Portfolio & Showcase — This Site
An interactive portfolio that ships real artifacts rather than screenshots: every Android release carries version code, file size, minSdk, and SHA-256 checksum. Go API on Fly.io, SvelteKit frontend on Vercel.

This site itself — an interactive portfolio that ships real artifacts rather than screenshots. Every Android project in this catalogue carries a version code, file size, minSdk, and a verifiable SHA-256 checksum, rather than mere claims in text.
Highlights
- Truly streaming APK uploads — the backend reads request bodies through
MultipartReaderrather thanParseMultipartForm, staging to a temp file while anio.TeeReaderfeedssha256.New(). Memory stays flat regardless of file size: a 45 MiB APK peaked at 23,364 kB RSS, and the download round-trip came back byte-identical. - Direct browser-to-Go uploads, bypassing SvelteKit — Vercel caps serverless request bodies at 4.5 MB, so routing an APK through a form action would fail in production while working locally. Both uploaders POST straight to the Go API with
XMLHttpRequest, carrying their own bearer token and reporting real progress. - Dual-mode authentication — the middleware switches on the token's
alg, verifying JWKS (RS256/ES256) for modern Supabase projects and HMAC for legacy shared secrets. Authorization is read from theprofiles.rolecolumn behind a TTL cache, never fromapp_metadataclaims in the token. - Deliberate prompt caching for AI — the DeepSeek context is rendered with a fixed section order, sorted metadata keys and no timestamps, so the prefix stays byte-identical between requests. A unit test asserts two builds are identical; production logs measured 11,904 of 11,995 prompt tokens served from cache (99.3%).
- Storage limits mapped to real status codes — Supabase's free plan refuses objects above 50 MiB and reports it as a 400 whose body carries the cause. That is matched and mapped to a 413, turning a 93-second upload that ended in a 502 into a refusal in 0.45 s.
- All services pinned to Tokyo — Go API on Fly.io (
nrt), SvelteKit on Vercel (hnd1), Supabase Postgres inap-northeast-1, eliminating an SSR round-trip that previously crossed the Pacific twice.
Key Features
- Project catalogue — public showcase detailing technical architecture, tags, and image galleries for each project, with relations loaded in a single round trip via
LEFT JOIN LATERAL+jsonb_aggrather than N+1 follow-up queries. - Verified APK releases — direct file uploads or external build links (Expo, GitHub Releases), with automated checksums and metadata extraction. A release either holds a Storage object or links a hosted build, and
/apk/latestcounts the download before redirecting to whichever it is. - Admin CMS — centralized dashboard to manage projects, tags, categories, and releases, with superforms + zod validation on both sides of the wire.
- AI assistant — chatbot answering questions about the catalogue from live database records, streamed over Server-Sent Events, with partial
<<<UI_ACTION:delimiters held back across chunk boundaries so raw markers never leak into the transcript. - Turnstile verification — Cloudflare bot-prevention challenge before an AI chat session can be opened.
- Bilingual throughout — English and Indonesian across the catalogue, the CMS, and this description, resolved client-side with no second SSR render and no CDN cache split.
Tech Stack
- Go 1.26 + chi router (backend)
- pgx/v5 + pgxpool (database access,
QueryExecModeDescribeExecfor the session pooler) - goose (database migrations, embedded in binary, applied on every boot)
- Supabase (Postgres, Storage, GoTrue Auth)
- SvelteKit 2 + Svelte 5 (runes)
- Tailwind CSS v4 (CSS-first
@theme) - bits-ui, superforms + zod4
- DeepSeek API (AI assistant, streamed via SSE)
- Cloudflare Turnstile (anti-bot gate)
- Fly.io (backend, region nrt) + Vercel (frontend, region hnd1)
Status & Maturity
No automated CI — validation is run manually via go vet, go test, svelte-check, vitest, and production builds on every change. Test coverage is deliberately focused on the easiest places to introduce silent regressions: the AI context builder (including a byte-identical prompt assertion), AI UI action parsing, slug generation, project domain validation, and the frontend markdown sanitizer. A whole-site performance pass cut an uncached first visit from 2,072,015 B to 243,588 B (−88.2%) and every public page's JavaScript by 35,583 B gzipped; the budget that produced those numbers is enforced by re-measuring, not by estimate.
Measured Metrics
| Commits | 29 |
| Date Range | 19 Aug 2026 – 21 Aug 2026 |
| Lines of code | 14,364 (excluding lockfiles and one binary inadvertently committed) |
| Tests | 38 Go tests + 12 Vitest tests, all passing |