Agent skill

Client Server Protocol

by celeriant in celeriant/celeriant-db

Celeriant's client-server protocol invariants, network behavior, failure modes, and shard routing.

Apache-2.0Auto-check passedDatabases

Install Client Server Protocol

skills CLI
$ npx skills add celeriant/celeriant-db --skill client-server-protocol -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install celeriant/celeriant-db client-server-protocol --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/celeriant/celeriant-db.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/client-server-protocol .claude/skills/client-server-protocol && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
client-server-protocol
GitHub stars
114
Token cost
~1.6k tokens
SKILL.md length
840 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

Celeriant's client-server protocol invariants, network behavior, failure modes, and shard routing.

  • Working with celeriantmsg
  • SKILL.md covers Connection Model, TLS, Identity & Auth and Pipelining, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Celeriantclienttokio

What it does

Client Server Protocol is an agent skill from celeriant/celeriant-db. Celeriant's client-server protocol invariants, network behavior, failure modes, and shard routing. Use when working with celeriantmsg, celeriantwire, celeriantclienttokio, or connection handling.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases. The repository describes itself as: Fast, distributed per-aggregate event log with strict ordering and optimistic concurrency control. The licence is Apache-2.0.

When your agent uses it

  • Working with celeriantmsg
  • Celeriantclienttokio
  • Connection handling

Example prompts

  • “/client-server-protocol”

What it can do on your machine

Read from SKILL.md and the folder at commit d071a6d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Client Server Protocol loads about 1.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 840 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from celeriant/celeriant-db at commit d071a6d, republished under its Apache-2.0 licence (© celeriant). 840 words, ~1,571 tokens.

Download SKILL.mdSave it as .claude/skills/client-server-protocol/SKILL.md (or your agent's skills folder).
name
client-server-protocol
description
Celeriant's client-server protocol invariants, network behavior, failure modes, and shard routing. Use when working with celeriant_msg, celeriant_wire, celeriant_client_tokio, or connection handling.

Client-Server Protocol

Connection Model

Stateless. No sessions, no prepared statements. Each request carries all context. Connections are reused for sequential pipelining - send request, get response, send next. Not multiplexed. One in-flight request per connection.

Two ports: client port for application traffic, replication port for cluster traffic. Wrong port = error 400. TCP_NODELAY on everything.

TLS

TLS 1.3 only. No fallback. kTLS offloads encryption to the kernel after the handshake, so io_uring reads/writes pass through without touching ciphertext in userspace. Session tickets are disabled (they desync kTLS sequence counters).

Two separate CAs: client CA on the client port, intracluster CA on the replication port. A client cert can't authenticate to the replication port. Replication always requires mTLS. Client port mTLS is configurable (default: require).

Hot-reload of certs is supported via configurable interval.

Identity & Auth

Identify is the mandatory first frame on every client connection, V4 and V5, whatever the server config. Any other first frame gets ProtocolError (response type 6) and the connection closes. Its body is discarded unparsed. Credentials in the Identify are optional unless the server requires them.

Two independent controls share the Identify round trip and nothing else:

  • require_client_identity requires a verified RSA key pair (public_key + nonce + signature). An API key does not satisfy it: 10004.
  • An api_keys.toml requires a valid API key. A key pair does not satisfy it: 10005. An API key presented to a server with no keys file: 10006.

Check order: signature (10001/10002), then the flag (10004), then API keys (10005/10006). So 10004 wins when both controls fail. Every rejected Identify closes the connection. Once identified, access level is stored on the connection for its lifetime. An API key grants access, not identity, and leaves write client_id unchecked.

The Identify also exchanges the compression dictionary: the client advertises known_dict_sha256 (seeded with the built-in), and the server ships bytes only on a mismatch. The dictionary ceiling is 1 MiB. Clients read the IdentifyResponse under ceiling + 128 (V4), not their response cap; the server's V5 write limit is 2 × ceiling + 128 because msgpack encodes the dictionary as an integer array. A non-Identify reply to Identify stays under the caller's cap. The server refuses to start with a larger dictionary.

API keys are stored as SHA-256 hashes only, never raw. Four slots: two ReadWrite, two ReadOnly.

API keys and client identity require TLS unless --insecure-allow-plaintext-auth is explicitly set (server exits at startup otherwise).

