Agent skill

Fastly Wildcard Subdomain Compute Edge

by divinevideo in divinevideo/divine-mobile

Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses.

MPL-2.0Auto-check passed

Install Fastly Wildcard Subdomain Compute Edge

skills CLI
$ npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile fastly-wildcard-subdomain-compute-edge --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/fastly-wildcard-subdomain-compute-edge .claude/skills/fastly-wildcard-subdomain-compute-edge && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fastly-wildcard-subdomain-compute-edge
GitHub stars
266
Token cost
~2.1k tokens
SKILL.md length
436 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses.

  • Works in 4 steps: Wrong SNI endpoint: TLS certificate is… → DNS trailing dot issue: CNAME records… → Domain not activated: Fastly domain-v1… → …
  • TLS subscription issued but edge serves default certificate (CN=j.sni-644-default)
  • SKILL.md covers Problem, Context / Trigger Conditions, Solution and Verification, plus 3 more sections
  • Calls curl, jq and openssl; reaches api.fastly.com; needs FASTLY_KEY

What it does

Fastly Wildcard Subdomain Compute Edge is an agent skill from divinevideo/divine-mobile. Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses. Use when: (1) TLS subscription "issued" but edge serves default certificate (CN=j.sni-644-default), (2) Fastly domain-v1 create succeeds but subdomain returns 500, (3) Static publisher/PublisherServer returns empty content for subdomain requests, (4) DNS wildcard CNAME resolves to wrong target. Covers TLS configuration SNI endpoint selection (x.sni vs j.sni vs w.sni), DNS…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The licence is MPL-2.0.

When your agent uses it

  • TLS subscription issued but edge serves default certificate (CN=j.sni-644-default)
  • Fastly domain-v1 create succeeds but subdomain returns 500
  • Static publisher/PublisherServer returns empty content for subdomain requests
  • DNS wildcard CNAME resolves to wrong target

Example prompts

  • “Domain Not Found”
  • “issued”
  • “/fastly-wildcard-subdomain-compute-edge”

Requirements

  • A credential in FASTLY_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Wrong SNI endpoint: TLS certificate is "issued" but edge serves default certificate
  2. DNS trailing dot issue: CNAME records resolve to target.com.yourdomain.com instead
  3. Domain not activated: Fastly domain-v1 shows "activated": false, "verified": false
  4. PublisherServer returns empty for subdomains: The @fastly/compute-js-static-publish

What it can do on your machine

Read from SKILL.md and the folder at commit c3d6f7e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.fastly.com

    Also links to:

    • fastly.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • FASTLY_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fastly Wildcard Subdomain Compute Edge loads about 2.1k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 436 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~171
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit c3d6f7e, republished under its MPL-2.0 licence (© divinevideo). 436 words, ~2,133 tokens.

Download SKILL.mdSave it as .claude/skills/fastly-wildcard-subdomain-compute-edge/SKILL.md (or your agent's skills folder).
name
fastly-wildcard-subdomain-compute-edge
description
Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses. Use when: (1) TLS subscription "issued" but edge serves default certificate (CN=j.sni-644-default), (2) Fastly domain-v1 create succeeds but subdomain returns 500, (3) Static publisher/PublisherServer returns empty content for subdomain requests, (4) DNS wildcard CNAME resolves to wrong target. Covers TLS configuration SNI endpoint selection (x.sni vs j.sni vs w.sni), DNS trailing dot issues, Fastly domain-v1 activation, and reading from KV store directly when PublisherServer fails for subdomains.
author
Claude Code
version
1.1.0
date
2026-02-02

Fastly Wildcard Subdomain Routing for Compute@Edge

Problem

Wildcard subdomains (*.example.com) don't work on Fastly Compute@Edge services even after:

  • Creating the domain with fastly domain-v1 create
  • Setting up DNS records
  • The static publisher working fine for the apex domain

Symptoms include:

  • 500 errors with "Fastly error: unknown domain: subdomain.example.com"
  • PublisherServer returning empty responses (content-length: 0) for subdomain requests
  • TLS subscriptions stuck in "pending" state
  • DNS resolving to wrong targets

Context / Trigger Conditions

  1. Wrong SNI endpoint: TLS certificate is "issued" but edge serves default certificate (CN=j.sni-644-default.ssl.fastly.net instead of your domain).

