Experience
Several periods overlap. Working as a consultant, I was regularly deployed on more than one client engagement simultaneously — typically a primary assignment of three to four days a week alongside a second engagement for the remainder, as with Smart Cable Guard from 2021 and with TATA Steel alongside the internal IBM platform in 2018–2019. Periods shown are client engagements and may be shorter than the corresponding period of employment.
Senior Software Engineer / Technical Architect
Mar 2024 – PresentPwC · Dev Talents
Architectural ownership of critical capabilities within Beacon, PwC's Kubernetes-based enterprise graph-data platform for tax professionals: dynamic per-client virtual server environments with dedicated Neo4j databases, a semi-shared GraphQL/Node.js API and dual React front-ends over polyglot persistence. Over the past two years I have independently owned the end-to-end design and delivery of a major architectural initiative, spanning distributed coordination at Kubernetes cluster scale, polyglot persistence strategy, third-party SaaS integration boundaries, security architecture and high-throughput data processing.
- Cluster-Wide Concurrency Architecture — The platform depended on third-party APIs with hard access limits, which capped throughput at the level of a single pod and made horizontal scaling ineffective. I owned the design and implementation of a distributed credential pool that moved access accounting out of the individual pod and into the cluster: Redlock leases for cross-pod mutual exclusion, atomic Redis round-robin selection holding zero per-pod state, self-extending leases, stale-lock reclamation, contention-driven rotation and a circuit breaker. The central trade-off was accepting coordination latency on each acquisition in exchange for linear throughput scaling and predictable behaviour under pod churn and upstream outages; the alternative — static per-pod quota partitioning — was rejected because it wastes capacity whenever pod counts change. Result: throughput scales linearly with the cluster and degrades gracefully rather than failing.
- End-to-End Integration Ownership (Tableau) — Sole architect and engineer for the complete Tableau integration surface. Designed and executed the migration of the identity model from internal keys to email-based identity, including the permission model and user-facing widget; designed secret handling with encryption at rest, key rotation and re-encryption tooling; and specified rate-limit and outage behaviour at the boundary. Delivered secure React-embedded dashboards using GraphQL subscriptions, thumbnail batching and a hardened CSP, with end-to-end test coverage. Coordinated with security, platform and product stakeholders throughout.
- File Import Pipeline Re-architecture — Legacy CSV/Excel/JSON import loaded entire files into memory and produced user-visible timeouts on large datasets. I redesigned it as a streaming Minio/S3 and BullMQ sequential worker architecture, and relocated the heaviest graph operations — fingerprint deletion over multi-million-row datasets — into Neo4j Java stored procedures to keep the work next to the data. Timeouts were eliminated.
- Security & Platform Hygiene — Responsible for the shared GraphQL API as a governed surface: explicit resolver-level access control, harmonised error-handling conventions across resolvers, and schema evolution without breaking consumers. Resolved multiple high-severity CVEs through transitive dependency overrides, hardened CSPs, stabilised flaky tests and upgraded the Helm/Skaffold toolchain.
- Internal Tooling & Automation — Automated recurring development and platform-maintenance tasks in a purpose-built TypeScript CLI, so routine operations are reproducible and shareable instead of differing per engineer.
- AI-Assisted Development — AI-assisted tooling is a fixed part of the daily workflow: exploring unfamiliar parts of the codebase, generating and refactoring code, and scaffolding tests. Review, design decisions and accountability for the result stay with me.
Methods & tools: React, TypeScript, Node.js, GraphQL, Neo4j, Java, Kubernetes, Docker, Vite, Redis, MinIO, Skaffold, MongoDB, Tableau, Apollo, Jest, Vitest, Helm, Styled Components, PostgreSQL, Redlock, Kafka, BullMQ, SonarQube, Selenium, MikroORM, Cucumber, Grafana, Infrastructure as Code
Senior Backend Engineer
May 2023 – Mar 2024Belastingdienst · Ventus
Advised on and implemented architectural improvements to MKM2, a high-throughput messaging platform designed to process approximately 10 million messages per day under strict security and availability requirements, running inside the Belastingdienst's internal on-premise infrastructure.
Responsible for the design and delivery of changes in the processing chain, including load and performance validation with JMeter and Gatling, and for translating requirements from non-technical stakeholders into implementable technical solutions. Observability ran on Grafana dashboards and ELK-stack log aggregation. Every change was delivered tested and documented.