Access levels: ReadWrite (all operations) or ReadOnly (reads, details, lists only). Write/Delete/TrimStart/RegisterSchema on a ReadOnly connection = error 10007.

Pipelining

Sequential request-response loop. Server reads a request, processes it, sends response, reads next. Connection stays open until client timeout, server shutdown, or a Watch request.

Watch is connection-terminal. Once a Watch starts, the connection streams events until the client disconnects or filters empty out. No further regular requests.

Show full SKILL.md (378 more words)Show less

Shard Routing

Deterministic. Aggregate key hashed, mod by num_shards. Same key always hits the same shard.

If a request lands on the wrong shard, the server redirects internally via glommio mesh channel. Invisible to the client. If the mesh channel is full - no queue, no retry - immediate SERVER_BUSY (11000).

Multi-aggregate writes: each aggregate hashed independently. If they map to different shards, the write is rejected (9001). You can't do cross-shard atomic writes.

RegisterSchema always routes to shard 0.

List operations (ListOrgs, ListAggregateTypes, ListAggregates) require explicit shard_id from the client. The client library iterators handle shard discovery, pagination, and deduplication automatically.

Failure Modes

Not leader: Write/Delete/TrimStart to a non-leader returns an error with the leader address embedded as JSON. Client can parse and redirect.

Server busy: Mesh channel full on internal redirect. Client should back off.

Decompression bomb: Both compressed and uncompressed sizes validated against max_size_bytes before decompression. Prevents amplification attacks.

Oversized message: Exceeds max_size_bytes -> connection closed.

Incomplete message: Connection closed.

Cleartext to TLS port: Server expects a TLS handshake. A cleartext client sends bytes that aren't a ClientHello, the TLS layer rejects it, connection drops. Client sees a network EOF with no error response.

Replication Invariants

Writes are replicated synchronously to the follower before the client gets an ACK. Both leader and follower fsync to disk. Acknowledged writes are durable on two nodes.

Follower validates each batch: WAL sequence continuity, tip hash match, clock drift threshold, lease fencing. Any mismatch -> explicit rejection with reason. Not a generic error - the FollowerRejection enum tells you exactly what went wrong.

Heartbeats are pure liveness signals. No WAL data. Separate validation path.

Every replication connection opens with a dictionary hello: type 108 from the dialer, 109 back, each an uncompressed V4 frame carrying the sender's 32-byte dictionary sha256. Nothing crosses before it, heartbeats included. A mismatch logs ERROR naming both shas, bumps celeriant_internode_dictionary_mismatch_total, and closes, so the pair behaves like a partition. It guards TCP only; S3 fallback/catchup is an open gap (see docs/invariants.md).

Wire Format

17-byte fixed header, then payload. Protocol version V4 (bincode, Rust clients and internode) or V5 (msgpack, non-Rust). Server auto-detects from the header and responds in kind. Compression is none (0) or dictionary zstd (1).

See celeriant_wire/src/network/wire_header.rs for the header layout. See celeriant_msg/src/error_codes.rs for all error codes.

© celeriant, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/client-server-protocol of celeriant/celeriant-db.

Open the folder on GitHubat commit d071a6d

Compare with similar skills

Client Server Protocol next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Client Server Protocol compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Client Server Protocol this skillceleriant/celeriant-db114—~1.6kAutomated safety check: PassApache-2.0
Mail Timeveliovgroup/mail-time143—~1kAutomated safety check: PassBSD-3-Clause
Tgf Server Devthkhxm/tgf128—~1.3kAutomated safety check: NotesMIT
Azure Storagemicrosoft/GitHub-Copilot-for-Azure2552 repos~1.3kAutomated safety check: PassMIT
ArchitectYougLin-dev/Aha-Loop181—~2.2kAutomated safety check: PassMIT
Configure REST Cachestrapi-community/plugin-rest-cache155—~1.1kAutomated safety check: PassMIT

Similar skills

  • Mail Time

    veliovgroup/mail-time

    A skill your agent uses when building, wiring, reviewing, or debugging MailTime and ostrio:mailer email queues for horizontally scaled Node.js, Bun, or Meteor apps.

