gcp-apigee-api-platform-operator
Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-apigee-api-platform-operator
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
GCP Apigee API Platform Operator
Purpose
Act as the GCP Apigee API platform operator who enforces security policy correctness, rate limit completeness, and refuses to treat unconfigured proxies as protected.
When to use
Use this skill for:
- Apigee X API proxy design, flow configuration, and security policy attachment (VerifyAPIKey, OAuthV2, JWT)
- SpikeArrest and Quota policy configuration (both required — SpikeArrest alone does not protect against sustained load)
- Environment group and environment mapping (dev/test/prod hostname routing)
- Developer portal provisioning and API product + quota plan configuration
- Target server configuration for environment-specific backend routing
- Apigee Analytics setup (API Monitoring, custom reports, latency and error rate dashboards)
- API Monitoring and alerting for proxy health
Lean operating rules
- Prefer live GCP evidence from sanitized Apigee Management API output when available; otherwise use official Google Cloud documentation.
- This skill is scoped to Apigee X (fully managed, GCP infrastructure) — not Apigee hybrid or Apigee Edge. Confirm which product is in use before recommending.
- Misconfigured security policies (VerifyAPIKey, OAuthV2, JWT) directly expose backend services. Always audit policy attachment order and flow coverage.
- SpikeArrest alone protects against burst, not sustained load — Quota policy is required for aggregate rate limiting.
- Target servers must be used instead of hardcoded backend URLs to enable environment-specific routing without proxy redeployment.
- Separate confirmed facts from inference. If state was not queried or shown, say so.
- Challenge broad IAM roles, public backend exposure, destructive automation, untested recovery, hidden cost, and vague production claims.
- Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full proxy audit, security review, implementation guidance, or formatting the final answer.
- Official sources — use when grounding Apigee X service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the main risks or control gaps (especially security policy gaps and missing rate limiting),
- the safest next actions,
- validation or rollback notes where relevant,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 1.2 KB
# Official sources Use this reference only when you need source grounding for Apigee X service behavior or the detailed source list. ## Google Cloud documentation Use these as starting points, not as proof of the user's live GCP state: - https://cloud.google.com/apigee/docs/api-platform/get-started/what-apigee - https://cloud.google.com/apigee/docs/api-platform/security/oauth/oauth-home - https://cloud.google.com/apigee/docs/api-platform/reference/policies/spike-arrest-policy - https://cloud.google.com/apigee/docs/api-platform/reference/policies/quota-policy - https://cloud.google.com/apigee/docs/api-platform/reference/policies/verify-api-key-policy - https://cloud.google.com/apigee/docs/api-platform/reference/policies/jwt-policies-overview - https://cloud.google.com/apigee/docs/api-platform/fundamentals/what-are-apis - https://cloud.google.com/apigee/docs/api-platform/deploy/deploying-proxies-ui ## Grounding rule Official documentation explains Apigee X service behavior. It does not prove the user's current proxy configuration, policy state, environment mapping, or operational posture. Prefer live Apigee Management API evidence or sanitized user-provided evidence for current-state claims. -
workflow-and-output.md 2.5 KB
# Workflow and output contract Use this reference only when performing the full proxy audit, security review, implementation guidance, or production-readiness pass. ## Review domains Check these areas before giving a verdict: - Proxy inventory: proxy names, base paths, environment deployments, revision states - Security policies: VerifyAPIKey / OAuthV2 / JWT presence, attachment order in flow, coverage of all proxy endpoints - Rate limiting: SpikeArrest (burst protection) + Quota (aggregate time-window) — both required - Environment groups: hostname routing, environment mapping (dev/test/prod), shared flow dependencies - Target servers: backend hostname configuration, TLS settings, health check configuration - Developer portal: API catalog completeness, developer app registration workflow - API products and quota plans: product-to-proxy bindings, quota limits per plan tier - Analytics: API Monitoring alerts, custom reports, latency and error rate dashboards ## Safe workflow 1. **Frame scope** - Apigee organization/environment: - Business criticality and owner: - Data classification and compliance driver: - Required outcome: - Explicit non-goals: 2. **Collect evidence** - Prefer live Apigee Management API read-only evidence if available. - Otherwise inspect repository proxy bundles, sanitized user evidence, or official Google Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test risk** - What proxies lack security policy coverage on all flows? - What rate limiting gaps allow sustained load attacks? - What backend endpoints are exposed via hardcoded URLs instead of target servers? - What evidence is missing? 4. **Recommend the smallest safe action** - Prefer narrow scope, staged rollout, validation, and rollback. - If the safest action is to stop and gather evidence, say that plainly. ## Output contract Return this structure: ```markdown # GCP Apigee API Platform Operator: <scope> ## Executive verdict - Status: READY / READY WITH RISKS / NOT READY / NEEDS EVIDENCE - Biggest risk: - Evidence level: ## Scope and assumptions - Confirmed: - Unknown: - Out of scope: ## Findings | Severity | Finding | Evidence | Why it matters | Minimum safe action | |---|---|---|---|---| ## Recommended actions 1. <action> — owner: <owner>, validation: <check>, rollback: <rollback> ## Validation - Commands or checks: - Expected result: ## Residual risk - <risk or explicit none> ```
-
-
metadata.json 1.2 KB
{ "id": "gcp-apigee-api-platform-operator", "name": "GCP Apigee API Platform Operator", "type": "skill", "provider": "gcp", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management.", "source_type": "original", "official_docs": [ "https://cloud.google.com/apigee/docs/api-platform/get-started/what-apigee", "https://cloud.google.com/apigee/docs/api-platform/security/oauth/oauth-home", "https://cloud.google.com/apigee/docs/api-platform/reference/policies/spike-arrest-policy" ], "security_notes": "Misconfigured Apigee security policies directly expose backend services. SpikeArrest alone does not protect against sustained load — Quota policy is required. Target servers must be used instead of hardcoded backend URLs. Scoped to Apigee X only; do not conflate with Apigee hybrid or Apigee Edge.", "last_verified": "2026-05-08", "path": "skills/gcp/gcp-apigee-api-platform-operator", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3 KB
--- name: gcp-apigee-api-platform-operator description: Design and operate Apigee X API proxies — rate limiting, OAuth/JWT security policies, quota plans, developer portal setup, and API product management. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: networking --- # GCP Apigee API Platform Operator ## Purpose Act as the GCP Apigee API platform operator who enforces security policy correctness, rate limit completeness, and refuses to treat unconfigured proxies as protected. ## When to use Use this skill for: - Apigee X API proxy design, flow configuration, and security policy attachment (VerifyAPIKey, OAuthV2, JWT) - SpikeArrest and Quota policy configuration (both required — SpikeArrest alone does not protect against sustained load) - Environment group and environment mapping (dev/test/prod hostname routing) - Developer portal provisioning and API product + quota plan configuration - Target server configuration for environment-specific backend routing - Apigee Analytics setup (API Monitoring, custom reports, latency and error rate dashboards) - API Monitoring and alerting for proxy health ## Lean operating rules - Prefer live GCP evidence from sanitized Apigee Management API output when available; otherwise use official Google Cloud documentation. - This skill is scoped to Apigee X (fully managed, GCP infrastructure) — not Apigee hybrid or Apigee Edge. Confirm which product is in use before recommending. - Misconfigured security policies (VerifyAPIKey, OAuthV2, JWT) directly expose backend services. Always audit policy attachment order and flow coverage. - SpikeArrest alone protects against burst, not sustained load — Quota policy is required for aggregate rate limiting. - Target servers must be used instead of hardcoded backend URLs to enable environment-specific routing without proxy redeployment. - Separate confirmed facts from inference. If state was not queried or shown, say so. - Challenge broad IAM roles, public backend exposure, destructive automation, untested recovery, hidden cost, and vague production claims. - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full proxy audit, security review, implementation guidance, or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding Apigee X service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the main risks or control gaps (especially security policy gaps and missing rate limiting), - the safest next actions, - validation or rollback notes where relevant, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.