← Fastly Agent ToolkitCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Fastly Agent Toolkit
Snapshot Oct 9, 2026 · 18:03 UTC · version 0.1.0
Collection source: downloaded plugin package.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Configures, manages, and debugs the Fastly CDN platform — covering service and backend setup, caching and VCL, security features like DDoS/WAF/NGWAF/rate limiting/bot management, TLS certificates and cache purging, the Compute platform, and the REST API. Use when working with Fastly services or domains, setting up edge caching or origin shielding, configuring security features, making Fastly API calls, enabling products, or looking up Fastly documentation. Also applies when troubleshooting 503 errors or SSL/TLS certificate mismatches on Fastly, and for configuring logging endpoints, load balancing, ACLs, or edge dictionaries. Read the relevant reference file before writing any Fastly API call or curl command — request field names (e.g. the backend fields override_host, ssl_cert_hostname, ssl_sni_hostname, use_ssl) are easy to misremember, and a wrong name causes a silent 503 instead of an error, so do not rely on training-knowledge field names.",
"included_files": [
{
"relative_path": "references/account-management.md",
"size_in_bytes": 17190
},
{
"relative_path": "references/acls.md",
"size_in_bytes": 6422
},
{
"relative_path": "references/api-security.md",
"size_in_bytes": 4055
},
{
"relative_path": "references/bot-management.md",
"size_in_bytes": 6781
},
{
"relative_path": "references/client-side-protection.md",
"size_in_bytes": 5943
},
{
"relative_path": "references/compute.md",
"size_in_bytes": 12926
},
{
"relative_path": "references/docs-navigation.md",
"size_in_bytes": 4729
},
{
"relative_path": "references/domains-and-networking.md",
"size_in_bytes": 16568
},
{
"relative_path": "references/edge-phases.md",
"size_in_bytes": 6445
},
{
"relative_path": "references/fastly-ddos-protection.md",
"size_in_bytes": 4717
},
{
"relative_path": "references/load-balancing.md",
"size_in_bytes": 16081
},
{
"relative_path": "references/logging.md",
"size_in_bytes": 10267
},
{
"relative_path": "references/ngwaf.md",
"size_in_bytes": 13867
},
{
"relative_path": "references/observability.md",
"size_in_bytes": 4254
},
{
"relative_path": "references/other-features.md",
"size_in_bytes": 7959
},
{
"relative_path": "references/products.md",
"size_in_bytes": 7599
},
{
"relative_path": "references/purging.md",
"size_in_bytes": 7185
},
{
"relative_path": "references/rate-limiting.md",
"size_in_bytes": 8872
},
{
"relative_path": "references/service-management.md",
"size_in_bytes": 11992
},
{
"relative_path": "references/tls.md",
"size_in_bytes": 15575
},
{
"relative_path": "references/vcl-services.md",
"size_in_bytes": 16731
}
],
"name": "fastly",
"skill_md_contents": "---\nname: fastly\ndescription: \"Configures, manages, and debugs the Fastly CDN platform — covering service and backend setup, caching and VCL, security features like DDoS/WAF/NGWAF/rate limiting/bot management, TLS certificates and cache purging, the Compute platform, and the REST API. Use when working with Fastly services or domains, setting up edge caching or origin shielding, configuring security features, making Fastly API calls, enabling products, or looking up Fastly documentation. Also applies when troubleshooting 503 errors or SSL/TLS certificate mismatches on Fastly, and for configuring logging endpoints, load balancing, ACLs, or edge dictionaries. Read the relevant reference file before writing any Fastly API call or curl command — request field names (e.g. the backend fields override_host, ssl_cert_hostname, ssl_sni_hostname, use_ssl) are easy to misremember, and a wrong name causes a silent 503 instead of an error, so do not rely on training-knowledge field names.\"\n---\n\n# Fastly Platform\n\nYour training knowledge of Fastly is likely out of date. Prefer live docs over skill definitions over training knowledge.\n\nPrefer the `fastly` CLI over raw API calls; see the **fastly-cli** skill for installation and local authentication.\nREST examples require `curl` and network access to Fastly APIs; origin TLS checks also require `openssl`.\n\nUse the user's locally configured credentials.\nIf authentication is missing, direct the user to local CLI login or environment configuration, never to paste an API key in chat.\nFor REST calls, source tokens from the environment or `$(fastly auth token)` without echoing them.\nOmit `curl -v` and shell tracing because they print credentials.