Methods & tools: Scala, TypeScript, Node.js, React, Python, Agile, Scrum, JMeter, Gatling, Grafana, ELK Stack, ESLint, Prettier, MySQL, Microsoft SQL Server, Cucumber, Platform Engineering
Technical Lead / Solution Architect
Feb 2022 – Dec 2022Alliander - Insight into Environment · Navara
Technical lead for the architectural renewal of the "Insight into Environment" platform, an energy-network visualisation embedded in Alliander's on-premise SAP landscape. The existing mapping foundation could not carry the required interaction model and had become a performance ceiling.
I owned the technical direction of the replacement: a Node.js/TypeScript architecture that took the mapping and interaction logic out of the SAP layer while retaining SAP as the system of record, so the platform could evolve on a modern stack without a disruptive migration of the surrounding landscape. Designed the new schematic map interactions and the drawing and editing capabilities, and delivered substantial performance improvements over the legacy implementation. Worked directly with network planners and SAP platform stakeholders to validate the design against operational practice.
Methods & tools: SAP UI5, ArcGIS, ESRI, SQL, JavaScript, TypeScript, Node.js, Jenkins, Git, GitHub Actions, XSD, HTML, SOAP, OData
Full Stack Developer
Jun 2021 – Feb 2022Stimulansz · Navara
Member of the Navara team that rebuilt the legacy KiC quality-control system from the ground up on GraphQL, React, Node.js, MongoDB and Azure. Contributed across the stack to the new application.
Within the team I owned the delivery infrastructure. I designed and implemented a fully dynamic Infrastructure as Code CI/CD pipeline on Azure (Bicep/YAML), including the Bash scripting for its build and deployment steps, established the integration and regression testing setup with Cypress, and coached the incoming DevOps engineer on both. Over the course of the project the team grew from three to six developers and reached a daily deployment cadence; the automated pipeline and test suite were what made that cadence sustainable.
Methods & tools: GraphQL, React, NX, Azure, TypeScript, Node.js, MongoDB, Styled Components, Apollo, Material UI, Docker, CI/CD, Cypress, Jest, Keycloak, YAML, Bicep, Bash, ESLint, Prettier, Agile, Scrum, DevOps, Infrastructure as Code, Test Pyramid, Platform Engineering
Lead Developer / Technical Owner
Apr 2021 – Dec 2022Alliander - Smart Cable Guard · Navara
Joined a newly formed three-person team responsible for the Smart Cable Guard platform, which monitors the condition of the energy grid, within Alliander's on-premise SAP landscape. The architecture spans an SAP UI5 front-end, a Node.js middleware layer and backend functionality in SAP HANA. I took responsibility for the backend and for the design of technical solutions across the stack.
On the strength of that delivery, Alliander asked me to take over management and continued development of the platform single-handedly for one day a week, alongside my other assignments; I held that ownership for a year and a half (April–July 2021 with the team, then September 2021 – December 2022 as sole owner).
In that period I set the technical direction for the platform, migrated the CI/CD pipeline from Jenkins to GitHub Actions, and automated a range of manual processes in the operational chain. The automation measurably reduced the administrative load on planners and field engineers, freeing their time for grid work.
Methods & tools: SAP UI5, SAP HANA, SQL, Jenkins, Git, GitHub, GitHub Actions, JavaScript, TypeScript, Node.js, YAML, HTML, XSD, SOAP, OData
Full Stack Developer
Jan 2021 – Apr 2021Nestlé · Navara
Worked with Navara's Zigzag team through the final phase before go-live of Nestlé's puppy training application.
Responsible for parts of the CI/CD pipeline and for delivering new features across the stack, including unit and integration test coverage.
Methods & tools: Angular, Ionic, Node.js, NX, Azure, TypeScript, MongoDB, CosmosDB, Docker, CI/CD, Cypress, Jest, Redux, NgRx, ESLint, Prettier, Agile, Scrum, DevOps, Test Pyramid, Platform Engineering
Lead Developer / Solution Designer
Oct 2020 – Jan 2021Deft Power · Navara
Designed and delivered the React Native MVP for Android and iOS for an electric-vehicle charging proposition, including real-time map, routing and backend integration.
Responsible for the technical set-up of the application and for the delivery decisions that kept an MVP scope shippable within the timeframe.
Methods & tools: JavaScript, TypeScript, React Native, Styled Components, Redux, MongoDB, Jest
Full Stack Developer
Jun 2019 – Jun 2020NG Compliance · NG-Compliance
NG-Compliance delivers enterprise solutions for anti-bribery legislation (FCPA, UK Bribery Act) and Governance, Risk and Compliance, built on its own GRC platform, Sherlock.
Responsible for extending and optimising platform functionality and for implementing customer-specific requirements on top of the standard product.
