Grpc Integration
Skill Profile
(Select at least one profile to enable specific modules)
Overview
gRPC (Google Remote Procedure Call) is a high-performance, open-source universal RPC framework using Protocol Buffers for serialization, ideal for microservices communication with efficient binary serialization, streaming capabilities, and built-in code generation.
gRPC consists of:
- HTTP/2: High-performance transport protocol
- Protocol Buffers: Efficient binary serialization format
- Code Generation: Auto-generate client and server code
- Streaming: Support for unary, server streaming, client streaming, bidirectional
- Multi-Language: Support for multiple programming languages
- Strong Typing: Type-safe contracts with .proto files
Why This Matters
- Enhance Performance: gRPC can enhance performance by 5-10x compared to REST
- Reduce Latency: HTTP/2 multiplexing reduces latency
- Reduce Bandwidth: Protocol Buffers reduce payload size by up to 70%
- Increase Developer Productivity: Code generation reduces boilerplate code
- Improve Type Safety: Strong typing reduces runtime errors
Core Concepts & Rules
1. Core Principles
- Follow established patterns and conventions
- Maintain consistency across codebase
- Document decisions and trade-offs
2. Implementation Guidelines
- Start with the simplest viable solution
- Iterate based on feedback and requirements
- Test thoroughly before deployment
Inputs / Outputs / Contracts
- Inputs:
- Proto file definitions
- Service requirements
- Authentication requirements
- Streaming requirements
- Entry Conditions:
- Node.js 16+ is available
- gRPC is installed
- Proto files are defined
- Services are available
- Outputs:
- Proto files
- Server implementation
- Client implementation
- Interceptors
- Artifacts Required (Deliverables):
- Proto file definitions
- Server implementation
- Client implementation
- Authentication interceptors
- TLS configuration
- Acceptance Evidence:
- RPCs work correctly
- Streaming works correctly
- Authentication is enforced
- TLS is configured
- Success Criteria:
- Services communicate efficiently
- Streaming works
- Authentication is secure
- Performance is high
Skill Composition
Quick Start / Implementation Example
- Review requirements and constraints
- Set up development environment
- Implement core functionality following patterns
- Write tests for critical paths
- Run tests and fix issues
- Document any deviations or decisions
# Example implementation following best practices
def example_function():
# Your implementation here
pass
Assumptions / Constraints / Non-goals
- Assumptions:
- Development environment is properly configured
- Required dependencies are available
- Team has basic understanding of domain
- Constraints:
- Must follow existing codebase conventions
- Time and resource limitations
- Compatibility requirements
- Non-goals:
- This skill does not cover edge cases outside scope
- Not a replacement for formal training
Compatibility & Prerequisites
- Supported Versions:
- Python 3.8+
- Node.js 16+
- Modern browsers (Chrome, Firefox, Safari, Edge)
- Required AI Tools:
- Code editor (VS Code recommended)
- Testing framework appropriate for language
- Version control (Git)
- Dependencies:
- Language-specific package manager
- Build tools
- Testing libraries
- Environment Setup:
.env.example keys: API_KEY, DATABASE_URL (no values)
Test Scenario Matrix (QA Strategy)
| Type |
Focus Area |
Required Scenarios / Mocks |
| Unit |
Core Logic |
Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |
| Integration |
DB / API |
All external API calls or database connections must be mocked during unit tests |
| E2E |
User Journey |
Critical user flows to test |
| Performance |
Latency / Load |
Benchmark requirements |
| Security |
Vuln / Auth |
SAST/DAST or dependency audit |
| Frontend |
UX / A11y |
Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |
Technical Guardrails & Security Threat Model
1. Security & Privacy (Threat Model)
- Top Threats: Injection attacks, authentication bypass, data exposure
2. Performance & Resources
3. Architecture & Scalability
4. Observability & Reliability
Agent Directives & Error Recovery
(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)
- Thinking Process: Analyze root cause before fixing. Do not brute-force.
- Fallback Strategy: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.
- Self-Review: Check against Guardrails & Anti-patterns before finalizing.