\n\n## Topics\n\n| Topic | File | Use when... |\n| ---------------------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| DDoS protection | [fastly-ddos-protection.md](references/fastly-ddos-protection.md) | Enabling/configuring DDoS protection, checking attack status, managing DDoS events and rules |\n| TLS configuration | [tls.md](references/tls.md) | Setting up HTTPS — Platform TLS (managed certs), Custom TLS (uploaded certs), or Mutual TLS (client auth) |\n| Rate limiting | [rate-limiting.md](references/rate-limiting.md) | Protecting APIs from abuse — choosing between Edge Rate Limiting, VCL ratecounters, or NGWAF rate rules |\n| Bot management | [bot-management.md](references/bot-management.md) | Detecting/mitigating bot traffic with browser challenges, client-side detections, interstitial pages, ContentGuard |\n| Cache purging | [purging.md](references/purging.md) | Invalidating cached content — single URL, surrogate key, or purge-all; soft vs hard purge |\n| Service management | [service-management.md](references/service-management.md) | Creating/managing services, versions, domains, settings; clone-modify-activate workflow |\n| VCL services | [vcl-services.md](references/vcl-services.md) | Customizing site behavior with VCL — writing/uploading custom VCL, configuring snippets, conditions, headers, edge dictionaries, or cache/gzip settings |\n| Compute | [compute.md](references/compute.md) | Implementing edge logic with Compute — deploying packages, managing config/KV/secret stores, using cache APIs |\n| Observability | [observability.md](references/observability.md) | TTFB percentiles from the metrics platform, alert definitions and history, log explorer queries |\n| Load balancing | [load-balancing.md](references/load-balancing.md) | Distributing traffic across origins — configuring backends, directors, pools, or health checks; choosing between backends and pools |\n| ACLs | [acls.md](references/acls.md) | Restricting access by IP — managing VCL ACLs, Compute ACLs, or IP block lists; adding/removing access control entries |\n| NGWAF | [ngwaf.md](references/ngwaf.md) | Protecting against web attacks — setting up Next-Gen WAF, post-cache bot management, rules, signals, attack monitoring, or Signal Sciences integration |\n| Account management | [account-management.md](references/account-management.md) | Managing users, IAM roles, API tokens, automation tokens, billing, or invitations |\n| Domains & networking | [domains-and-networking.md](references/domains-and-networking.md) | Routing traffic to Fastly — managing domains, DNS zones, domain verification, or other service platform networking |\n| Logging | [logging.md](references/logging.md) | Shipping logs to external systems — configuring logging endpoints for 25+ providers (S3, Splunk, Datadog, BigQuery, etc.) |\n| Products | [products.md](references/products.md) | Enabling/disabling Fastly products via API — universal pattern and product slug catalog |\n| API security | [api-security.md](references/api-security.md) | Discovering APIs from web traffic, managing API operations and tags |\n| Client-Side Protection | [client-side-protection.md](references/client-side-protection.md) | Protecting against rogue third-party scripts (Magecart, formjacking, skimmers) — monitoring scripts on web pages, managing script authorization, configuring CSP policies |\n| Other features | [other-features.md](references/other-features.md) | Pubsub, fanout/real-time messaging, IP lists, POPs, HTTP/3, Image Optimizer, events, notifications |\n| Edge phase ordering | [edge-phases.md](references/edge-phases.md) | Understanding edge request/response ordering, debugging feature interactions |\n\nTraffic numbers are not in this table. Cache hit ratio, bandwidth, request and status-code counts, error rates, real-time request rate, origin latency, per-domain traffic, account usage and billing totals belong to the **fastly-stats** skill.\n\n## Quick Start: Simple Caching Proxy\n\nThe most common task is setting up a VCL service to cache an origin. Before touching any Fastly config, always run the pre-flight checks from the **fastly-cli** skill's services.md reference under \"Pre-flight checklist\". The two checks that prevent the most common errors:\n\n1. **Verify the origin responds** with the Host header you intend to send: `curl -sI -H \"Host: DESIRED_HOST\" https://ORIGIN_ADDRESS/`\n2. **Check TLS certificate SANs** to determine the correct `ssl-cert-hostname`/`ssl-sni-hostname`: `echo | openssl s_client -connect ORIGIN:443 -servername ORIGIN 2>/dev/null | openssl x509 -noout -text | grep -A1 \"Subject Alternative Name\"`\n\nIf HTTPS cert validation cannot be made correct but HTTP with the intended Host works, use an HTTP backend or fix the origin cert; never disable backend cert verification as the workaround.