- Where
- Personal project
- Team
- Solo
- My role
- Everything
Problem
A portfolio that only describes what you can build asks the reader to take your word for it. The site itself is the first artifact anyone actually inspects.
Solution
Render two front ends over one content source — a conventional portfolio and a terminal that walks the same data as a fake filesystem — and keep the whole thing databaseless, with posts as markdown in git and sessions as HMAC-signed cookies minted only for the repo owner.
Overview
The site you are reading. It renders two front ends over one set of content: a portfolio view, and a terminal that exposes the same projects and experience as a navigable fake filesystem with tab completion and command history. Login is GitHub OAuth and lives only in the terminal — sessions are HMAC-signed cookies minted solely for the repository owner, with no session store, so rotating the secret revokes everything at once. The blog has no database: posts are markdown files in git, and the owner-gated editor commits them back through the GitHub API, so a published post is a commit that triggers a deploy. Hardened with a strict Content-Security-Policy and covered by a Playwright end-to-end suite.
Impact
- No database and no session store: rotating one secret revokes every session at once.
- Publishing a post is a git commit, which triggers the deploy.