# Portfolio

> Browse the full portfolio of Engineer ApS engineering achievements, each with a detailed review.

- [Increased brand popularity by 200x through successful brand development across offline and online platforms.](https://engineer.company/portfolio/increased-brand-popularity-by-200x-through-successful-brand-1/)
- [Drove brand engagement and loyalty by 100% through market trend analysis and consumer behavior insights.](https://engineer.company/portfolio/drove-brand-engagement-and-loyalty-by-100-through-2/)
- [Designed a comprehensive infrastructure framework for DTU impacting 14 departments, featuring flexible modules, unified data pipelines, and structured support strategies for long‑term adoption.](https://engineer.company/portfolio/designed-a-comprehensive-infrastructure-framework-for-dtu-impacting-3/)
- [Engineered hourly electricity consumption aggregation pipeline in Python / SQL / Bash + Jq, achieving 180ms for 30‑day datasets across heterogeneous JSONL sources.](https://engineer.company/portfolio/engineered-hourly-electricity-consumption-aggregation-pipeline-in-python-4/)
- [Accelerated geographical data pipeline performance by 50x by improving SQL programming and data modeling across PostgreSQL, MS SQL, and Google Cloud BigQuery.](https://engineer.company/portfolio/accelerated-geographical-data-pipeline-performance-by-50x-by-5/)
- [Improved geographical map application performance by 10x through strategic database transition from MSSQL to PostgreSQL, optimizing processing and data security.](https://engineer.company/portfolio/improved-geographical-map-application-performance-by-10x-through-6/)
- [Resolved 1,000 issues in geographical data and time‑series data, using GDAL, ArcGIS, PostGIS, Mapbox, QGIS, SQL (PL/pgSQL, Transact‑SQL), Bash, ensuring high‑quality big data processing.](https://engineer.company/portfolio/resolved-1-000-issues-in-geographical-data-and-7/)
- [Designed, implemented, and administered 6 ETL/ELT pipelines, utilizing Google BigQuery, MSSQL, PostgreSQL, Shell scripting, PL/pgSQL, and Transact‑SQL, integrating data for efficient Python API processing.](https://engineer.company/portfolio/designed-implemented-and-administered-6-etl-elt-pipelines-8/)
- [Developed and launched the company's first observability dashboard, providing real‑time system performance insights and data visualization on the large office TV.](https://engineer.company/portfolio/developed-and-launched-the-company-s-first-observability-9/)
- [Delivered 8 Power BI projects with comprehensive manuals, integrating Microsoft Power BI tools with NodeJS API and Python FastAPI for effective data analytics and visualization.](https://engineer.company/portfolio/delivered-8-power-bi-projects-with-comprehensive-manuals-10/)
- [Released 500 electricity and GIS data analysis reports, utilizing deep research and troubleshooting to ensure accurate geographic and time series big data insights.](https://engineer.company/portfolio/released-500-electricity-and-gis-data-analysis-reports-11/)
- [Architected, created, and managed 100 PostgreSQL, MS SQL, and Google BigQuery data warehouse databases with primarily GIS and time‑series data, optimizing performance and scalability.](https://engineer.company/portfolio/architected-created-and-managed-100-postgresql-ms-sql-12/)
- [Designed, deployed, and maintained 10 PostgreSQL and MS SQL servers on Ubuntu Linux VPS, ensuring optimal server performance and reliability.](https://engineer.company/portfolio/designed-deployed-and-maintained-10-postgresql-and-ms-13/)
- [Enhanced data security by implementing 1,000 RBAC rules for developers, application instances, PostgreSQL, MS SQL, and other Linux servers, preventing unauthorized access; documented with Ansible automation.](https://engineer.company/portfolio/enhanced-data-security-by-implementing-1-000-rbac-14/)
- [Accelerated PostgreSQL performance by 10x via strategic indexing, partitioning, and query optimization, enhancing database efficiency for user, tenant, geospatial, and time‑series electrical data.](https://engineer.company/portfolio/accelerated-postgresql-performance-by-10x-via-strategic-indexing-15/)
- [Automated GIS SaaS application deployment, data processing, and reporting system using GitHub Actions CI/CD, Python, Bash, and SQL.](https://engineer.company/portfolio/automated-gis-saas-application-deployment-data-processing-and-16/)