    143 GitHub stars~1k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Tgf Server Dev

    thkhxm/tgf

    基于 tgf v2(github.com/thkhxm/tgf/v2)用确定性的 tgfctl 工作流创建、验证和维护 Go 游戏服务器项目。

    128 GitHub stars~1.3k tokensUpdated 2 mo ago
    DatabasesAuto-check: notes
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    DatabasesAuto-check passed
  • Architect

    YougLin-dev/Aha-Loop

    Designs system architecture and selects technology stack based on vision analysis.

    181 GitHub stars~2.2k tokensUpdated 8 mo ago
    DatabasesAuto-check passed
  • Configure REST Cache

    strapi-community/plugin-rest-cache

    Choose and write a Strapi REST Cache configuration for a specific use case.

    155 GitHub stars~1.1k tokensUpdated 11 days ago
    DatabasesAuto-check passed
  • Pocketbase

    pockethost/pockethost

    Models PocketBase backends: collections, relations, auth, API rules, migrations, and architecture.

    1.4k GitHub stars~1k tokensUpdated 11 days ago
    DatabasesAuto-check passed

More from celeriant/celeriant-db

All 13 skills in this repo
  • Error Handling

    celeriant/celeriant-db

    Error handling patterns in Celeriant. An agent skill from celeriant/celeriant-db.

    114 GitHub stars~550 tokensUpdated 10 days ago
    Auto-check passed
  • Testing

    celeriant/celeriant-db

    How to write and run tests in Celeriant. An agent skill from celeriant/celeriant-db.

    114 GitHub stars~951 tokensUpdated 10 days ago
    Auto-check passed
  • Understanding Celeriant Structure

    celeriant/celeriant-db

    Celeriant codebase architecture, crate responsibilities, and how they fit together.

    114 GitHub stars~803 tokensUpdated 10 days ago
    Auto-check passed
  • Extract A Type

    celeriant/celeriant-db

    Refactor a named Rust type or its surrounding code with an agreed scope.

    114 GitHub stars~934 tokensUpdated 10 days ago
    Auto-check passed
  • Database Architecture

    celeriant/celeriant-db

    Core architecture invariants for Celeriant. An agent skill from celeriant/celeriant-db.

    114 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check passed
  • Glommio Locking Patterns

    celeriant/celeriant-db

    Locking patterns for Glommio's single-threaded async executors.

    114 GitHub stars~876 tokensUpdated 10 days ago
    Auto-check passed

Questions about Client Server Protocol

What does Client Server Protocol do?

Celeriant's client-server protocol invariants, network behavior, failure modes, and shard routing. Client Server Protocol is an agent skill from celeriant/celeriant-db. Celeriant's client-server protocol invariants, network behavior, failure modes, and shard routing.

When should I use Client Server Protocol?

Client Server Protocol fits situations like: working with celeriantmsg; celeriantclienttokio; connection handling.

How do I install Client Server Protocol in Claude Code?

Run `npx skills add celeriant/celeriant-db --skill client-server-protocol -a claude-code`. Or copy the skill folder (.claude/skills/client-server-protocol in celeriant/celeriant-db) into .claude/skills/client-server-protocol in your project. Claude Code loads it when a task matches its description.

How do I install Client Server Protocol in Codex?

Run `npx skills add celeriant/celeriant-db --skill client-server-protocol -a codex`. Or copy the skill folder (.claude/skills/client-server-protocol in celeriant/celeriant-db) into .agents/skills/client-server-protocol in your project. Codex loads it when a task matches its description.

Can I use Client Server Protocol in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add celeriant/celeriant-db --skill client-server-protocol -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/client-server-protocol, .gemini/skills/client-server-protocol, .github/skills/client-server-protocol and .opencode/skills/client-server-protocol in your project.

What does Client Server Protocol need to run?

SKILL.md names no scripts, command-line tools or credentials: Client Server Protocol is instructions for the agent only.

Does Client Server Protocol access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Client Server Protocol safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Client Server Protocol use?

Client Server Protocol is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Client Server Protocol use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Client Server Protocol?

Skills that share tags, products or a category with Client Server Protocol: Mail Time (veliovgroup/mail-time, 143 stars), Tgf Server Dev (thkhxm/tgf, 128 stars), Azure Storage (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Architect (YougLin-dev/Aha-Loop, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Client Server Protocol?

celeriant (a GitHub organization) maintains it in celeriant/celeriant-db, which has 114 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 28, 2026.

Source: celeriant/celeriant-db on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.