# Network Engineer

> Configures and troubleshoots network infrastructure: DNS records, reverse proxies, SSL certificates, firewalls, CDNs, and load balancers.

- Skill: `leandrobenjaminl/network-engineer` (Agent Skill)
- Install (CLI): `npx skillmds@latest add leandrobenjaminl/network-engineer`
- Raw SKILL.md: https://api.skillmd.com/api/skills/leandrobenjaminl/network-engineer/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra, Coding & Dev Tools, Security, Cloud Platforms, Deployment & Release
- Tags: Caddy, Dns, Firewall, Load Balancing, Nginx, Reverse Proxy, Ssl, Traefik
- License: MIT
- Author: LeandroBenjaminL (https://skillmd.com/u/leandrobenjaminl)
- Updated: 2026-08-22
- Page: https://skillmd.com/skills/leandrobenjaminl/network-engineer

---


# Skill: network-engineer

Redes bien hechas. DNS, proxies, firewalls, TLS — la capa que nadie ve hasta que falla.

## Trigger

- Hay que configurar DNS para un dominio
- Necesitás un reverse proxy (Nginx, Caddy, Traefik)
- Un certificado SSL venció o hay que renovarlo
- Problemas de conectividad entre servicios
- Configurar firewall, CDN o load balancer

## Workflow LEND

1. ANALIZAR
   ├── Stack: Nginx, Caddy, Traefik, Cloudflare, AWS, HAProxy
   ├── Estado actual: ¿qué está funcionando? ¿qué no?
   ├── Requisitos: SSL, CDN, balanceo, WAF?
   └── Riesgo: ¿es producción? ¿hay downtime aceptable?

2. OFRECER (Menú del Senior)
   ├── A) Reverse proxy simple — Nginx/Caddy con SSL automático (acme.sh/certbot)
   ├── B) Stack completo — proxy + CDN (Cloudflare) + WAF + balanceo
   └── C) Mesh/infra moderna — Tailscale + Caddy + internal DNS

3. ELEGIR → confirmación

4. HACER
   ├── DNS: registrar A/AAAA/CNAME, TTL adecuado, propagación verificada
   ├── SSL: Let's Encrypt con certbot o acme.sh, renovación automática
   ├── Reverse proxy: Nginx/Caddy config, upstreams, headers, rate limiting
   ├── Firewall: iptables/nftables o security groups, mínimo privilegio
   ├── CDN: Cloudflare/CloudFront, caching, purging
   └── Load balancing: ALB/NLB/HAProxy, healthchecks, sticky sessions si aplica

5. VERIFICAR
   ├── DNS resuelve correctamente (dig +noshort)
   ├── SSL válido (curl -vI https://dominio)
   ├── Proxy responde (curl -H "Host: dominio" localhost)
   └── Firewall permite solo lo necesario (nmap desde afuera)

