Infrastructure.
The production path for divyam.top: one private GitOps repo describes a 2-vCPU VPS end to end. A systemd timer pulls it every five minutes and converges with Docker Compose. Caddy is the only thing with public ports.
- Host
- 2 vCPU · 4 GB · Ubuntu 24.04
- Deploy
- git push → ≤ 5 min
- Public ports
- 80 · 443 (Caddy only)
- TLS
- Let’s Encrypt, CAA pinned
Topology
request path, left to rightClient
- User browserany modern browser
DNS
- Namecheap DNSA @ · A www · CAA letsencrypt.org
Edge
- CaddyTLS via Let’s Encrypt · security headers · CSP
- CrowdSecbouncer in Caddy · bans on the security page
Source
- GitHubportfolio-next + voyager · read-only deploy keys
Build
- systemd timergit pull every 5 min · fingerprint diff
- docker composeup -d --build · caddy reload
- Next.js exportnode build → caddy:2-alpine :8080
Services
- Hugo blog/blog · built by deploy.sh
- Gatusstatus.divyam.top · uptime checks
- GoatCounteranalytics.divyam.top · no cookies
- hopgo. + paste.divyam.top · Go
- NetBirdvpn.divyam.top · self-hosted mesh
- Zitadelaccounts.divyam.top · OIDC
- User browserNamecheap DNSresolve
- User browserCaddyHTTPS
- CaddyCrowdSeccheck IP
- CaddyNext.js exportreverse_proxy :8080
- GitHubsystemd timergit pull
- systemd timerdocker composechanged?
- docker composeNext.js exportbuild
- GatusCaddyprobe
- Request-time· what happens when you load the page
- Build-time· git push → the box rebuilds within five minutes
- Out-of-band· monitoring that runs on its own clock
A push to main is the whole deploy: the box pulls every five minutes, rebuilds only when the repo fingerprint changes, runs docker compose up -d --build and reloads Caddy. This page itself is a Next.js static export built inside a multi-stage Dockerfile and served by a tiny Caddy container that the edge Caddy proxies to.