Methods & tools: Java, Spring Boot, SQL, Hibernate, GWT, PostgreSQL, Maven, Tomcat, JUnit, Mockito, ESLint, Prettier, Agile, Scrum, DevOps, Platform Engineering
Lead Developer / Integration Solution Lead
Nov 2018 – Jun 2019TATA-Steel · IBM
Engagement at the Dutch branch of one of the world's largest steel producers, carried out as the main assignment (roughly four days a week) alongside the internal IBM platform assignment.
I owned the resolution of billing and service-delivery data discrepancies between a TATA Steel system and an IBM system — a persistent mismatch that was being corrected manually. I designed and built the reconciliation independently in Python over the SOAP interfaces of both systems, removing the discrepancy and the manual overhead attached to it.
I also contributed to a team-based project structuring and analysing heterogeneous document types with Watson's natural-language tooling. There the dominant risk was requirement volatility rather than technology, and my focus was on keeping scope and stakeholder expectations aligned as the requirements moved.
Methods & tools: Python, SOAP, SQL, Watson Explorer, Watson Knowledge Studio, Watson NLA
Lead Developer / Solution Architect
Sep 2018 – Jun 2019IBM · IBM
Designed and built IBM's internal Feedback Form platform end to end on a MEAN stack (MongoDB, Express, Angular, Node.js), with Watson NLA integration for response analysis and a CloudFoundry CI/CD pipeline. Took technical lead responsibility for the platform, including its technical direction and delivery. The platform was subsequently sold to other divisions within IBM.
Started in September 2018 as the sole assignment; from November 2018 it continued as a secondary assignment of roughly one day a week, run in parallel with the TATA Steel engagement.
Methods & tools: MongoDB, Express, Angular, Node.js, IBM Cloud, CloudFoundry, Docker, CI/CD, Watson NLA, ESLint, Prettier, Agile, Scrum, Platform Engineering
Integration Specialist / Software Engineer
Sep 2017 – Jan 2019Jumbo Supermarkten · IBM
Member of the integration team responsible for improving, replacing and extending the interfaces across Jumbo's enterprise infrastructure, and for connecting new parts of the organisation to the digital platform.
I was responsible for monitoring of message traffic across the platform, for which I designed and implemented an entirely new solution, and I subsequently built a tooling set for application performance monitoring in Node.js, TypeScript and Angular that gave the team visibility into the behaviour of the interfaces in Jumbo's network.
The principal challenge was organisational rather than technical: consolidating requirements from many teams into a single enterprise-level solution.
Methods & tools: Websphere Message Broker, IBM MQ, IBM Integration Bus, ESQL, XML/XSD, MEAN-Stack, IBM Cloud, CloudFoundry, SOAP, REST, Java, JavaScript, TypeScript, Python, MongoDB, Angular, Express, Node.js
Technical Skills
Languages
JavaScript, TypeScript, Java, Python, Scala, C/C++, Rust, Dart, Solidity
Frameworks
GraphQL, Apollo, NestJS, Express, Tailwind CSS, Angular, LangGraph, SGLang, Prisma, BullMQ, Next.js, MikroORM, React, Node.js, Mongoose, egui / eframe, Riverpod, TanStack Query, Zustand, shadcn/ui, React Hook Form, Local LLMs, Flutter, Bevy, eframe / egui, Recharts, FastAPI, Fastify, sqlx, Hardhat, React Flow, ARQ, React Native, React Three Fiber, Framer Motion, Astro, Spring Boot, Three.js, Axum
Databases
MinIO, Redis, MySQL, Neo4j, MongoDB, LanceDB, Microsoft SQL Server, PostgreSQL, SQLite, Kuzu
Platform & Cloud
Azure, IBM Cloud, AWS, Google Cloud
Tools & DevOps
WebSocket, Vitest, WireGuard, Zod, Nginx, MCP (Model Context Protocol), Kubernetes, Git, Vite, GitHub Actions, ESLint, Prettier, Stripe, Bash, Prometheus, Socket.io, Docker, Docker Registry, Gitea, Helm, RustDesk, notify (filesystem), git2, Parquet / Arrow, tree-sitter, Resend, Grafana, Dockerode, Jenkins, CoinGate, WebRTC, Neko, Obsidian, LoRA / QLoRA, Tesseract, Puppeteer, ELK Stack, Skaffold, Kafka, Surya, Commander, Storybook, Fuse.js, Traefik, Tailscale, SearXNG, Unsloth, FastEmbed, DataFusion, PM2, Coinbase Commerce, ethers.js, OpenZeppelin, node-cron, Sharp, flutter_rust_bridge, vodozemac (Olm/Megolm), Gemini, Shiki, Radix UI, Let's Encrypt, ClamAV, Everlaw, License Management, Relativity, rodio, Rayon
Testing
SonarQube, Selenium, Jest, Cypress, Cucumber, JMeter, Gatling, Playwright
Methodologies
Monorepo Architecture, Infrastructure as Code, End-to-End Encryption, Agile, Test Pyramid, Platform Engineering, Scrum, DevOps, CI/CD
Personal Projects
Enclave — Self-Hosted End-to-End Encrypted Messenger
A self-hosted, end-to-end encrypted messenger implementing the modern Signal protocol stack: X3DH key agreement and the Double Ratchet for 1:1 sessions, and Megolm sender-keys for efficient group chats. Cryptography runs through vodozemac (the Rust Olm/Megolm library used by Matrix).
