Skip to content
fullstack web-application featured

Portfolio & Showcase — This Site

An interactive portfolio that ships real artifacts rather than screenshots: every Android release carries version code, file size, minSdk, and SHA-256 checksum. Go API on Fly.io, SvelteKit frontend on Vercel.

fullstack │ live · build03.online · fly-io· go· postgresql· supabase
Portfolio & Showcase — This Site
Fly.io Go PostgreSQL Supabase Svelte SvelteKit Tailwind CSS TypeScript Vercel

This site itself — an interactive portfolio that ships real artifacts rather than screenshots. Every Android project in this catalogue carries a version code, file size, minSdk, and a verifiable SHA-256 checksum, rather than mere claims in text.

Highlights

  • Truly streaming APK uploads — the backend reads request bodies through MultipartReader rather than ParseMultipartForm, staging to a temp file while an io.TeeReader feeds sha256.New(). Memory stays flat regardless of file size: a 45 MiB APK peaked at 23,364 kB RSS, and the download round-trip came back byte-identical.
  • Direct browser-to-Go uploads, bypassing SvelteKit — Vercel caps serverless request bodies at 4.5 MB, so routing an APK through a form action would fail in production while working locally. Both uploaders POST straight to the Go API with XMLHttpRequest, carrying their own bearer token and reporting real progress.
  • Dual-mode authentication — the middleware switches on the token's alg, verifying JWKS (RS256/ES256) for modern Supabase projects and HMAC for legacy shared secrets. Authorization is read from the profiles.role column behind a TTL cache, never from app_metadata claims in the token.
  • Deliberate prompt caching for AI — the DeepSeek context is rendered with a fixed section order, sorted metadata keys and no timestamps, so the prefix stays byte-identical between requests. A unit test asserts two builds are identical; production logs measured 11,904 of 11,995 prompt tokens served from cache (99.3%).
  • Storage limits mapped to real status codes — Supabase's free plan refuses objects above 50 MiB and reports it as a 400 whose body carries the cause. That is matched and mapped to a 413, turning a 93-second upload that ended in a 502 into a refusal in 0.45 s.
  • All services pinned to Tokyo — Go API on Fly.io (nrt), SvelteKit on Vercel (hnd1), Supabase Postgres in ap-northeast-1, eliminating an SSR round-trip that previously crossed the Pacific twice.

Key Features

  1. Project catalogue — public showcase detailing technical architecture, tags, and image galleries for each project, with relations loaded in a single round trip via LEFT JOIN LATERAL + jsonb_agg rather than N+1 follow-up queries.
  2. Verified APK releases — direct file uploads or external build links (Expo, GitHub Releases), with automated checksums and metadata extraction. A release either holds a Storage object or links a hosted build, and /apk/latest counts the download before redirecting to whichever it is.
  3. Admin CMS — centralized dashboard to manage projects, tags, categories, and releases, with superforms + zod validation on both sides of the wire.
  4. AI assistant — chatbot answering questions about the catalogue from live database records, streamed over Server-Sent Events, with partial <<<UI_ACTION: delimiters held back across chunk boundaries so raw markers never leak into the transcript.
  5. Turnstile verification — Cloudflare bot-prevention challenge before an AI chat session can be opened.
  6. Bilingual throughout — English and Indonesian across the catalogue, the CMS, and this description, resolved client-side with no second SSR render and no CDN cache split.

Tech Stack

  • Go 1.26 + chi router (backend)
  • pgx/v5 + pgxpool (database access, QueryExecModeDescribeExec for the session pooler)
  • goose (database migrations, embedded in binary, applied on every boot)
  • Supabase (Postgres, Storage, GoTrue Auth)
  • SvelteKit 2 + Svelte 5 (runes)
  • Tailwind CSS v4 (CSS-first @theme)
  • bits-ui, superforms + zod4
  • DeepSeek API (AI assistant, streamed via SSE)
  • Cloudflare Turnstile (anti-bot gate)
  • Fly.io (backend, region nrt) + Vercel (frontend, region hnd1)

Status & Maturity

No automated CI — validation is run manually via go vet, go test, svelte-check, vitest, and production builds on every change. Test coverage is deliberately focused on the easiest places to introduce silent regressions: the AI context builder (including a byte-identical prompt assertion), AI UI action parsing, slug generation, project domain validation, and the frontend markdown sanitizer. A whole-site performance pass cut an uncached first visit from 2,072,015 B to 243,588 B (−88.2%) and every public page's JavaScript by 35,583 B gzipped; the budget that produced those numbers is enforced by re-measuring, not by estimate.

Measured Metrics

Commits 29
Date Range 19 Aug 2026 – 21 Aug 2026
Lines of code 14,364 (excluding lockfiles and one binary inadvertently committed)
Tests 38 Go tests + 12 Vitest tests, all passing