hyperforce-2025
Salesforce Hyperforce public cloud infrastructure and architecture (2025). PROACTIVELY activate for: (1) understanding Hyperforce architecture (multi-region, public cloud), (2) Hyperforce migration planning, (3) data residency and regional deployments, (4) Hyperforce security model (BYOK, Shield encryption), (5) network architecture (PrivateLink, public IP allowlists), (6) Hyperforce vs first-generation infrastructure differences, (7) backup and disaster recovery on Hyperforce, (8) Hyperforce performance and SLA, (9) compliance certifications (HIPAA, FedRAMP, GDPR). Provides: Hyperforce overview, migration checklist, network architecture patterns, BYOK setup, and DR/backup configuration.
What this skill does
## π¨ CRITICAL GUIDELINES
### Windows File Path Requirements
**MANDATORY: Always Use Backslashes on Windows for File Paths**
When using Edit or Write tools on Windows, you MUST use backslashes (`\`) in file paths, NOT forward slashes (`/`).
**Examples:**
- β WRONG: `D:/repos/project/file.tsx`
- β
CORRECT: `D:\repos\project\file.tsx`
This applies to:
- Edit tool file_path parameter
- Write tool file_path parameter
- All file operations on Windows systems
### Documentation Guidelines
**NEVER create new documentation files unless explicitly requested by the user.**
- **Priority**: Update existing README.md files rather than creating new documentation
- **Repository cleanliness**: Keep repository root clean - only README.md unless user requests otherwise
- **Style**: Documentation should be concise, direct, and professional - avoid AI-generated tone
- **User preference**: Only create additional .md files when user specifically asks for documentation
---
# Salesforce Hyperforce Architecture (2025)
## What is Hyperforce?
Hyperforce is Salesforce's next-generation infrastructure architecture built on public cloud platforms (AWS, Azure, Google Cloud). It represents a complete re-architecture of Salesforce from data center-based infrastructure to cloud-native, containerized microservices.
**Key Innovation**: Infrastructure as code that can be deployed anywhere, giving customers choice, control, and data residency compliance.
## Five Architectural Principles
### 1. Immutable Infrastructure
**Traditional**: Patch and update existing servers
**Hyperforce**: Destroy and recreate servers with each deployment
```yaml
Old Architecture:
Server β Patch β Patch β Patch β Configuration Drift
Hyperforce:
Container Image v1 β Deploy
New Code β Build Container Image v2 β Replace v1 with v2
Result: Every deployment is identical, reproducible
```
**Benefits**:
- No configuration drift
- Consistent environments (dev = prod)
- Fast rollback (redeploy previous image)
- Security patches applied immediately
### 2. Multi-Availability Zone Design
**Architecture**:
```text
Region: US-East (Virginia)
ββ Availability Zone A (Data Center 1)
β ββ App Servers (Kubernetes pods)
β ββ Database Primary
β ββ Load Balancer
ββ Availability Zone B (Data Center 2)
β ββ App Servers (Kubernetes pods)
β ββ Database Replica
β ββ Load Balancer
ββ Availability Zone C (Data Center 3)
ββ App Servers (Kubernetes pods)
ββ Database Replica
ββ Load Balancer
Traffic Distribution: Round-robin across all AZs
Failure Handling: If AZ fails, traffic routes to remaining AZs
RTO (Recovery Time Objective): <5 minutes
RPO (Recovery Point Objective): <30 seconds
```
**Impact on Developers**:
- Higher availability (99.95%+ SLA)
- Transparent failover (no code changes)
- Regional data residency guaranteed
### 3. Zero Trust Security
**Traditional**: Perimeter security (firewall protects everything inside)
**Hyperforce**: No implicit trust - verify everything, always
```text
Zero Trust Model:
ββ Identity Verification (MFA required for all users by 2025)
ββ Device Trust (managed devices only)
ββ Network Segmentation (micro-segmentation between services)
ββ Least Privilege Access (minimal permissions by default)
ββ Continuous Monitoring (real-time threat detection)
ββ Encryption Everywhere (TLS 1.3, data at rest encryption)
```
**Code Impact**:
```apex
// OLD: Assume internal traffic is safe
public without sharing class InternalService {
// No auth checks - trusted network
}
// HYPERFORCE: Always verify, never trust
public with sharing class InternalService {
// Always enforce sharing rules
// Always validate session
// Always check field-level security
public List<Account> getAccounts() {