    CRITICAL: The TLS configuration name tells you which SNI endpoint to use:

    • "HTTP/3 & TLS v1.3 + 0RTT (x.sni)" → DNS to x.sni.global.fastly.net.
    • "HTTP/3 & TLS v1.3 (w.sni)" → DNS to w.sni.global.fastly.net.
    • Default/legacy → DNS to j.sni.global.fastly.net.

    Check your TLS configuration:

    bash
    FASTLY_KEY=$(fastly profile token) && curl -s -H "Fastly-Key: $FASTLY_KEY" \
      "https://api.fastly.com/tls/configurations" | jq '.data[] | {id: .id, name: .attributes.name}'

    Verify by connecting directly to the correct endpoint:

    bash
    echo | openssl s_client -servername subdomain.yourdomain.com \
      -connect x.sni.global.fastly.net:443 2>/dev/null | openssl x509 -noout -subject
  2. DNS trailing dot issue: CNAME records resolve to target.com.yourdomain.com instead of target.com because the DNS provider appends the zone name without a trailing dot.

    Check with: dig @ns-server *.yourdomain.com CNAME +short

    Bad: x.sni.global.fastly.net.yourdomain.com. Good: x.sni.global.fastly.net.

  3. Domain not activated: Fastly domain-v1 shows "activated": false, "verified": false even after DNS is set up.

    Check with:

    bash
    curl -s -H "Fastly-Key: $(fastly profile token)" \
      "https://api.fastly.com/domain-management/v1/domains/DOMAIN_ID" | jq
  4. PublisherServer returns empty for subdomains: The @fastly/compute-js-static-publish PublisherServer returns null/empty responses when the request hostname is a subdomain, even though it works for the apex domain and edgecompute.app URL.

Solution

Part 1: Fix DNS Configuration
  1. Wildcard CNAME with trailing dot (check your TLS config for correct SNI endpoint):

    Name: *
    Type: CNAME
    Value: x.sni.global.fastly.net.   <- Use endpoint from your TLS config name (x.sni, w.sni, or j.sni)
  2. ACME challenge CNAME with trailing dot (for TLS validation):

    Name: _acme-challenge
    Type: CNAME
    Value: CHALLENGE_VALUE.fastly-validations.com.   <- MUST include trailing dot
  3. Alternative: Use A records instead of CNAME (avoids trailing dot issues):

    Name: *
    Type: A
    Values: 151.101.1.242, 151.101.65.242, 151.101.129.242, 151.101.193.242
Show full SKILL.md (177 more words)Show less
Part 2: Recreate Fastly Domain (if stuck)

If domain shows activated: false even after DNS is correct:

bash
# 1. Delete TLS subscription first (if exists)
fastly tls-subscription delete --id SUBSCRIPTION_ID --force

# 2. Delete the domain
fastly domain-v1 delete --domain-id DOMAIN_ID

# 3. Recreate domain
fastly domain-v1 create --fqdn "*.yourdomain.com" --service-id SERVICE_ID

# 4. Create new TLS subscription
fastly tls-subscription create --domain "*.yourdomain.com"

# 5. Wait 1-5 minutes for verification and TLS issuance
Part 3: Fix PublisherServer for Subdomains

The PublisherServer from @fastly/compute-js-static-publish doesn't serve content for subdomain hostnames. You must read from the KV store directly:

javascript
if (subdomain) {
  // Open the content KV store
  const contentStore = new KVStore('your-content-store-name');

  // Read the index file - NOTE: collection name might be 'undefined' not 'default'
  const indexEntry = await contentStore.get('default_index_undefined');
  const indexData = await indexEntry.json();

  // Get the index.html entry - structure is { '/path': { key: 'sha256:HASH', ... } }
  const indexHtmlInfo = indexData['/index.html'];

