Context
The stack requires a Go backend. The site itself has no write paths, no users and no secrets. A backend added only to satisfy the requirement would be complexity without purpose, and a website that fails when that backend fails would be worse.
Options
- Next.js fetches its data from the Go API at runtime. The API becomes a single point of failure for every page.
- The Go API owns persistence and an admin UI. Adds an attack surface and state the portfolio does not need.
- The Go API serves the same immutable snapshot as a versioned, machine-readable contract.
Decision
services/api serves /api/v1/*: the evidence matrix with strict filtering, single claims, projects,
benchmarks, incidents, decisions and summary statistics. It is what a recruiter's tooling, a script or
another site can rely on. It is read-only, standard library only, and uses ETags with conditional
requests, bounded concurrency, request IDs, structured logs and graceful shutdown. Next.js renders from
the snapshot at build time and never calls it.
Consequences
- A broken or slow API affects only
/api/v1; every page stays up. - The API's value is modest and stated plainly: a stable contract, schemas published under
/schemas, and an OpenAPI description. - The service boundary is where future runtime features would go, such as signed evidence attestations, without touching the site.