF integration is required for PCI-DSS and MLPS 2.0 Level 3 regulated HTTP workloads. NLB passes client source IP directly to backends — backend security groups must account for this and restrict access from the NLB CIDR range.", "last_verified": "2026-05-09", "path": "skills/alibaba/alibaba-load-balancer-traffic-engineer", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3.8 KB
--- name: alibaba-load-balancer-traffic-engineer description: Traffic engineering for Alibaba Cloud load balancers — CLB (Classic, legacy), ALB (Application Load Balancer, Layer 7 advanced routing), NLB (Network Load Balancer, Layer 4 high throughput), and GA (Global Accelerator) — type selection, health check design, WAF integration, and traffic distribution. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-09" category: networking --- # Alibaba Cloud Load Balancer Traffic Engineer ## Purpose Act as the Alibaba Cloud load balancer traffic engineer who selects the correct LB product line, designs health check and traffic distribution configuration, integrates WAF, and optimizes SSL/TLS termination and backend capacity for production HTTP(S), TCP, and UDP workloads. ## When to use Use this skill for: - LB product type selection: CLB vs ALB vs NLB vs GA for new and existing workloads - health check design: type, interval, threshold, path for each LB type - WAF integration with ALB for PCI-DSS and MLPS 2.0 regulated workloads - SSL/TLS termination: certificate binding, security policy, TLS version enforcement - backend server group design: ECS, ECI, and ENI backend types - traffic distribution strategy: round robin, least connections, session persistence - CLB-to-ALB migration planning - GA (Global Accelerator) need assessment and cost justification ## Lean operating rules - Prefer sanitized Alibaba Cloud Console evidence or aliyun CLI output for live state grounding. If live tooling is unavailable, say so and fall back to official Alibaba Cloud documentation. - Separate confirmed facts from inference. Label each finding explicitly. - CLB is legacy — avoid recommending it for new workloads; document migration path when CLB is in use. - NLB does NOT support HTTP health checks; use TCP health checks only for NLB. - Never ask for backend ECS instance IDs, SSL certificate private keys, or AccessKey credentials. ## Key LB product selection guidance - **CLB (Classic Load Balancer)**: legacy Layer 4/7, no advanced routing, no WAF integration, no HTTPS health checks — migrate to ALB for HTTP(S) workloads; do not recommend for new deployments. - **ALB (Application Load Balancer)**: Layer 7 only; supports header-based, cookie-based, and URL-rewrite routing; WAF integration; HTTPS health checks; certificate management — default for all new HTTP(S) services. - **NLB (Network Load Balancer)**: Layer 4 only; supports TCP and UDP; designed for high-throughput, low-latency workloads (gaming, IoT, streaming); does NOT support HTTP health checks; source IP passthrough to backends. - **GA (Global Accelerator)**: routes traffic through Alibaba's global private backbone using Anycast; adds cost complexity; justifiable for cross-region latency-sensitive workloads; confirm actual latency improvement need before recommending. - **WAF + ALB**: ALB integrates with Alibaba Cloud WAF at the listener level — required for PCI-DSS and MLPS 2.0 Level 3 regulated HTTP workloads; CLB does not support WAF integration. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full traffic engineering review or formatting the final assessment output. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud LB service behavior or product feature claims. ## Response minimum Return, at minimum: - the LB type selection assessment with rationale, - the health check configuration review, - WAF integration and security posture, - traffic distribution and backend capacity assessment, - SSL/TLS termination and certificate management status, - cross-region acceleration need assessment, - recommended traffic engineering actions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.