The Flutter/Dart client (Riverpod) bridges via flutter_rust_bridge to a Rust core that owns crypto, encrypted storage (SQLCipher), and networking. A dedicated Rust Axum relay routes only ciphertext over WebSockets, with a PostgreSQL offline queue for delivery when a device is off. Multi-device linking is handled with QR-based session transfer. Verified by unit tests, a CI job that drives two clients through the full wire protocol against a live relay and Postgres, and a repeatable two-emulator runtime integration pass.
Stack: Flutter, Dart, Riverpod, Rust, flutter_rust_bridge, vodozemac (Olm/Megolm), End-to-End Encryption, Axum, WebSocket, PostgreSQL, SQLite
StarChamp — 4X Real-Time Strategy Space Game (Rust / Bevy)
A 4X real-time strategy space game built in Rust on the Bevy 0.14 ECS. Players colonize planets, mine asteroids, research technologies, build fleets, send resource offers to rivals, and fight for galactic dominance across five victory conditions. Combat resolves once per clock-driven turn, with unit formations (line, wedge, circle, column), five activatable ship abilities (afterburner, shield, barrage, cloak, repair), weapon ranges, and positioning.
The crate ships four binaries — the Bevy game client, a dedicated game server, an egui-based map editor, and a lobby server — plus server-authoritative WebSocket multiplayer with delta compression, full replay record/playback, and player-to-player resource trading. Audio is procedurally synthesized through rodio. The main line is ~26k lines of Rust across those four binaries; a separate gameplay branch runs to ~78k while exploring further combat and UI systems, and the repo carries ~710 commits across all branches.
Stack: Rust, Bevy, egui / eframe, WebSocket, rodio, Monorepo Architecture
@snlans/* — Private TypeScript Library Ecosystem
A private pnpm monorepo of 18 independent, production-grade TypeScript packages published under the @snlans scope and consumed across webshop, crawler-saas, cv-site, tool-sites, blog, and mail-service. Packages include @snlans/auth (JWT / OAuth / RBAC / API keys / TOTP / magic links), @snlans/stripe, @snlans/storage (S3 / Azure / GCS / local + media processing), @snlans/crawler, @snlans/queue (Memory / BullMQ / Postgres / SQLite backends), @snlans/observability, and a @snlans/ship deploy CLI.
The design philosophy is framework-agnostic cores with thin Express adapters and edge/Web-standard entry points that drop straight into Next.js middleware, explicit types everywhere, over 11,000 tests with 90% coverage thresholds configured, and TypeDoc-generated docs — a genuine "build once, extract, reuse" ecosystem. ~380 commits.
Stack: TypeScript, Monorepo Architecture, Vitest, BullMQ, Stripe, MinIO, PostgreSQL, Redis, Platform Engineering
Lanselot Pro — Self-Hosted Agentic Coding Assistant
The first of two products in the gx10 repo: an agentic coding assistant for a private workstation, built from three decoupled services. A native Rust indexer watches the workspace with notify, parses a semantic AST with tree-sitter (Python + TypeScript), embeds chunks locally with FastEmbed and scrapes git history with git2 — writing vectors into LanceDB and a relational/graph layer into Parquet queried through DataFusion. A FastAPI + LangGraph engine enqueues each request onto an ARQ worker, checkpoints graph state in Postgres, and streams thoughts and tokens back over Redis Pub/Sub as Server-Sent Events. A Next.js 15 / React 19 hub renders the chat, an indexer dashboard, and a codebase graph (xyflow + d3-force).
