Colophon
How this site is built
A static site, a private bucket, a CDN in front, and a gate that every build has to pass before it uploads.
The stack
- Astro generates plain HTML at build time. The only script is about 2 KB, and it remembers a light or dark preference.
- S3 and CloudFront serve it. The bucket is private, and CloudFront reaches it through origin access control.
- AWS CDK in TypeScript defines the infrastructure. Tests synthesize the stack and run the edge function's routing.
- The fonts are Inter and Newsreader, served from this domain under the SIL Open Font License.
What a visit sends elsewhere
Nothing. The pages load no third-party scripts, fonts or images, and set no cookies. There is no analytics. The content security policy allows this origin and no other, with no inline script or style.
The deploy gate
I wrote about a deploy gate on my own product, so this site has one too. A build that fails any check does not upload. It checks that:
- no page or PDF contains a phone number, an email address, a ZIP code or a cloud account identifier
- every internal link and anchor resolves
- no page needs anything the content security policy would block
- every page has one main heading, a title and a description, and every page but the 404 a canonical URL
- a preview build asks not to be indexed, and a production build does not
- the copy stays clear of the stock phrases that mark machine-written text
The gate has a self-test. Its privacy, writing-style, link and content-security rules are each fed a failing input, and the self-test fails if one of them stays quiet.
Who wrote it
I built this site with AI coding agents, in the same shape as the AI agents case study: author agents, then separate reviewers. I set the brief and made the decisions. An agent wrote the code and a first draft of the copy from my resume, my interview notes and my own project records. Separate reviewer agents then checked each claim against its source, and what they found was fixed before launch.