The problem
A portfolio usually claims things. This one is built to prove them: the site you are reading is itself a full-stack, database-backed system, and every claim it makes is enforced somewhere real.
How it works
- Next.js 16 (App Router, TypeScript strict) serves the public site, an admin panel and a versioned REST API from one codebase on Vercel.
- PostgreSQL (Neon) with Prisma holds everything. Visitors read only through public views under a separate database role — unpublished, private or client-restricted rows are not filtered out by the page, they never reach it.
- A daily scheduler runs the jobs: the GitHub sync that keeps this catalog current, data retention, and the figures shown on the home page.
- The CV is generated on request as PDF and Word from the same records the site shows.
- The AI guide answers questions from the site's own data, through the Vercel AI Gateway, read-only and behind feature flags.
Engineering decisions
- Rules live in the database. Business rules — an inquiry starts as new, a system is never deleted, a client's work stays hidden until approved — are database constraints and triggers, not page logic. The platform counts them live on the home page.
- Every admin change is audited by database triggers, not by code that a route could forget to call.
- Nothing hardcoded. Limits, windows, copy, titles and photos are admin-editable data; growing lists are lookup tables.
- Every database capability has an endpoint, enforced by a coverage test, and the API matches a written OpenAPI contract.
- Admin sign-in is hand-rolled — signed session cookies with a per-admin version, and two-factor authentication on every write.
Built to be trusted
- 41 migrations, all additive — a CI guard rejects anything destructive.
- 46 test files: unit tests and integration tests against a real Postgres database.
- Releases ship in reviewed batches, each closing its tracked issues.
Where it stands
Live in production and growing page by page — this systems catalog is part of the current redesign.