Featured posts
• Agent architecture in production
• Migrating WordPress to S3 + CloudFront with Claude
• What an LLM really is
• Agentic Patterns and the many faces of RAG
• AI SDLC: best practices for developing with AI
How this site is built
It’s a static site: no server, database or admin panel to maintain or patch.
- Content — every post is a Markdown file in a private GitHub repo. Astro turns it into HTML at build time, in five languages, and Pagefind builds the search index, which runs in the browser.
- Hosting — the files live in a private S3 bucket that only CloudFront can read (Origin Access Control). A CloudFront Function resolves the URLs and redirects the old WordPress ones, and every response carries security headers such as HSTS and CSP.
- Infrastructure as code — the certificates, buckets, CloudFront, the deploy role and a cost alarm are defined in TypeScript with AWS CDK and versioned in Git.
- Deploy — every push to
mainpublishes to a staging environment; production only changes through a manual promotion in GitHub Actions. The pipeline authenticates to AWS via OIDC with credentials that last one hour: there are no stored access keys, and the role can only write to the site’s bucket and invalidate its cache.
How I migrated the site from WordPress is covered in this post.
