Engineer Secure and Optimized Network Architectures
Modern cloud networking expert: multi-cloud architecture, service mesh, zero-trust security, and performance optimization.
Why it matters
Leverage expert network engineering knowledge to design, implement, and optimize secure, scalable, and high-performance network solutions across multi-cloud environments. Ensure robust security, efficient traffic management, and seamless connectivity.
Outcomes
What it gets done
Design and implement cloud networking solutions (AWS, Azure, GCP)
Configure load balancing, DNS, and SSL/TLS for optimal performance and security
Implement zero-trust architectures and advanced network security measures
Troubleshoot network issues and perform performance analysis
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/ag-network-engineer | bash Overview
Network Engineer
Provides expert guidance on modern cloud and multi-cloud networking, covering service mesh, zero-trust security, load balancing, and performance optimization. Use when designing multi-cloud network architecture, implementing zero-trust security, or troubleshooting service mesh connectivity.
What it does
Provides expert guidance on modern cloud networking, security, and performance optimization - covering multi-cloud networking, service mesh technologies, zero-trust architectures, load balancing, DNS, SSL/TLS, and advanced troubleshooting.
When to use - and when NOT to
Use this skill when designing multi-cloud or hybrid network architecture, implementing zero-trust networking, troubleshooting connectivity issues in a Kubernetes service mesh, configuring load balancing or CDN strategy, setting up SSL/TLS with automated certificate management, or planning network disaster recovery and compliance. Not a fit for application-layer development unrelated to network design, or for tasks outside network engineering scope.
Inputs and outputs
Covers cloud networking across AWS (VPC, subnets, route tables, NAT/Internet gateways, Transit Gateway), Azure (virtual networks, NSGs, Load Balancer, Application Gateway, VPN Gateway), and GCP (VPC networks, Cloud Load Balancing, Cloud NAT, Cloud Interconnect), plus multi-cloud and edge networking (CDN, 5G, IoT connectivity).
Load balancing guidance spans cloud load balancers (ALB/NLB, Azure LB, GCP Cloud LB), software load balancers (Nginx, HAProxy, Envoy, Traefik, Istio Gateway), Layer 4/7 balancing, global traffic distribution, and API gateways (Kong, Ambassador, AWS/Azure API Gateway). DNS guidance covers BIND/PowerDNS/cloud DNS, service discovery (Consul, etcd, Kubernetes DNS), DNS security (DNSSEC, DoH, DoT), and advanced patterns like split-horizon and anycast DNS.
SSL/TLS and PKI guidance covers certificate management (Let's Encrypt, commercial/internal CAs, automation), protocol/cipher tuning, mTLS implementation, and full PKI architecture. Security guidance covers zero-trust networking, firewall technologies, Kubernetes/service mesh network policies, VPN solutions (WireGuard, IPSec, SD-WAN), and DDoS protection. Service mesh and container networking guidance covers Istio/Linkerd/Consul Connect, CNI plugins (Calico, Cilium, Flannel), ingress controllers, and east-west traffic management.
Performance guidance covers bandwidth/latency optimization, CDN strategy (CloudFlare, CloudFront, Azure CDN), HTTP/2 and HTTP/3 (QUIC), and capacity planning. Advanced protocol coverage includes gRPC, WebSockets, network virtualization (VXLAN, NVGRE), and emerging technologies (eBPF networking, P4 programming, intent-based networking). Troubleshooting tooling includes tcpdump, Wireshark, iperf3, mtr, cloud-specific flow logs, and application-layer tools (curl, dig, openssl s_client). Infrastructure integration covers network automation via Terraform, Ansible, Netmiko/NAPALM, and GitOps-based configuration management. Also covers compliance (GDPR, HIPAA, PCI-DSS network requirements), monitoring/observability, and disaster recovery/business continuity planning.
Integrations
Spans AWS, Azure, and GCP native networking services, service mesh platforms (Istio, Linkerd, Consul Connect), container networking (Calico, Cilium), CDN providers (CloudFlare, CloudFront), and network automation tooling (Terraform, Ansible, Netmiko, NAPALM).
Who it's for
Network engineers designing or troubleshooting cloud, multi-cloud, or service-mesh networking who need concrete platform, protocol, and tooling guidance across security, performance, and compliance rather than a single-cloud networking primer.
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.