  // Read the actual content
  const contentHash = indexHtmlInfo.key.replace('sha256:', '');
  const contentKey = `default_files_sha256_${contentHash}`;
  const htmlEntry = await contentStore.get(contentKey);
  const html = await htmlEntry.text();

  // Inject subdomain-specific data and return
  const modifiedHtml = html.replace('<head>', `<head><script>window.SUBDOMAIN_DATA = {...}</script>`);
  return new Response(modifiedHtml, {
    headers: { 'Content-Type': 'text/html; charset=utf-8' }
  });
}
Part 4: Key Format Discovery

The static publisher uses these KV key formats:

  • Index: ${publishId}_index_${collectionName} (e.g., default_index_undefined)
  • Settings: ${publishId}_settings_${collectionName}
  • Files: ${publishId}_files_sha256_${hash}

To discover your actual key names:

bash
curl -s -H "Fastly-Key: $(fastly profile token)" \
  "https://api.fastly.com/resources/stores/kv/STORE_ID/keys?limit=50" | jq '.data[]' | grep index

Verification

bash
# 1. Verify DNS is correct
dig @8.8.8.8 subdomain.yourdomain.com A +short
# Should return Fastly IPs

# 2. Verify domain is activated
curl -s -H "Fastly-Key: $(fastly profile token)" \
  "https://api.fastly.com/domain-management/v1/domains/DOMAIN_ID" | jq '{activated, verified}'
# Both should be true

# 3. Verify TLS is issued
fastly tls-subscription list | grep yourdomain
# State should be "issued"

# 4. Test the subdomain
curl -sI "https://subdomain.yourdomain.com"
# Should return 200 with content

Example

Complete fix for *.divine.space subdomain routing:

javascript
// In Compute@Edge handler
if (subdomain && namesStore) {
  const entry = await namesStore.get(`name:${subdomain}`);

  const contentStore = new KVStore('divine-space-content');
  const indexEntry = await contentStore.get('default_index_undefined');
  const indexData = await indexEntry.json();
  const indexHtmlInfo = indexData['/index.html'];
  const contentHash = indexHtmlInfo.key.replace('sha256:', '');
  const htmlEntry = await contentStore.get(`default_files_sha256_${contentHash}`);
  const html = await htmlEntry.text();

  if (entry) {
    const data = await entry.json();
    const injectedHtml = html.replace('<head>', `<head>
      <script>window.__DIVINE_SPACE_USER__ = {
        subdomain: "${subdomain}",
        pubkey: "${data.pubkey}"
      };</script>`);
    return new Response(injectedHtml, {
      headers: { 'Content-Type': 'text/html; charset=utf-8' }
    });
  }
}

Notes

  • The collectionName in KV keys is often undefined (literal string) rather than default due to how the static publisher is configured. Always check actual keys.
  • DNS changes can take up to 3 hours to propagate due to TTL settings.
  • Fastly edge cache may serve stale responses—use fastly purge --all after changes.
  • Static assets (/assets/*, .js, .css files) should be served BEFORE subdomain handling using the normal PublisherServer.
  • The wildcard TLS cert (*.domain.com) requires the ACME challenge DNS record to be correct before it will issue.

References

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/fastly-wildcard-subdomain-compute-edge of divinevideo/divine-mobile.

Open the folder on GitHubat commit c3d6f7e

Compare with similar skills

Fastly Wildcard Subdomain Compute Edge next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fastly Wildcard Subdomain Compute Edge compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fastly Wildcard Subdomain Compute Edge this skilldivinevideo/divine-mobile266—~2.1kAutomated safety check: PassMPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0
Nginx To Higress Migrationhigress-group/higress9.5k—~3.9kAutomated safety check: PassApache-2.0
Rustpgdogdev/pgdog5.6k—~1.9kAutomated safety check: NotesAGPL-3.0
Bfe Rd Workflowbfenetworks/bfe6.3k—~1.3kAutomated safety check: PassApache-2.0
NGINX Ingress Controller Feature Checklistsnginx/kubernetes-ingress5.1k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Nginx To Higress Migration

    higress-group/higress

    Migrate from ingress-nginx to Higress in Kubernetes environments.