- [Automated delivery of 20 GIS data pipelines and app data ETL processes, streamlining infrastructure automation and reporting.](https://engineer.company/portfolio/automated-delivery-of-20-gis-data-pipelines-and-17/)
- [Automated 100 critical data backups using Barman, Google Cloud, Bash, and Python, ensuring data integrity across databases.](https://engineer.company/portfolio/automated-100-critical-data-backups-using-barman-google-18/)
- [Deployed and maintained 20 Docker containerized applications, troubleshooting with Podman and Kubernetes, and managing R‑based apps on Google Cloud and AWS.](https://engineer.company/portfolio/deployed-and-maintained-20-docker-containerized-applications-troubleshooting-19/)
- [Managed 30 Ubuntu Linux VPS instances, implementing disaster recovery strategies and ensuring optimal network configurations.](https://engineer.company/portfolio/managed-30-ubuntu-linux-vps-instances-implementing-disaster-20/)
- [Prevented security breaches by leading access management initiatives, utilizing M365, 1Password, Red Hat SSO, and OKTA SSO.](https://engineer.company/portfolio/prevented-security-breaches-by-leading-access-management-initiatives-21/)
- [Mitigated operational risks by implementing a monitoring dashboard using Grafana and Prometheus, improving system reliability.](https://engineer.company/portfolio/mitigated-operational-risks-by-implementing-a-monitoring-dashboard-22/)
- [Managed and troubleshooted 8 WireGuard VPN and IPSEC VPN connections, ensuring secure communication across Google Cloud and Linux systems.](https://engineer.company/portfolio/managed-and-troubleshooted-8-wireguard-vpn-and-ipsec-23/)
- [Led the software development of a GIS map application, driving revenue growth by 10x and positioning the product as a primary data asset.](https://engineer.company/portfolio/led-the-software-development-of-a-gis-map-24/)
- [Directed full‑stack GIS map development, overseeing PostgreSQL, Mapbox, ReactJS, and NodeJS to deliver an integrated solution.](https://engineer.company/portfolio/directed-full-stack-gis-map-development-overseeing-postgresql-25/)
- [Saved 4,000 hours by mentoring and growing a team from 2 to 18 members, optimizing workflows and fostering cross‑departmental collaboration.](https://engineer.company/portfolio/saved-4-000-hours-by-mentoring-and-growing-26/)
- [Optimized forecasting and investment strategies for 11 electricity grid operators, driving operational efficiency through data‑driven GIS solutions.](https://engineer.company/portfolio/optimized-forecasting-and-investment-strategies-for-11-electricity-27/)
- [Presented 200 UI/UX improvements for the GIS map application, boosting revenue by 10x through enhanced software features.](https://engineer.company/portfolio/presented-200-ui-ux-improvements-for-the-gis-28/)
- [Designed and managed 5,000 hours of map development, utilizing Agile methodologies such as Scrum and Jira for effective project management.](https://engineer.company/portfolio/designed-and-managed-5-000-hours-of-map-29/)
- [Wrote 50,000 words of comprehensive software documentation utilizing Markdown in GitHub, Craft, and Confluence, thereby ensuring the retention of knowledge and the transparency of the process.](https://engineer.company/portfolio/wrote-50-000-words-of-comprehensive-software-documentation-30/)
- [Gathered and analyzed business requirements to translate into actionable features and user stories aligned with data governance standards.](https://engineer.company/portfolio/gathered-and-analyzed-business-requirements-to-translate-into-31/)
- [Managed the execution of 30 successful GIS projects, demonstrating leadership in delivering innovative solutions across the field.](https://engineer.company/portfolio/managed-the-execution-of-30-successful-gis-projects-32/)
- [Led company growth from 4 to 14 employees by employing Agile methodologies and effective project management practices.](https://engineer.company/portfolio/led-company-growth-from-4-to-14-employees-33/)
- [Improved team communication and collaboration by implementing Slack, Mattermost, 1Password, and Jira, saving 8,000 hours of labor.](https://engineer.company/portfolio/improved-team-communication-and-collaboration-by-implementing-slack-34/)
- [Led the development, deployment, and support of over 30 GIS projects, demonstrating expertise in PostgreSQL, Bash, Python, JavaScript, GDAL, ArcGIS, PostGIS, and Mapbox technologies.](https://engineer.company/portfolio/led-the-development-deployment-and-support-of-over-35/)