- Output Constraints: Output ONLY the modified code block. Do not explain unless asked.
Definition of Done (DoD) Checklist
Anti-patterns / Pitfalls
- ⛔ Don't: Log PII, catch-all exception, N+1 queries
- ⚠️ Watch out for: Common symptoms and quick fixes
- 💡 Instead: Use proper error handling, pagination, and logging
Reference Links & Examples
- Internal documentation and examples
- Official documentation and best practices
- Community resources and discussions
Versioning & Changelog
- Version: 1.0.0
- Changelog:
- 2026-02-22: Initial version with complete template structure
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: grpc-integration3description: gRPC (Google Remote Procedure Call) is a high-performance, open-source Use when this capability is needed.4---56# Grpc Integration78## Skill Profile9*(Select at least one profile to enable specific modules)*10- [ ] **DevOps**11- [x] **Backend**12- [ ] **Frontend**13- [ ] **AI-RAG**14- [ ] **Security Critical**1516## Overview17gRPC (Google Remote Procedure Call) is a high-performance, open-source universal RPC framework using Protocol Buffers for serialization, ideal for microservices communication with efficient binary serialization, streaming capabilities, and built-in code generation.1819gRPC consists of:20- **HTTP/2**: High-performance transport protocol21- **Protocol Buffers**: Efficient binary serialization format22- **Code Generation**: Auto-generate client and server code23- **Streaming**: Support for unary, server streaming, client streaming, bidirectional24- **Multi-Language**: Support for multiple programming languages25- **Strong Typing**: Type-safe contracts with .proto files2627## Why This Matters28- **Enhance Performance**: gRPC can enhance performance by 5-10x compared to REST29- **Reduce Latency**: HTTP/2 multiplexing reduces latency30- **Reduce Bandwidth**: Protocol Buffers reduce payload size by up to 70%31- **Increase Developer Productivity**: Code generation reduces boilerplate code32- **Improve Type Safety**: Strong typing reduces runtime errors3334---3536## Core Concepts & Rules3738### 1. Core Principles39- Follow established patterns and conventions40- Maintain consistency across codebase41- Document decisions and trade-offs4243### 2. Implementation Guidelines44- Start with the simplest viable solution45- Iterate based on feedback and requirements46- Test thoroughly before deployment474849## Inputs / Outputs / Contracts50* **Inputs**:51 - Proto file definitions52 - Service requirements53 - Authentication requirements54 - Streaming requirements55* **Entry Conditions**:56 - Node.js 16+ is available57 - gRPC is installed58 - Proto files are defined59 - Services are available60* **Outputs**:61 - Proto files62 - Server implementation63 - Client implementation64 - Interceptors65* **Artifacts Required (Deliverables)**:66 - Proto file definitions67 - Server implementation68 - Client implementation69 - Authentication interceptors70 - TLS configuration71* **Acceptance Evidence**:72 - RPCs work correctly73 - Streaming works correctly74 - Authentication is enforced75 - TLS is configured76* **Success Criteria**:77 - Services communicate efficiently78 - Streaming works79 - Authentication is secure80 - Performance is high8182## Skill Composition83* **Depends on**: [error-handling](../error-handling/SKILL.md)84* **Compatible with**: [express-rest](../express-rest/SKILL.md), [nodejs-api](../nodejs-api/SKILL.md)85* **Conflicts with**: None86* **Related Skills**: [service-design](../../09-microservices/service-design/SKILL.md), [service-discovery](../../09-microservices/service-discovery/SKILL.md)8788---8990## Quick Start / Implementation Example91921. Review requirements and constraints932. Set up development environment943. Implement core functionality following patterns954. Write tests for critical paths965. Run tests and fix issues976. Document any deviations or decisions9899```python100# Example implementation following best practices101def example_function():102 # Your implementation here103 pass104```105106107## Assumptions / Constraints / Non-goals108109* **Assumptions**:110 - Development environment is properly configured111 - Required dependencies