planetscale-traffic-control-recommendations
Build a safe recommendation plan for PlanetScale Postgres Database Traffic Control budgets and rules without applying them.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 47b1a25a966b1317… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Database Traffic Control recommendations
Purpose
For PlanetScale Postgres, recommend Traffic Control budgets and rules that protect critical traffic from runaway queries, traffic spikes, batch jobs, agents, and third-party integrations. Do not create or change budgets without approval.
Preconditions
Run this skill only for PlanetScale Postgres.
Before recommending rules, inspect:
- Current budgets and rules.
- Insights query patterns.
- Current query tags.
- Application routes and jobs.
- Known critical paths.
- Known expensive non-critical paths.
- Active incidents or recent anomalies.
If query tags are missing, recommend tagging first unless a fingerprint-specific rule is clearly needed for an immediate known offender.
Candidate traffic slices
Look for:
- Exports.
- Reports.
- Search endpoints.
- Admin dashboards.
- Backfills.
- Workers and queues.
- Webhooks from third-party systems.
- BI tools.
- Agent-generated read queries.
- High-frequency polling.
- Known expensive query fingerprints.
- Customer-triggered endpoints with high variance.
Budget modes
Recommend in this order:
warnmode first for normal rollout.- Observe warnings and false positives.
- Tune tags, fingerprints, and thresholds.
- Move to
enforceonly with explicit approval and an emergency rollback path.
Do not recommend starting directly in enforce unless there is an active incident and the operator explicitly asks for emergency mitigation.
Rule strategy
Prefer tag-based rules when tags are stable and bounded:
source=agentsource=bifeature=exportfeature=reportroute=/admin/reportsjob=DailyBackfillservice=analytics-worker
Use fingerprint rules when:
- A specific known query pattern is dangerous.
- Tagging is missing or unreliable.
- The query source is hard to attribute.
Use a separate budget for each materially different traffic class.
Do not combine unrelated traffic in one budget because it hides who is consuming the budget.
Suggested default budgets
Use these as recommendation patterns, not as values to apply blindly.
Agent budget
Target: queries tagged source=agent or source=mcp.
Intent: prevent agents from starving application traffic.
Mode: start in warn.
Recommendation: agents should prefer replicas and read-only scopes. Writes require human approval.
Export/reporting budget
Target: feature=export, feature=report, or specific report route/job.
Intent: keep customer-triggered reporting from consuming all database resources.
Mode: start in warn; consider enforce after observation.
Background job budget
Target: worker service, queue, or job tags.
Intent: prevent backfills and retries from starving interactive traffic.
Mode: warn first; enforce only after confirming queue backpressure behavior.
Third-party integration budget
Target: source=integration, partner-specific bounded tags, or route templates for inbound integration calls.
Intent: isolate unpredictable partner behavior.
Mode: warn first.
Known fingerprint budget
Target: specific expensive query fingerprint.
Intent: contain a known pathological query while code or schema fixes are developed.
Mode: warn first unless emergency.
“Each tag value” strategy
When PlanetScale supports applying a budget separately for each unique value of a selected tag, recommend it for bounded tags such as:
applicationserviceroutewhen normalizedjobfeaturesource
Do not recommend it for unbounded tags such as user IDs, request IDs, raw tenant IDs, emails, UUIDs, or raw URLs.
Limits and caveats to include
Every recommendation must explain:
- Traffic Control limits resource use; it does not replace query tuning.
- It is not a web application firewall.
- It does not replace application-level rate limits.
- Limits are guardrails, not exact guarantees for every failure mode.
- Bad tags create bad rules.
- Enforce mode can reject queries and affect application behavior.
Output format
For each proposed budget:
- Budget name.
- Target branch.
- Mode: off, warn, or enforce.
- Matched traffic slice.
- Rule type: tag, fingerprint, keyspace, query kind.
- Proposed tags or fingerprint.
- Limit rationale.
- Queries seen in Insights that justify it.
- Safety risk.
- Test/observe plan.
- Rollback plan.
- Approval requirement.
End with:
“No Traffic Control budgets or rules have been created, updated, deleted, or enforced.”
Files
1- SKILL.md
45dcc41f4d4.6 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from planetscale/skills8
Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extr
A concise feature matrix for deciding which PlanetScale safety, observability, and automation recommendations apply by engine.
Enforce explicit approval gates for any PlanetScale, database, repository, credential, network, or automation mutation.
Inspect an application repository connected to PlanetScale and recommend SQLCommenter-compatible query tagging packages and conventions.
Produce the final PlanetScale best-practices report after running the inventory and relevant review skills.
Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.
Review PlanetScale Postgres for Traffic Control, query tags, roles, pg_strict, backups/PITR, private connectivity, webhooks, branches, and safe agent operation.
Use the PlanetScale CLI (pscale) from automated agents with --format json, auth check, pscale sql, and per-command --force. Run before other PlanetScale skills when driving pscale directly. Use when the user asks to automate pscale, run CLI commands headless, or verify pscale auth from an agent.
Related database skillsscan passed
Direct PubMed and NCBI E-utilities search workflows for biomedical literature, MeSH queries, PMID lookup, citation retrieval, and API-backed literature monitoring. Use when a task needs biomedical literature from PubMed rather than general web search.
Use when the user wants to provision infrastructure or third-party services using Stripe Projects. Triggers: "I need a database", "set up auth", "add caching", "give me a Postgres", "provision Redis", "I need hosting", "add a vector DB", "get me an API key for X", "get credentials for X", "sign up f
Build and troubleshoot Cloudflare Basin analytics workflows with Basin Pipelines, Basin Catalog, and Basin SQL. Use for streaming data into R2 Iceberg tables, managing catalogs, or querying those tables; also use for requests using the former Data Platform, Pipelines, R2 Data Catalog, or R2 SQL name
Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when migrating a database schema in production, such as renaming or dropping a column without downtime (expand/contract). Use when deciding whether to
Sets up, manages, queries, and configures Cloud Firestore databases (Standard/Enterprise edition), including data modeling, security rules, indexes, and SDK integrations (Web, Python, iOS, Android, Flutter). Use when creating/listing Firestore databases, defining data models/indexes, writing SDK que
Full inventory and audit of AWS Glue Data Catalog assets across S3 Tables, Redshift-federated, and remote Iceberg catalogs. Triggers on: inventory the catalog, audit databases, list all tables, catalog overview, data landscape, enumerate catalogs, data inventory, search the catalog. Do NOT use for f