The graph is compiled to interrupt before its tools node, so in the strictest autonomy mode a tool call — running a shell command, for example — pauses execution, persists state to Postgres, and waits for an Allow/Deny decision in the UI before resuming; two looser modes auto-approve read-only tools, or everything. The stack is designed for an on-prem NVIDIA box: an ASUS Ascent GX10 (GB10 Grace-Blackwell, 128 GB unified memory), with a compose file that ships SGLang serving Qwen/Qwen3-32B next to Postgres, Redis, and a self-hosted SearXNG. Honest caveat: fully local inference is the goal, not the shipped default — the model selector falls back to cloud gemini-2.5-flash unless a local SGLang endpoint is chosen.
~47 commits across the three services, in a repo shared with the Lanselot digital butler (~207 commits repo-wide). An early sibling prototype, Lanselot Pro Hybrid, is one commit deep: scaffolding for a legal-document RAG pipeline aimed at a hypothetical bilingual law firm — pytesseract and pdf2image baked into the worker image, bge-m3 embeddings behind a TEI container, LanceDB as the target and per-case row-level scoping injected as a prefilter — with the OCR worker itself still a simulated stub.
Stack: Rust, Python, FastAPI, LangGraph, LanceDB, DataFusion, FastEmbed, tree-sitter, git2, Parquet / Arrow, Rayon, Next.js, SGLang, SearXNG, Gemini, PostgreSQL, Redis
Lanselot — Autonomous Agent Swarm & Digital Butler
The second and most-developed product in the gx10 repo — not a newer version of the coding assistant but a separate system: an always-on personal assistant. A Starlette router exposes an OpenAI-compatible /v1 API in front of an SGLang container serving Qwen/Qwen3.5-35B-A3B-FP8 at 131k context; keeping inference in its own container means the Python layers can be restarted in seconds without paying the model cold-start again. OpenWebUI is the desktop frontend, and a Signal bridge (signal-cli REST API) puts the same assistant in a phone chat — voice notes transcribed locally by a Cohere ASR model, spoken replies synthesized with Kokoro.
Memory is three stores with different jobs: LanceDB for semantic search over an Obsidian vault that a watchdog re-embeds on every save, a Kuzu graph for durable facts, preferences and note-to-note links, and SQLite for the scheduler and chat history. Thirty registered tools cover vault read/write and auto-linking, memory CRUD, SearXNG search and page fetching, a news agent that tracks followed topics, Google Calendar, and Python execution inside a sandbox container with no host volumes and no published ports. Long jobs are spawned as sub-agents onto an ARQ/Redis swarm — the worker is capped at one CPU and 4 GB so background research cannot starve the inference container — and SQLite cron tasks let the system contact its owner on Signal unprompted.
Iterated as 51 versioned deployment directories, from V1 (Qwen 32B fp16) to the current V12.0.0 — every one a runnable compose stack, the later ones carrying the full config and app tree, and nothing pruned: the versions marked FAILED and ROLLBACK are still there. ~141 commits, on the same on-prem ASUS Ascent GX10 (NVIDIA GB10, 128 GB unified memory) as Lanselot Pro.
Stack: Python, SGLang, ARQ, LanceDB, Kuzu, SQLite, Redis, SearXNG, Obsidian, Docker
Crawler SaaS — Visual Web-Crawling Platform
A web-crawling SaaS built as a pnpm/TypeScript monorepo: a Next.js 15 frontend with a seven-step visual job builder and live progress, and an Express + BullMQ backend running five specialized worker types (schedule, crawl, browser, export, cleanup). It leans heavily on the @snlans/crawler engine and other shared packages for auth, queues, storage, and billing.
Backed by PostgreSQL 16 (organization-scoped multi-tenancy) and Redis 7, with ethical-crawling defaults (robots.txt, politeness, rate limiting) and five pre-built schema extractors plus a custom-schema option. ~113k LOC of TypeScript — roughly half of it tests — across ~117 commits.
Stack: TypeScript, Next.js, Express, PostgreSQL, Redis, BullMQ, Socket.io, Radix UI, Vitest, Docker, Platform Engineering
Free Online Tools Platform [lans.cloud]
A Next.js App Router platform serving 107 single-purpose browser tools across 11 cluster hubs at lans.cloud — classroom utilities, generators, calculators, party and prank tools. Tool logic is client-side by design: the core of a tool runs without a server round-trip, which is what keeps the pages fast enough to compete on Core Web Vitals. Prisma over the shared PostgreSQL cluster backs everything that is not the tool itself — first-party page and referrer stats, tool link clicks and impressions, and a Google Search Console query ledger.