are available112 - Team has basic understanding of domain113* **Constraints**:114 - Must follow existing codebase conventions115 - Time and resource limitations116 - Compatibility requirements117* **Non-goals**:118 - This skill does not cover edge cases outside scope119 - Not a replacement for formal training120121122## Compatibility & Prerequisites123124* **Supported Versions**:125 - Python 3.8+126 - Node.js 16+127 - Modern browsers (Chrome, Firefox, Safari, Edge)128* **Required AI Tools**:129 - Code editor (VS Code recommended)130 - Testing framework appropriate for language131 - Version control (Git)132* **Dependencies**:133 - Language-specific package manager134 - Build tools135 - Testing libraries136* **Environment Setup**:137 - `.env.example` keys: `API_KEY`, `DATABASE_URL` (no values)138139140## Test Scenario Matrix (QA Strategy)141142| Type | Focus Area | Required Scenarios / Mocks |143| :--- | :--- | :--- |144| **Unit** | Core Logic | Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |145| **Integration** | DB / API | All external API calls or database connections must be mocked during unit tests |146| **E2E** | User Journey | Critical user flows to test |147| **Performance** | Latency / Load | Benchmark requirements |148| **Security** | Vuln / Auth | SAST/DAST or dependency audit |149| **Frontend** | UX / A11y | Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |150151152## Technical Guardrails & Security Threat Model153154### 1. Security & Privacy (Threat Model)155* **Top Threats**: Injection attacks, authentication bypass, data exposure156- [ ] **Data Handling**: Sanitize all user inputs to prevent Injection attacks. Never log raw PII157- [ ] **Secrets Management**: No hardcoded API keys. Use Env Vars/Secrets Manager158- [ ] **Authorization**: Validate user permissions before state changes159160### 2. Performance & Resources161- [ ] **Execution Efficiency**: Consider time complexity for algorithms162- [ ] **Memory Management**: Use streams/pagination for large data163- [ ] **Resource Cleanup**: Close DB connections/file handlers in finally blocks164165### 3. Architecture & Scalability166- [ ] **Design Pattern**: Follow SOLID principles, use Dependency Injection167- [ ] **Modularity**: Decouple logic from UI/Frameworks168169### 4. Observability & Reliability170- [ ] **Logging Standards**: Structured JSON, include trace IDs `request_id`171- [ ] **Metrics**: Track `error_rate`, `latency`, `queue_depth`172- [ ] **Error Handling**: Standardized error codes, no bare except173- [ ] **Observability Artifacts**:174 - **Log Fields**: timestamp, level, message, request_id175 - **Metrics**: request_count, error_count, response_time176 - **Dashboards/Alerts**: High Error Rate > 5%177178179## Agent Directives & Error Recovery180*(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)*181182- **Thinking Process**: Analyze root cause before fixing. Do not brute-force.183- **Fallback Strategy**: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.184- **Self-Review**: Check against Guardrails & Anti-patterns before finalizing.185- **Output Constraints**: Output ONLY the modified code block. Do not explain unless asked.186187188## Definition of Done (DoD) Checklist189190- [ ] Tests passed + coverage met191- [ ] Lint/Typecheck passed192- [ ] Logging/Metrics/Trace implemented193- [ ] Security checks passed194- [ ] Documentation/Changelog updated195- [ ] Accessibility/Performance requirements met (if frontend)196197198## Anti-patterns / Pitfalls199200* ⛔ **Don't**: Log PII, catch-all exception, N+1 queries201* ⚠️ **Watch out for**: Common symptoms and quick fixes202* 💡 **Instead**: Use proper error handling, pagination, and logging203204205## Reference Links & Examples206207* Internal documentation and examples208* Official documentation and best practices209* Community resources and discussions210211212## Versioning & Changelog213214* **Version**: 1.0.0215* **Changelog**:216 - 2026-02-22: Initial version with complete template structure217218---219> Converted and distributed by [TomeVault](https://tomevault.io/claim/amnadtaowsoam) — claim your Tome and manage your conversions.220<!-- tomevault:4.0:skill_md:2026-04-13 -->