Token导航 LogoToken导航TokenDH.com
运维和基础设施敏感数据github未标认证来源可访问许可证需确认审计通过

apollo-router阿波罗路由器

Agent Skill

apollo-router 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

14,321

周安装

585

GitHub Stars

56

下载量

4,586
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:apollo-router(阿波罗路由器)
来源仓库:https://github.com/apollographql/skills
仓库路径:skills/apollo-router
安装命令:
npx skills add https://github.com/apollographql/skills --skill apollo-router
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/apollographql/skills --skill apollo-router

简介

apollo-router 是高性能图路由引擎,专为 Apollo Federation 2 超图设计,负责查询计划与响应组装。

  • 支持 CORS、JWT 认证与连接器配置生成,适用于微服务架构下的 GraphQL 网关部署。
  • 使用时需明确目标 Router 版本(v1 或 v2),因两者配置 schema 存在不兼容变更。
  • 安装前应确认是否会修改系统服务或执行 Rust 编译操作,避免影响线上环境。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

Apollo Router Config Generator

Apollo Router is a high-performance graph router written in Rust for running Apollo Federation 2 supergraphs. It sits in front of your subgraphs and handles query planning, execution, and response composition.

This skill generates version-correct configuration. Router v1 and v2 have incompatible config schemas in several critical sections (CORS, JWT auth, connectors). Always determine the target version before generating any config.

Step 1: Version Selection

Ask the user before generating any config:

Which Apollo Router version are you targeting?

  [1] Router v2.x (recommended — current LTS, required for Connectors)
  [2] Router v1.x (legacy — end-of-support announced, security patches only)
  [3] Not sure — help me decide

If the user picks [3], display:

Quick guide:

  • Pick v2 if: you're starting fresh, using Apollo Connectors for REST APIs,
    or want backpressure-based overload protection.
  • Pick v1 if: you have an existing deployment and haven't migrated yet.
    Note: Apollo ended active support for v1.x. The v2.10 LTS (Dec 2025)
    is the current baseline. Migration is strongly recommended.

  Tip: If you have an existing router.yaml, you can auto-migrate it:
    router config upgrade router.yaml

Store the selection as ROUTER_VERSION=v1|v2 to gate all subsequent template generation.

Step 2: Environment Selection

Ask: Production or Development?

  • Production: security-hardened defaults (introspection off, sandbox off, homepage off, subgraph errors hidden, auth required, health check on)
  • Development: open defaults (introspection on, sandbox on, errors exposed, text logging)

Load the appropriate base template from:

  • templates/{version}/production.yaml
  • templates/{version}/development.yaml

Step 3: Feature Selection

Ask which features to include:

  • JWT Authentication
  • CORS (almost always yes for browser clients)
  • Operation Limits
  • Traffic Shaping / Rate Limiting
  • Telemetry (Prometheus, OTLP tracing, JSON logging)
  • APQ (Automatic Persisted Queries)
  • Connectors (REST API integration — Router v2 only; GA key is connectors, early v2 preview key was preview_connectors)
  • Subscriptions
  • Header Propagation
  • Response Caching (entity + root field caching with Redis — Router v2 only, v2.6.0+)

Step 4: Gather Parameters

For each selected feature, collect required values.

  • Use section templates from templates/{version}/sections/ for auth, cors, headers, limits, telemetry, and traffic-shaping.
  • For Connectors in v2, use templates/v2/sections/connectors.yaml as the source.
  • For APQ and subscriptions, copy the snippet from the selected base template (templates/{version}/production.yaml or templates/{version}/development.yaml) or from references.
  • Only offer Connectors when ROUTER_VERSION=v2.

CORS

  • List of allowed origins (never use "*" for production)

JWT Authentication

  • JWKS URL
  • Issuer(s) — note: v1 uses singular issuer, v2 uses plural issuers array

Connectors (v2 only)

  • Subgraph name and source name (used as connectors.sources.<subgraph>.<source>)
  • Optional $config values for connector runtime configuration
  • If migrating old v2 preview config, rename preview_connectors to connectors

Operation Limits

Present the tuning guidance:

Operation depth limit controls how deeply nested a query can be.

