Skip to content
Ali Akbari
Menu

Case study

aliakbari.dev

This site: a static Next.js front end and a small Go API that serve one audited evidence snapshot, behind nginx and Cloudflare, deployed by gated CI with automatic rollback. You can call its API from this page.
Personal labImplementedenvironment:Deployed× 3 claims
Role
Sole developer
Period
Oct 2026
Updated
11 October 2026
  • Next.js
  • TypeScript
  • Go
  • nginx
  • Docker Compose
  • Cloudflare
  • GitHub Actions
  • Playwright
Jump to a section
  1. Overview
  2. Try the API
  3. Architecture
  4. Delivery
  5. Decisions
  6. Limitations
  7. Evidence index

Overview

Content, case studies and evidence manifests are plain files in a repository. A build step validates them against JSON Schemas, audits every cross-reference (an evidence id, a CV link, a diagram or demo name) and writes one snapshot with a SHA-256 identity. The static pages, the Go API and the CV PDF are all produced from that snapshot, so they cannot disagree within a release.

Try the API

Live

Call this site's evidence API

Calls the running system from your browser.

Counts computed from the evidence snapshot this release was built from.

Requests go from your browser to /api/v1 on this site: read-only and rate-limited at the proxy. The index lists every endpoint, and its tests check the routes against an OpenAPI contract. The pages never depend on it.

Architecture

Production runtimeVisitors reach Nginx over HTTPS. Nginx terminates TLS, applies a per-route content security policy and rate limits, and proxies page requests to the Next.js server and /api/v1 requests to the Go service. Both application containers run on a private Docker network without published ports and carry the same evidence snapshot. Certbot on the host renews certificates and reloads Nginx.private docker network · no published portsHTTPS/*/api/v1/*Visitorbrowser or API clientNginxTLS · CSP map · rate limitsNext.js serverstatic pages · :3000Go API/api/v1 · :8080Snapshotsame sha256certbot (host)renew → reload nginx
Figure — Runtime. Pages never depend on the API; both read the snapshot shipped in their image.
  • Pages are rendered at build time by Next.js and served by its standalone server; no page calls the API, so the site keeps working if the API is down.
  • The API is a small Go service using only the standard library. It loads the snapshot, checks its hash, and serves it read-only under /api/v1 with validated parameters and ETags.
  • nginx terminates TLS, sets a Content Security Policy per route with the hashes of that route's inline scripts, and rate-limits requests. Cloudflare sits in front.
Evidence pipelineSource repositories publish releases. A sync step verifies paths, test names and CI conclusions at the pinned commit and vendors them through a reviewed pull request. The build validates schemas and audits cross-references, then writes one snapshot that the static site, the Go API and the résumé all consume.clean onlySource repositoriescode · tests · ADRs · reportsPinned releasetag → commit SHAEvidence syncpaths · test names · CI runReviewed pull requestvendor/ + sources.lock.jsonSchema + auditrejects invalid evidencesnapshot.jsonone sha256 per releaseNext.js static pagesrendered at buildGo API/api/v1, read-onlyRésumé HTML + PDFbullets cite evidence ids
Figure — Evidence flow. GitHub is the source of truth; every consumer renders the same audited snapshot.

Delivery

A push to main runs CI: schema and audit checks, unit tests, Go tests with the race detector, type-checks, a secret scan, image builds, and an end-to-end run of the whole stack behind nginx. Only a commit whose CI passed can be deployed. The deploy runs on the production host, pins the tested image digests, checks the release's health and rolls back automatically if it fails. The site is then tested again from the internet with the full end-to-end suite.

Decisions

The design decisions are recorded as ADRs and published at /decisions.

Limitations

  • One host: a deploy restarts the containers, and there is no failover.
  • No analytics by design, so there are no traffic figures.
  • The repository is private; the pipeline is described here, not published.

Evidence index

Every claim this case study relies on, rendered from the evidence manifests.

Implementedenvironment:DeployedSelf-reported · private source

Read-only Go evidence API

A small Go service (standard library only) serves the same audited evidence snapshot as the site under /api/v1, with an OpenAPI contract, validated query parameters, ETags and rate limiting at the proxy. The console on this site calls it live.

GoPersonal lab · no public artifactsEvidence
Implementedenvironment:DeployedSelf-reported · private source

Gated deploys with automatic rollback for this site

This site deploys only commits on main whose CI passed, by pinning the tested image digests, health-checking the release and rolling back automatically; production is then checked from the internet with the full end-to-end suite.

CI/CDPersonal lab · no public artifactsEvidence
Implementedenvironment:DeployedSelf-reported · private source

Strict Content Security Policy on a static site

Every page is static and served with a Content Security Policy that allows no inline script or style except inline scripts whose hashes are computed per route at build time, plus HSTS preload, behind nginx and Cloudflare.

SecurityPersonal lab · no public artifactsEvidence

← All work