Overview
Content, case studies and evidence manifests are plain files in a repository. A build step validates them against JSON Schemas, audits every cross-reference (an evidence id, a CV link, a diagram or demo name) and writes one snapshot with a SHA-256 identity. The static pages, the Go API and the CV PDF are all produced from that snapshot, so they cannot disagree within a release.
Try the API
Call this site's evidence API
Calls the running system from your browser.
Counts computed from the evidence snapshot this release was built from.
Architecture
- Pages are rendered at build time by Next.js and served by its standalone server; no page calls the API, so the site keeps working if the API is down.
- The API is a small Go service using only the standard library. It loads the snapshot, checks
its hash, and serves it read-only under
/api/v1with validated parameters and ETags. - nginx terminates TLS, sets a Content Security Policy per route with the hashes of that route's inline scripts, and rate-limits requests. Cloudflare sits in front.
Delivery
A push to main runs CI: schema and audit checks, unit tests, Go tests with the race detector, type-checks, a secret scan, image builds, and an end-to-end run of the whole stack behind nginx. Only a commit whose CI passed can be deployed. The deploy runs on the production host, pins the tested image digests, checks the release's health and rolls back automatically if it fails. The site is then tested again from the internet with the full end-to-end suite.
Decisions
The design decisions are recorded as ADRs and published at /decisions.
Limitations
- One host: a deploy restarts the containers, and there is no failover.
- No analytics by design, so there are no traffic figures.
- The repository is private; the pipeline is described here, not published.
Evidence index
Every claim this case study relies on, rendered from the evidence manifests.
Read-only Go evidence API
A small Go service (standard library only) serves the same audited evidence snapshot as the site under /api/v1, with an OpenAPI contract, validated query parameters, ETags and rate limiting at the proxy. The console on this site calls it live.
Gated deploys with automatic rollback for this site
This site deploys only commits on main whose CI passed, by pinning the tested image digests, health-checking the release and rolling back automatically; production is then checked from the internet with the full end-to-end suite.
Strict Content Security Policy on a static site
Every page is static and served with a Content Security Policy that allows no inline script or style except inline scripts whose hashes are computed per route at build time, plus HSTS preload, behind nginx and Cloudflare.