  Router default: 100 (permissive — allows very deep queries)
  Recommended starting point: 50

  Lower values (15–25) are more secure but will reject legitimate queries
  in schemas with deep entity relationships or nested fragments.
  Higher values (75–100) are safer for compatibility but offer less
  protection against depth-based abuse.

  Tip: Run your router in warn_only mode first to see what depths your
  real traffic actually uses, then tighten:
    limits:
      warn_only: true

What max_depth would you like? [default: 50]

The same principle applies to max_height, max_aliases, and max_root_fields.

Telemetry

  • OTEL collector endpoint (default: http://otel-collector:4317)
  • Prometheus listen port (default: 9090)
  • Trace sampling rate (default: 0.1 = 10%)

Traffic Shaping

  • Client-facing rate limit capacity (default: 1000 req/s)
  • Router timeout (default: 60s)
  • Subgraph timeout (default: 30s)

Response Caching (v2 only, v2.6.0+)

Security: data leakage risk. Before generating any response cache config, you MUST ask the user which types and fields return user-specific data. Cached data defaults to shared — subgraph responses without Cache-Control: private are visible to all users. User-specific subgraphs must return Cache-Control: private and have private_id configured on the router.
  • Ask: Which subgraphs serve user-specific data? (e.g., accounts, profiles, carts)
  • Ask: How do you identify users? (JWT sub claim, session token, API key)
  • Redis URL (default: redis://localhost:6379)
  • Default TTL (default: 5m)
  • Enable active invalidation? If yes: invalidation listen address and shared key
  • Use section template: templates/v2/sections/response-caching.yaml
  • For security requirements, schema directives, and advanced config: references/response-caching.md (start with the Security section)

Step 5: Generate Config

  1. Load the correct version template from templates/{version}/
  2. Assemble section templates for supported sectioned features, then merge base-template snippets for APQ/subscriptions as needed
  3. Inject user-provided parameters
  4. Add a comment block at the top stating the target version

Step 6: Validate

Run the post-generation checklist:

  • All env vars referenced in config are documented
  • CORS origins don't include wildcards (production)
  • Rate limiting is on router: (client-facing), not only all: (subgraph)
  • JWT uses issuers (v2) not issuer (v1), or vice versa
  • If production: introspection=false, sandbox=false, subgraph_errors=false
  • Health check is enabled
  • Homepage is disabled (production)
  • Run: router config validate <file> if Router binary is available

Required Validation Gate (always run)

After generating or editing any router.yaml, you MUST:

  1. Run validation/checklist.md and report pass/fail for each checklist item.
  2. Run router config validate <path-to-router.yaml> if Router CLI is available.
  3. If Router CLI is unavailable, state that explicitly and still complete the checklist.
  4. Do not present the configuration as final until validation is completed.

Step 7: Conditional Next Steps Handoff

After answering any Apollo Router request (config generation, edits, validation, or general Router guidance), decide whether the user already has runnable prerequisites:

  • GraphOS-managed path: APOLLO_KEY + APOLLO_GRAPH_REF, or
  • Local path: a composed supergraph.graphql plus reachable subgraphs

If prerequisites are already present, do not add extra handoff text.

If prerequisites are missing or unknown, end with a concise Next steps handoff (1-3 lines max) that is skill-first and command-free:

  1. Suggest the rover skill to compose or fetch the supergraph schema.
  2. Suggest continuing with apollo-router once the supergraph is ready to validate and run with the generated config.
  3. If subgraphs are missing, suggest apollo-server, graphql-schema, and graphql-operations skills to scaffold and test.

Do not include raw shell commands in this handoff unless the user explicitly asks for commands.

Quick Start (skill-first)

  1. Use this apollo-router skill to generate or refine router.yaml for your environment.
  2. Choose a runtime path:

- GraphOS-managed path: provide APOLLO_KEY and APOLLO_GRAPH_REF (no local supergraph composition required). - Local supergraph path: use graphql-schema + apollo-server to define/run subgraphs, then use graphql-operations for smoke tests, then use the rover skill to compose or fetch supergraph.graphql.

  1. Use this apollo-router skill to validate readiness (validation/checklist.md) and walk through runtime startup inputs.

Default endpoint remains http://localhost:4000 when using standard Router listen defaults.