Every tool page carries its own metadata, JSON-LD, HowTo and FAQ blocks and an /llms.txt surface for AI crawlers, plus an Open Graph card generated offline by a headless-Chrome screenshot pipeline (puppeteer-core) on top of the owner's own @snlans/seo package. What gets built is decided from measured search data rather than intuition: a written targeting doctrine that screens a query on whether its SERP already has an incumbent — and that was rewritten when a Search Console pull falsified its first version, which had assumed phrase length and cluster depth drove ranking.
The entire third-party ad chain sits behind a single build-time killswitch, added after measuring the ad loader at roughly 31% of the homepage's served bytes while filling nothing (the ad account was never approved); re-enabling is a documented flag flip and rebuild rather than an archaeology exercise. A daily digest job mails the previous day's traffic, click and Search Console movement through the internal mail-service. Deployed as a locally built image streamed to the VPS behind Traefik. Roughly 210k lines of TypeScript across ~1,360 commits, with 4,015 tests in 302 files.
Live: lans.cloud
Stack: Next.js, React, TypeScript, Tailwind CSS, shadcn/ui, Prisma, PostgreSQL, Puppeteer, Vitest, Docker, Traefik, Platform Engineering
Lans Shop — Digital Commerce Platform [shop.lans.cloud]
A commerce platform for digital goods, SaaS subscriptions, services, and software licenses, now running as the v2 rebuild after a MongoDB-to-Postgres cutover, with v1 archived under legacy/. Built on Next.js 16 / React 19 with Tailwind 4 + shadcn/ui, Prisma 7 over PostgreSQL 16, Redis, and MinIO for presigned, purchase-gated asset delivery.
Payments run through Stripe, with a provider-abstracted crypto path (CoinGate preferred; the Coinbase Commerce integration is kept as legacy after Coinbase closed to EU merchants) and all monetary values stored as integer cents. It consumes eight @snlans packages — auth, stripe, storage, security, seo, license, observability, ship — so effort concentrates on catalog, cart, checkout, fulfillment, and license delivery. The v2 rebuild is ~28k LOC across ~190 commits since the v1-final tag, next to the ~65k-LOC v1 archive, with Playwright + Vitest coverage.
Live: shop.lans.cloud
Stack: Next.js, React, TypeScript, Prisma, PostgreSQL, Redis, MinIO, Tailwind CSS, shadcn/ui, Stripe, CoinGate, Playwright, Vitest
Markdown Blog Platform [blog.lans.cloud]
A production Astro blog that generates posts from a mounted markdown directory with server-side Shiki syntax highlighting. It adds Fuse.js full-text search, series navigation, per-post Open Graph images rendered with Satori/resvg, JSON-LD, RSS, and an /llms.txt surface for AI crawlers.
Monetization runs through Stripe subscriptions with magic-link auth, gating premium posts, plus a double opt-in newsletter delivered via the internal mail-service. Deployed with Docker behind Traefik. ~16k LOC across ~106 commits.
Live: blog.lans.cloud
Stack: Astro, TypeScript, SQLite, Shiki, Fuse.js, Stripe, Resend, Docker, Traefik
This Portfolio [cv.lans.cloud]
The portfolio itself, built as a pnpm + Turborepo monorepo. The backend is NestJS 11 with a code-first GraphQL API (Apollo), MikroORM 6 over PostgreSQL, Redis, BullMQ for the live-lab job queue, and MinIO for the gated CV PDF. The frontend is Next.js 15 / React 19 styled with Panda CSS, featuring an interactive expertise graph (React Flow + d3-force) that visualizes skills, technologies, projects, and outcomes.
It includes a gated CV-download flow (magic-link approval), a Cloudflare Turnstile-protected contact form, a JWT-authenticated admin panel with CRUD for experience, skills, outcomes, and projects, and self-hosted Umami analytics.
Live: cv.lans.cloud
Stack: TypeScript, NestJS, GraphQL, MikroORM, PostgreSQL, Redis, BullMQ, MinIO, Next.js, React, Monorepo Architecture
recall — Semantic Search & Dependency Graph Over a Workspace
A Python tool that indexes the written record of a whole multi-repo workspace, every git-tracked markdown file and every commit message across ~36 repositories, into a single SQLite database, and answers "have we hit this before" and "why did we choose X" by meaning rather than by keyword. The live index is 8,706 documents split into 47,354 chunks, every one embedded. Retrieval is hybrid: BM25 over FTS5 fused with cosine similarity over bge-m3 vectors held in sqlite-vec. Embeddings are computed locally through FastEmbed, so after the model is cached the tool makes no network call at all.
