All skills
debabratasaha-dev avatar

/backend-engineer

@a1f81fa

Professional backend engineering for production-grade APIs, services, workers, databases, authentication, authorization, integrations, queues, observability, testing, reliability, and security. Use when the agent needs to build, improve, review, debug, or harden backend systems in Node.js, Python, Go, Java, .NET, Ruby, PHP, SQL, NoSQL, REST, GraphQL, WebSockets, event-driven systems, or similar backend stacks. Triggers on requests to build APIs, services, workers, webhook handlers, auth systems, database layers, background jobs, queues, cron tasks, billing flows, or server-side features. Also triggers on requests to fix slow queries, race conditions, deadlocks, failing tests, deployment issues, or to review backend code for security, correctness, and reliability.

Use this Skill: https://skilld.dev/gh/debabratasaha-dev/techskills/backend-engineer

This session only. Nothing lands on disk.

referencesreliability-patterns.md

≈836 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Reliability Patterns

Reference for building resilient backend systems. Read when implementing workers, queues, external integrations, caching, or operational infrastructure.


Table of Contents


Retries

  • Exponential backoff with jitter: delay = base * 2^attempt + random(0, base).
  • Max retry count: 3–5 for API calls, 5–10 for queue jobs.
  • Only retry transient errors (5xx, timeouts, connection errors). Never retry 4xx.
  • After max retries, route to dead-letter queue or alert.

Idempotency

  • Workers must produce same result regardless of how many times message is processed.
  • Use idempotency keys: store (key, result) with unique constraint.
  • Use database upserts for naturally idempotent writes.
  • Check "already processed" before side effects (emails, payments).
  • Set TTL on idempotency records (24–72 hours).

Dead-Letter Queues

  • Route messages exceeding max retry count to DLQ.
  • Include: original message, error details, retry count, timestamp.
  • Monitor DLQ size. Alert when messages appear.
  • Build tooling to inspect, replay, or discard DLQ messages.

Scheduled Jobs

  • Make scheduled jobs idempotent.
  • Use distributed locks (Redis SETNX, database advisory locks) for multi-instance.
  • Log job start, completion, duration, items processed.
  • Set timeout to prevent runaway execution.

Worker Concurrency

  • CPU-bound: match CPU cores. I/O-bound: 2–4x cores. Start at 2x, adjust.
  • Separate queues for different priorities.
  • Implement backpressure when downstream overloaded.

External API Timeouts

  • Set connect timeout (3–5s) and read timeout (10–30s) on every HTTP client.
  • Never use infinite timeouts.
  • Tighter timeouts on user-facing paths (5–10s total).

Circuit Breakers

States: Closed (normal) → Open (fail fast) → Half-Open (test).

  • Per-dependency circuit breakers. Not global.
  • Return fallback when open (cached data, defaults).
  • Config: 5 failures in 60s → open for 30s → half-open with 3 test requests.

Caching and Invalidation

Strategy Best for
TTL API responses, config
Write-through User profiles, settings
Event-based Inventory, pricing
  • Set TTL on every cache entry. No unbounded caches.
  • Cache-aside pattern for most cases.
  • Handle cache stampede with locking or stale-while-revalidate.
  • Never cache sensitive data in shared caches.

Graceful Shutdown

  1. Stop accepting new requests.
  2. Drain in-flight requests (timeout 30s).
  3. Close database/cache connections.
  4. Flush logs and metrics.
  5. Exit.

Handle SIGTERM/SIGINT. Drain timeout < orchestrator kill timeout.

Health Checks

Liveness (/health/live): process alive? Lightweight 200 response. No dependency checks.

Readiness (/health/ready): can handle requests? Check database, cache, queue connections. Timeout 2–5s.

Keep health check queries cheap (SELECT 1). No sensitive info in responses.

Source: SKILL.md on GitHub

No alerts18d3 checks · Risk SAFE
  • Gen Agent Trust Hub18d

    The skill provides comprehensive, high-quality engineering guidelines and references for backend development. It focuses on security best practices, such as input validation, authorization, and secure secret handling, without any detected malicious patterns.

  • Socket18d

    No alerts

  • Snyk18d

    Risk: LOW · No issues

Signed by skilld at a1f81fa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 4 months ago
metadata
{
  "version": "1.0.0"
}

README badge

README badge for debabratasaha-dev/techskills/backend-engineer