// WITH SECURITY_ENFORCED prevents data leaks
return [SELECT Id, Name FROM Account WITH SECURITY_ENFORCED];
}
}
```
**2025 Requirements**:
- **MFA Mandatory**: All users must enable MFA
- **Session Security**: Shorter session timeouts, IP restrictions
- **API Security**: JWT with short expiration (15 minutes)
### 4. Infrastructure as Code (IaC)
**Everything defined as code, version-controlled**:
```yaml
# Hyperforce deployment manifest (conceptual)
apiVersion: hyperforce.salesforce.com/v1
kind: SalesforceOrg
metadata:
name: production-org
region: aws-us-east-1
spec:
edition: enterprise
features:
- agentforce
- dataCloud
- einstein
compute:
pods: 50
autoScaling:
min: 10
max: 100
targetCPU: 70%
storage:
size: 500GB
replication: 3
backup:
frequency: hourly
retention: 30days
networking:
privateLink: enabled
ipWhitelist:
- 203.0.113.0/24
```
**Benefits for Developers**:
- **Reproducible**: Recreate exact environment anytime
- **Version Controlled**: Track all infrastructure changes in Git
- **Testable**: Validate infrastructure before deployment
- **Automated**: No manual configuration, eliminates human error
### 5. Clean Slate (No Legacy Constraints)
**Hyperforce rebuilt from scratch**:
- Modern Kubernetes orchestration
- Cloud-native services (managed databases, object storage)
- API-first design (everything accessible via API)
- Microservices architecture (independent scaling)
- No legacy code or technical debt
## Public Cloud Integration
### AWS Hyperforce Architecture
```text
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β AWS Region (us-east-1) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β VPC (Virtual Private Cloud) β
β ββ Public Subnets (3 AZs) β
β β ββ Application Load Balancer (ALB) β
β ββ Private Subnets (3 AZs) β
β β ββ EKS Cluster (Kubernetes) β
β β β ββ Salesforce App Pods (autoscaling) β
β β β ββ Metadata Service Pods β
β β β ββ API Gateway Pods β
β β β ββ Background Job Pods (Batch, Scheduled) β
β β ββ RDS Aurora PostgreSQL (multi-AZ) β
β β ββ ElastiCache Redis (session storage) β
β β ββ S3 Buckets (attachments, documents) β
β ββ Database Subnets (3 AZs) β
β ββ Aurora Database Cluster β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Additional Services β
β ββ CloudWatch (monitoring, logs) β
β ββ CloudTrail (audit logs) β
β ββ AWS Shield (DDoS protection) β
β ββ AWS WAF (web application firewall) β
β ββ KMS (encryption key management) β
β ββ PrivateLink (secure connectivity) β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
**AWS Services Used**:
- **Compute**: EKS (Elastic Kubernetes Service)
- **Database**: Aurora PostgreSQL (multi-master)
- **Storage**: S3 (object storage), EBS (block storage)
- **Networking**: VPC, ALB, Route 53, CloudFront CDN
- **Security**: IAM, KMS, Shield, WAF, Certificate Manager
### Azure Hyperforce Architecture
```text
Azure Region (East US)
ββ Virtual Network (VNet)
β ββ AKS (Azure Kubernetes Service)
β β ββ Salesforce workloads
β ββ Azure Database for PostgreSQL (Hyperscale)
β ββ Azure Cache for Redis
β ββ Azure Blob Storage
ββ Azure Front Door (CDN + Load Balancer)
ββ Azure Monitor (logging, metrics)
ββ Azure Active Directory (identity)
ββ Azure Key Vault (secrets, encryption)
```
### Google Cloud Hyperforce Architecture
```text
GCP Region (us-central1)
ββ VPC Network
β ββ GKE (Google Kubernetes Engine)
β ββ Cloud SQL (PostgreSQL)
β ββ Memorystore (Redis)
β ββ Cloud Storage (GCS)
ββ Cloud Load Balancing
ββ Cloud Armor (DDoS protection)
ββ Cloud Monitoring (Stackdriver)
ββ Cloud KMS (encryption)
```
## Data Residency and Compliance
### Geographic RegionRelated in Cloud & DevOps
appbuilder-action-scaffolder
IncludedCreate, implement, deploy, and debug Adobe Runtime actions with consistent layout, validation, and error handling. Use this skill whenever the user needs to add actions to an App Builder project, understand action structure (params, response format, web/raw actions), configure actions in the manifest, use App Builder SDKs (State, Files, Events, database), deploy and invoke actions via CLI, debug action issues, or implement patterns such as webhook receivers, custom event providers, journaling consumers, large payload redirects, action sequence pipelines, and Asset Compute workers. Also trigger when users mention serverless functions in Adobe context, action logging, IMS authentication for actions, or cron-style scheduled actions.