The fusion weights are measured, not assumed. On a 20-query golden set with strict path-matched scoring, keyword-only search reaches recall@5 of 0.05 and vector-only 0.35, meaning that on prose questions over this corpus semantic search does effectively all of the work, so the arms are fused 4:1 vector:keyword after a sweep showed equal weighting let the weak arm outvote the strong one's mid-ranks. Keyword-only survives as the right tool for an exact token (an error string, a sha, a package name) and is the only mode that loads no model.
The second half is exact rather than statistical: a dependency graph parsed from package.json, Cargo.toml, pyproject.toml and pnpm workspace members, so `deps` lists every repo pinning a package and `impact` reports who actually receives a given release. It encodes the rule that below 1.0.0 a caret does not float the minor, which means a publish can reach nobody until pins are bumped by hand.
The newest layer makes retrieval ambient rather than asked for. A long-lived daemon (`recall serve`, under launchd) holds the embedding model warm and serves HTTP over a unix domain socket beside the index, no TCP port and no auth token, because the filesystem is already the authorisation boundary for the database itself. A prompt hook asks that daemon a question on every prompt and injects at most three workspace pointers when the best hit clears a similarity threshold. The threshold was measured rather than guessed: 200 real prompts were harvested and scored, and τ = 0.71 was chosen as the lowest value whose precision interval clears 0.8 (precision 0.95, Wilson 95% [0.82, 0.99], firing on roughly one prompt in ten, with the irrelevant hits clustering just below it). The safety case is latency and reversibility: compute is 67 ms at the median and 130 ms at p95 against a 2 s hook budget, the hook fails open on any error so a broken daemon can never cost a prompt, and a single file toggles the whole thing off with no restart.
Three entry points share one engine: the CLI (`index`, `search`, `stats`, `doctor`, `serve`, `deps`, `impact`), an MCP stdio server exposing three read-only tools, and the daemon, which the MCP server also proxies its vector work to so the 2.27 GB model is loaded once on the machine rather than once per process. A nightly launchd job re-indexes incrementally by head sha and then runs `doctor`, because the index stage commits its freshness stamp before embedding finishes, so a run killed mid-embed would otherwise leave a stamped, fresh-looking, vectorless index. About 5k lines of Python behind 7.3k lines of tests (1,261 cases) across 96 commits.
Stack: Python, SQLite, sqlite-vec, FTS5, FastEmbed, bge-m3, MCP (Model Context Protocol), Unix Domain Sockets, launchd
Online Raffle & Lottery Platform
An online raffle and lottery platform with a TypeScript + Express backend and a separate React 19 + Vite frontend, backed by MongoDB via Mongoose. Hourly and daily draws run unattended on node-cron — the job picks a ticket-weighted winner, closes the raffle, credits 90% of the pot, and opens the next period. Players top up an in-app balance by transferring a self-issued ERC-20 token on BSC testnet, which the backend verifies on-chain with ethers.js by parsing each deposit transaction's Transfer log.
Wired with JWT auth, bcrypt, helmet, rate limiting, and compression, and shipped as separate backend/frontend Docker images pushed by self-hosted CI. 377 commits over an intensive Feb–Apr 2025 build.
Stack: TypeScript, Express, React, MongoDB, Mongoose, ethers.js, node-cron, Docker
Artist Portfolio — Milen Dimitrov [milendimitrov.art]
A full-stack portfolio site built for 2D designer Milen Dimitrov, with a distinctive circular, space-themed UI. The frontend is React 18 + Vite with Framer Motion; the backend is Node 20 + Express on MongoDB via Mongoose, with a Sharp-based image-processing pipeline and a secure admin dashboard for content management.
Deployed with Docker Compose behind Traefik and covered by a 120-test Playwright E2E suite. It answers on two hostnames — the artist's own milendimitrov.art and portfolio.lans.cloud — from a single router rule per service rather than a duplicated stack, so both domains serve the same containers and Let's Encrypt issues for both. ~25.8k lines of TypeScript (plus ~9k CSS) across ~188 commits.
Live: milendimitrov.art
Stack: React, TypeScript, Framer Motion, Express, MongoDB, Mongoose, Sharp, Docker, Traefik, Playwright
Plane MCP Server — 35 Tools for AI Assistants
A Model Context Protocol (MCP) server that exposes project management as native tools for AI assistants like Claude Code. Built on the official MCP Python SDK — stdio for local Claude Code use, SSE behind Traefik when Dockerized — it provides 35 tools: 24 for Plane, 8 for Git, and 3 for GitHub. A heuristic complexity engine scores tickets, parses "depends on / blocked by" references (with a topological sort over them), and proposes a sub-task breakdown the calling agent can then create through the sub-issue tools.