    9.5k GitHub stars~3.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Rust

    pgdogdev/pgdog

    Rust coding best practices for idiomatic, efficient, and maintainable code.

    5.6k GitHub stars~1.9k tokensUpdated today
    DatabasesAuto-check: notes
  • Bfe Rd Workflow

    bfenetworks/bfe

    引导用户在 bfe 代码库中完成一次完整的功能研发流程,包括需求对齐、文档修改、代码实现、集成测试与回归验证. An agent skill from bfenetworks/bfe.

    6.3k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Gives step-by-step checklists for adding Ingress annotations, VirtualServer fields and Helm values to the NGINX Kubernetes Ingress Controller, with common gotchas.

    5.1k GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • NGINX Ingress Policy CRD Guide

    nginx/kubernetes-ingress

    Step-by-step checklist for adding a new Policy CRD type to the NGINX Ingress Controller, from the Go types and validation to config generation and templates.

    5.1k GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Questions about Fastly Wildcard Subdomain Compute Edge

What does Fastly Wildcard Subdomain Compute Edge do?

Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses. Fastly Wildcard Subdomain Compute Edge is an agent skill from divinevideo/divine-mobile. Fix wildcard subdomain routing for Fastly Compute@Edge services when subdomains resolve but return 500 "Domain Not Found" or empty responses.

When should I use Fastly Wildcard Subdomain Compute Edge?

Fastly Wildcard Subdomain Compute Edge fits situations like: TLS subscription issued but edge serves default certificate (CN=j.sni-644-default); fastly domain-v1 create succeeds but subdomain returns 500; static publisher/PublisherServer returns empty content for subdomain requests; DNS wildcard CNAME resolves to wrong target.

How do I install Fastly Wildcard Subdomain Compute Edge in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a claude-code`. Or copy the skill folder (.agents/skills/fastly-wildcard-subdomain-compute-edge in divinevideo/divine-mobile) into .claude/skills/fastly-wildcard-subdomain-compute-edge in your project. Claude Code loads it when a task matches its description.

How do I install Fastly Wildcard Subdomain Compute Edge in Codex?

Run `npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a codex`. Or copy the skill folder (.agents/skills/fastly-wildcard-subdomain-compute-edge in divinevideo/divine-mobile) into .agents/skills/fastly-wildcard-subdomain-compute-edge in your project. Codex loads it when a task matches its description.

Can I use Fastly Wildcard Subdomain Compute Edge in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill fastly-wildcard-subdomain-compute-edge -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fastly-wildcard-subdomain-compute-edge, .gemini/skills/fastly-wildcard-subdomain-compute-edge, .github/skills/fastly-wildcard-subdomain-compute-edge and .opencode/skills/fastly-wildcard-subdomain-compute-edge in your project.

What does Fastly Wildcard Subdomain Compute Edge need to run?

Going by SKILL.md and its folder, Fastly Wildcard Subdomain Compute Edge needs the command-line tools its instructions call (curl, jq and openssl) and credentials named FASTLY_KEY. Our summary lists: A credential in FASTLY_KEY.

Does Fastly Wildcard Subdomain Compute Edge access the network?

SKILL.md names 2 domains. In commands or code: api.fastly.com; the agent is likely to contact it when it follows the instructions. As links in the text: fastly.com. This is read from the text; nothing was executed.

Is Fastly Wildcard Subdomain Compute Edge safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fastly Wildcard Subdomain Compute Edge use?

Fastly Wildcard Subdomain Compute Edge is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fastly Wildcard Subdomain Compute Edge use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fastly Wildcard Subdomain Compute Edge?

Skills that share tags, products or a category with Fastly Wildcard Subdomain Compute Edge: Kubeshark KFL2 Filter Reference (kubeshark/kubeshark, 12k stars), Nginx To Higress Migration (higress-group/higress, 9.5k stars), Rust (pgdogdev/pgdog, 5.6k stars) and Bfe Rd Workflow (bfenetworks/bfe, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fastly Wildcard Subdomain Compute Edge?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 10, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.