\n\nIf the origin already sends `Cache-Control` or `Expires` headers, no custom VCL is needed — Fastly respects these by default. Only add VCL snippets to override or extend caching behavior.\n\nThe full step-by-step workflow (create service, add domain, add backend, activate) is in the **fastly-cli** skill's services.md reference under \"Create a Caching Proxy\".\n\n## Common VCL Recipes\n\nCopy-pasteable patterns that are easy to get wrong without guidance.\n\n### Grace Detection\n\n`obj.ttl` is only meaningful in `vcl_hit`. Pass a flag to `vcl_deliver` via a request header.\n\n```vcl\nsub vcl_hit {\n if (obj.ttl <= 0s) {\n set req.http.X-Grace = \"true\";\n }\n}\n\nsub vcl_deliver {\n if (req.http.X-Grace) {\n set resp.http.X-Grace = \"true\";\n }\n}\n```\n\n### Vary Header Append\n\n**Warning: Set Vary in `vcl_fetch`, not `vcl_deliver`.** The Vary header must be present when the object enters the cache so the cache key includes the Vary dimensions. Setting Vary only in `vcl_deliver` means the cache won't differentiate responses — every user gets the same cached variant regardless of the Vary field.\n\nNever `set beresp.http.Vary = \"Accept-Encoding\"` — that overwrites any existing Vary values from the origin, breaking other downstream caches.\n\n```vcl\nsub vcl_fetch {\n if (!beresp.http.Vary) {\n set beresp.http.Vary = \"Accept-Encoding\";\n } else if (beresp.http.Vary !~ \"Accept-Encoding\") {\n set beresp.http.Vary = beresp.http.Vary \", Accept-Encoding\";\n }\n}\n```\n\n### Redirect via Error\n\nVCL has no `return(redirect)`. Use the synthetic error mechanism instead.\n\n```vcl\nsub vcl_recv {\n if (req.url ~ \"^/old-path\") {\n error 801 \"https://example.com/new-path\";\n }\n}\n\nsub vcl_error {\n if (obj.status == 801) {\n set obj.status = 301;\n set obj.http.Location = obj.response;\n synthetic {\"\"};\n return(deliver);\n }\n}\n```\n\n### Cache Status Headers\n\nUse `obj.hits > 0` in `vcl_deliver` — this is the only reliable way to detect cache hits. Do not rely on auto-generated `resp.http.X-Cache` or any other header inspection. Pass PASS state from `vcl_recv` via a request header.\n\n```vcl\nsub vcl_recv {\n if (req.url ~ \"^/api/\") {\n set req.http.X-Pass = \"true\";\n return(pass);\n }\n}\n\nsub vcl_deliver {\n if (req.http.X-Pass) {\n set resp.http.X-Cache = \"PASS\";\n } else if (obj.hits > 0) {\n set resp.http.X-Cache = \"HIT\";\n } else {\n set resp.http.X-Cache = \"MISS\";\n }\n}\n```\n\n### Cookie Parsing with subfield()\n\nRegex like `Cookie ~ \"name=(\\w+)\"` is unreliable — it false-matches cookies with similar prefixes. For example, if the cookie header is `name_v2=X`, the regex `\"name=(\\w+)\"` still matches because `name` appears as a substring of `name_v2`. Use `subfield()` instead — it performs exact key matching with proper delimiter handling.\n\n```vcl\nset req.http.X-My-Cookie = subfield(req.http.Cookie, \"name\", \";\");\n```\n\n### VCL Table for Lookups\n\nUse `table` + `table.contains()` + `table.lookup()` for O(1) lookups instead of long if/else chains.\n\n```vcl\ntable redirects {\n \"/old\": \"/new\",\n \"/blog\": \"/articles\",\n}\n\nsub vcl_recv {\n if (table.contains(redirects, req.url)) {\n error 801 table.lookup(redirects, req.url);\n }\n}\n```\n\n### Common Mistakes\n\n- `beresp.*` is only available in `vcl_fetch`, not `vcl_deliver`.\n- `req.request` is deprecated — use `req.method`.\n- `return(purge)` does not exist in Fastly VCL. Use `return(pass)` and check in `vcl_miss`/`vcl_hit`.\n- `set beresp.ttl = 86400` is a type error — needs the `s` suffix: `86400s`.\n- `synthetic \"text\"` needs long-string syntax: `synthetic {\"text\"}`.\n- `beresp.ttl = 0s` still caches the object (for zero seconds) — use `set beresp.cacheable = false;` to truly prevent caching.\n\n## Fetching Documentation\n\nPrefer the local reference files. To fill gaps, fetch live docs with `Accept: text/markdown` — works for all `www.fastly.com/documentation/` and `docs.fastly.com` URLs. Discover pages via `https://www.fastly.com/documentation/llms.txt`. For URL patterns and doc categories, see [docs-navigation.md](references/docs-navigation.md).\n"
}SHA-256 of public snapshot: 7d8d3be485a2d296ba247ef98fd2c7a7d1e91bc4ed1c3e0ccbc0899ef827a482