If the user asks for executable shell commands, provide them on request. Otherwise keep Quick Start guidance skill-oriented.

Running Modes

ModeCommandUse Case
Local schemarouter --supergraph./schema.graphqlDevelopment, CI/CD
GraphOS managedAPOLLO_KEY=... APOLLO_GRAPH_REF=my-graph@prod routerProduction with auto-updates
Developmentrouter --dev --supergraph./schema.graphqlLocal development
Hot reloadrouter --hot-reload --supergraph./schema.graphqlSchema changes without restart

Environment Variables

VariableDescription
APOLLO_KEYAPI key for GraphOS
APOLLO_GRAPH_REFGraph reference (graph-id@variant)
APOLLO_ROUTER_CONFIG_PATHPath to router.yaml
APOLLO_ROUTER_SUPERGRAPH_PATHPath to supergraph schema
APOLLO_ROUTER_LOGLog level (off, error, warn, info, debug, trace)
APOLLO_ROUTER_LISTEN_ADDRESSOverride listen address

Reference Files

CLI Reference

router [OPTIONS]

Options:
  -s, --supergraph <PATH>    Path to supergraph schema file
  -c, --config <PATH>        Path to router.yaml configuration
      --dev                  Enable development mode
      --hot-reload           Watch for schema changes
      --log <LEVEL>          Log level (default: info)
      --listen <ADDRESS>     Override listen address
  -V, --version              Print version
  -h, --help                 Print help

Ground Rules

  • ALWAYS determine the target Router version (v1 or v2) before generating config
  • DEFAULT to v2 for new projects
  • ALWAYS include a comment block at top of generated config stating the target version
  • ALWAYS use --dev mode for local development (enables introspection and sandbox)
  • ALWAYS disable introspection, sandbox, and homepage in production
  • PREFER GraphOS managed mode for production (automatic updates, metrics)
  • USE --hot-reload for local development with file-based schemas
  • NEVER expose APOLLO_KEY in logs or version control
  • USE environment variables (${env.VAR}) for all secrets and sensitive config
  • PREFER YAML configuration over command-line arguments for complex setups
  • TEST configuration changes locally before deploying to production
  • WARN if user enables allow_any_origin or wildcard CORS in production
  • RECOMMEND router config upgrade router.yaml for v1 → v2 migration instead of regenerating from scratch
  • MUST run validation/checklist.md after every router config generation or edit
  • MUST run router config validate <file> when Router CLI is available
  • MUST report when CLI validation could not run (for example, Router binary missing)
  • MUST append a brief conditional handoff when runtime prerequisites are missing or unknown
  • MUST make this handoff skill-first and avoid raw shell commands unless the user explicitly requests commands
  • MUST keep Quick Start guidance skill-first and command-free unless the user explicitly requests commands
  • MUST state that Rover is required only for the local supergraph path; GraphOS-managed runtime does not require local Rover composition
  • USE max_depth: 50 as the default starting point, not 15 (too aggressive) or 100 (too permissive)
  • RECOMMEND warn_only: true for initial limits rollout to observe real traffic before enforcing
  • ONLY offer Response Caching when ROUTER_VERSION=v2 (requires v2.6.0+)
  • ALWAYS use ${env.*} for Redis URLs, passwords, and invalidation shared keys
  • NEVER enable response_cache.debug: true in production config
  • RECOMMEND combining Cache-Control headers (passive TTL) with @cacheTag (active invalidation) for production
  • ALWAYS ask which fields return user-specific data before generating response cache config — never assume all data is safe to cache as shared
  • ALWAYS configure private_id for subgraphs that serve user-specific data, and ensure those subgraphs return Cache-Control: private (via @cacheControl(scope: PRIVATE) in Apollo Server, or by setting the header directly in other frameworks)
  • NEVER generate response cache config without addressing private data — if the user says "no user-specific data", confirm explicitly before proceeding
  • ALWAYS bind the invalidation endpoint to 127.0.0.1, NEVER 0.0.0.0 in production

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

34.06%
按下载量换算1,562

Claude

31.37%
按下载量换算1,439

Cursor

18.06%
按下载量换算828

Gemini CLI

10.3%
按下载量换算472

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills