The Quayel Gateway Skill
The Quayel Gateway Skill
The skill is a single markdown file — skills/quayel-gateway/SKILL.md in the gateway repository — in the Agent Skills format (YAML frontmatter with name + description, followed by instructions). Drop it into any compatible tool and the agent knows how to configure Quayel Gateway correctly.
What it does
- Generates complete, valid
config.jsonfiles — required fields, exact snake_case enums, safe defaults - Validates before declaring success: syntax check → JSON Schema → the gateway's own parser → smoke test → hot reload
- Troubleshoots why a rule does (or does not) fire: startup error map, access-log fields, behavior gotchas
- Explains the pipeline: plugin order, first-match-wins rule semantics, short-circuiting
When the skill activates
The skill's frontmatter description tells the agent when to use it:
Generate, validate, and troubleshoot Quayel Gateway configs (
config.json). Use this skill whenever a user asks to proxy/protect a service, add rate limits, firewall rules, caching or load balancing, edit a quayelconfig.json, or debug why a quayel rule does or does not fire.
So a request like "put a rate limit on /api and block Tor traffic" activates the skill without any extra prompting.
What's inside
| Section | Content |
|---|---|
| 1. Non-negotiables | Required top-level fields; every enum copied exactly (operator, action.type, algorithm.type, health_check.mode, …); hard constraints (firewall rules need ≥1 condition, rate-limit limit/window_seconds ≥1, location not url for redirects) |
| 2. Minimal config | A copy-paste proxy-everything config with the safe defaults spelled out |
| 3. Condition paths | Every path usable in left, rate-limit key, and cache-key parts: req.*, headers/cookies/query, JWT claims (req.header.authorization.jwt.<claim.path>), and all ip.* fields |
| 4. Recipes | Firewall (anonymizers, geo-fence), rate limiting (global + per-IP), cache (static assets with stale windows), load balancing (2 backends, health checks), TLS (on-demand Let's Encrypt) |
| 5. Workflow | The six-step validation loop, the authoritative check (timeout -k 2 3 ./target/release/quayel-gateway config.json), and a startup-error → fix map |
| 6. Behavior notes | Things that surprise people: injected headers, client-IP sourcing behind Cloudflare/proxies, JSON error bodies, cache status header, in-memory counters |
How the skill thinks
A few rules are baked into every generated config:
- Plugins run in a fixed pipeline —
ip_intel → firewall → rate_limiting → load_balancer → cache → logging— and any plugin can short-circuit the request. - Rules inside a plugin run in array order, first match wins (most specific first).
- Firewall rules must have at least one condition; rate-limit, cache, and load-balancer rules may use
conditions: []to match everything. - Enums are snake_case strings copied exactly —
health_check.modeishttps/accepts_connections/off(there is no"http"mode). - Every change bumps
config_version.
Relationship to the AI Agent Guide
The skill is a condensed, portable version of the AI Agent Guide. When the agent is working inside the quayel-gateway repository, the skill directs it to read docs/ai-guide.md first (and docs/config.schema.json for validation) — the guide is verified against the source and wins over other docs.
Use the skill for day-to-day configuration from any tool; use the AI Agent Guide when you want the complete contract in front of the agent (or your tool has no skills support).