A companion Python CLI, md-to-plane, migrates structured markdown todo files into Plane as modules (epics) and AI-agent-ready issues. Dockerized for easy integration.
Stack: Python, MCP (Model Context Protocol), Docker
Self-Hosted Core Infrastructure & Shared Services (MinIO · Postgres · Redis)
Five Docker Compose services on one VPS, attached to an already-running external Traefik network rather than owning the edge: MinIO for S3-compatible object storage (public API at s3.lans.cloud), PostgreSQL 16, Redis 7 with AOF + RDB persistence and AUTH, self-hosted Umami for cookieless analytics (analytics.lans.cloud, its own database on the shared Postgres), and Remark42 for blog comments (comments.lans.cloud, email-verified sign-in, anonymous commenting deliberately off). Webshop and the tool-sites platform run on the shared Postgres; cv-site keeps its own database and consumes only the shared object storage.
The security posture is deliberate. No database ports are published to the host at all — applications resolve infrastructure-postgres:5432 and infrastructure-redis:6379 over Docker DNS. Each app gets its own database and least-privilege user from an idempotent provisioning script that hands the app ownership of just that database and revokes CONNECT from PUBLIC. After a security audit the MinIO admin console was taken off the internet entirely (loopback bind, SSH tunnel only), while the S3 API stays public with browser-facing buckets on a custom GetObject-only anonymous policy instead of the listing-enabled preset.
Every service has a healthcheck, and Umami only starts once Postgres reports healthy. A nightly cron rotation keeps seven rolling day-of-week copies of a full pg_dumpall and a Redis snapshot — AES-256 encrypted before they enter a private offsite git repository — alongside an mc mirror of the buckets, where the private ones go in as an encrypted tar and the public site assets stay plain. A quarterly drill re-checks freshness and decrypts every artifact to verify integrity, emailing on failure. A load and runaway-process watchdog, written after an orphaned recursive search quietly pegged three and a half of four cores for five days, now runs every fifteen minutes.
Stack: Docker, MinIO, PostgreSQL, Redis, Umami, Remark42, Traefik, Let's Encrypt, Infrastructure as Code, Platform Engineering
Self-Hosted Homelab & Reverse-Proxy Platform
A personal homelab VPS, run through 2025 and since decommissioned in favour of the current lans.cloud infrastructure. A central Nginx reverse proxy (sites-available/enabled discipline, Let's Encrypt TLS termination with HSTS, a 444 catch-all for unmatched hosts) exposed self-hosted Gitea, an htpasswd-authenticated private Docker registry, Nextcloud, and the deployed applications.
The registry anchored a real push-to-deploy chain: self-hosted CI built and pushed images, the registry's webhook notified a small PM2-managed Node receiver, and a lock-guarded deploy script pulled and restarted the containers. Remote access ran over two independent paths — WireGuard for encrypted network access, with self-hosted RustDesk as a GUI fallback.
Stack: Nginx, Docker, WireGuard, Gitea, PM2, PostgreSQL, Let's Encrypt, Platform Engineering
Internal Mail Gateway Microservice
A small, purpose-built microservice that fronts SMTP with an internal HTTP API, so the lans.cloud apps authenticate with a service key rather than sharing the mailbox password. Built with Fastify on top of @snlans/email.
It joins the Traefik network with no public exposure — siblings reach it internally — boots cleanly without SMTP credentials, and returns 503 until configured. Four applications now send through it: the tool-sites daily digest, the blog newsletter, webshop, and cv-site.
Stack: TypeScript, Fastify, SMTP, Docker, Traefik, Vitest
AI Programming Toolkit
A documentation-and-templates toolkit that codifies standards, configs, and best practices for AI-assisted development, targeting Copilot / Claude Code / Cursor workflows. It includes reusable modules, worked examples, a showcase, and a setup wizard.
A content-first project capturing a repeatable method for getting high-quality output from AI coding tools. Four of the nine modules ship configs, templates, and examples; the other five are documentation-only guides with no installable assets yet. ~33 commits, paused since late 2025.
Stack: MCP (Model Context Protocol), Platform Engineering
MishCoin — ERC-20 Token Contract
A focused Solidity ERC-20 token (MishCoin, symbol MISH) built on OpenZeppelin's ERC20 + Ownable. It supports owner minting, holder burning, and recovery of tokens sent to the contract address by mistake, and ships a small ethers deploy script targeting a BSC testnet.
Deliberately small in scope — a smart-contract exercise rather than a product.
Stack: Solidity, Hardhat, OpenZeppelin, ethers.js, TypeScript