orchestrating-datacloud
IncludedSalesforce Data Cloud product orchestrator for connectβprepareβharmonizeβsegmentβact workflows. Use this skill when the user needs a multi-step Data Cloud pipeline, cross-phase troubleshooting, or data space and data kit management. TRIGGER when: user needs a multi-step Data Cloud pipeline, asks to set up or troubleshoot Data Cloud across phases, manages data spaces or data kits, or wants a cross-phase sf data360 workflow. DO NOT TRIGGER when: work is isolated to a single phase (use the matching phase-specific skill), the task is STDM/session tracing/parquet telemetry (use observing-agentforce), standard CRM SOQL (use querying-soql), or Apex implementation (use generating-apex).
github-project-automation
IncludedAutomate GitHub repository setup with CI/CD workflows, issue templates, Dependabot, and CodeQL security scanning. Includes 12 production-tested workflows and prevents 18 errors: YAML syntax, action pinning, and configuration. Use when: setting up GitHub Actions CI/CD, creating issue/PR templates, enabling Dependabot or CodeQL scanning, deploying to Cloudflare Workers, implementing matrix testing, or troubleshooting YAML indentation, action version pinning, secrets syntax, runner versions, or CodeQL configuration. Keywords: github actions, github workflow, ci/cd, issue templates, pull request templates, dependabot, codeql, security scanning, yaml syntax, github automation, repository setup, workflow templates, github actions matrix, secrets management, branch protection, codeowners, github projects, continuous integration, continuous deployment, workflow syntax error, action version pinning, runner version, github context, yaml indentation error
sf-datacloud
IncludedSalesforce Data Cloud product orchestrator for connectβprepareβharmonizeβsegmentβact workflows. TRIGGER when: user needs a multi-step Data Cloud pipeline, asks to set up or troubleshoot Data Cloud across phases, manages data spaces or data kits, or wants a cross-phase `sf data360` workflow. DO NOT TRIGGER when: work is isolated to a single phase (use the matching sf-datacloud-* skill), the task is STDM/session tracing/parquet telemetry (use sf-ai-agentforce-observability), standard CRM SOQL (use sf-soql), or Apex implementation (use sf-apex).
fabric-cli
IncludedUse this skill for Fabric.so CLI workflows with the `fabric` terminal command: diagnose/install/login, search or browse a Fabric library, save notes/links/files, create folders, ask the Fabric AI assistant, manage tasks/workspaces, generate shell completion, check subscription usage, produce JSON output, and use Fabric as persistent agent memory. Do not use for Microsoft Fabric/Azure/Power BI `fab`, Daniel Miessler's Fabric framework, Python Fabric SSH, Fabric.js, or textile/fashion fabric.
lark
IncludedLark/Feishu CLI skills: lark-cli operations for docs, markdown, sheets, base, calendar, im, mail, task, okr, drive, wiki, slides, whiteboard, apps, approval, attendance, contact, vc, minutes, event. Use when the user needs to operate Lark/Feishu resources via lark-cli, send messages, manage documents, spreadsheets, calendars, tasks, OKRs, deploy web pages, or any Feishu/Lark workspace operations.