- [Contributed to user interface design processes, ensuring intuitive, visually appealing, and user‑friendly project interfaces.](https://engineer.company/portfolio/contributed-to-user-interface-design-processes-ensuring-intuitive-36/)
- [Guided the execution of numerous company projects, offering expert support in the software development phases.](https://engineer.company/portfolio/guided-the-execution-of-numerous-company-projects-offering-37/)
- [Overhauled internal processes, saving 8,000 hours by improving software architecture, systems, and scheduling efficiency.](https://engineer.company/portfolio/overhauled-internal-processes-saving-8-000-hours-by-38/)
- [Administered network infrastructure for over 1,000 servers, ensuring optimal system deployment, security, and troubleshooting.](https://engineer.company/portfolio/administered-network-infrastructure-for-over-1-000-servers-39/)
- [Established a Technical Support department, servicing over 10,000 clients with IT support and troubleshooting solutions.](https://engineer.company/portfolio/established-a-technical-support-department-servicing-over-10-40/)
- [Automated SSL/TLS certificate creation for 100 Docker applications, ensuring secure connections across Ubuntu Linux hosts.](https://engineer.company/portfolio/automated-ssl-tls-certificate-creation-for-100-docker-41/)
- [Streamlined CI/CD processes, saving 4,000 hours by introducing automation in software development pipelines.](https://engineer.company/portfolio/streamlined-ci-cd-processes-saving-4-000-hours-42/)
- [Streamlined data analysis and software development processes, saving 4,000 hours by introducing GitHub, GitLab, Bash, and Python CI/CD practices.](https://engineer.company/portfolio/streamlined-data-analysis-and-software-development-processes-saving-43/)
- [Developed a Data Analytics reporting system, increasing quarterly software revenue by 400% through Python‑based PDF reports.](https://engineer.company/portfolio/developed-a-data-analytics-reporting-system-increasing-quarterly-44/)
- [Automated data processing tasks using Shell scripting, PL/pgSQL, Python, and Transact‑SQL, increasing productivity and efficiency.](https://engineer.company/portfolio/automated-data-processing-tasks-using-shell-scripting-pl-45/)
- [Enhanced project efficiency, saving 150 hours per month across 30 projects by optimizing workflows and resource management.](https://engineer.company/portfolio/enhanced-project-efficiency-saving-150-hours-per-month-46/)
- [Managed a team delivering IT support, data recovery, and hardware repair services to over 1,000 clients, ensuring high‑quality service.](https://engineer.company/portfolio/managed-a-team-delivering-it-support-data-recovery-47/)
- [Configured and deployed 1,000 Wi‑Fi routers, improving network accessibility and performance for clients.](https://engineer.company/portfolio/configured-and-deployed-1-000-wi-fi-routers-48/)
- [Managed 4,000 computer repairs, ensuring rapid and effective resolution of hardware and software issues.](https://engineer.company/portfolio/managed-4-000-computer-repairs-ensuring-rapid-and-49/)
- [Administered 100 Bare Bone servers, physical networks, and IP telephony systems, ensuring robust infrastructure for company growth.](https://engineer.company/portfolio/administered-100-bare-bone-servers-physical-networks-and-50/)
- [Developed 100 web applications using HTML/HTML5, CSS/SCSS, Django, WordPress, and Joomla frameworks, ensuring diverse online presence.](https://engineer.company/portfolio/developed-100-web-applications-using-html-html5-css-51/)
- [Designed 30 websites, delivering unique and flexible solutions by converting Photoshop designs to HTML.](https://engineer.company/portfolio/designed-30-websites-delivering-unique-and-flexible-solutions-52/)
- [Administered 40 websites on Ubuntu Linux hosting servers with Apache and Nginx, ensuring high availability and performance.](https://engineer.company/portfolio/administered-40-websites-on-ubuntu-linux-hosting-servers-53/)
- [Engineered 600 PL/pgSQL‑based ETL/ELT pipelines to streamline complex data processing workflows across multiple PostgreSQL development and production environments.](https://engineer.company/portfolio/engineered-600-pl-pgsql-based-etl-elt-pipelines-54/)
- [Architected, developed, implemented, supported infrastructure, data processing, and the map application for 2 years non‑stop without any weekends, holidays, or vacations, 10–14 hours a day.](https://engineer.company/portfolio/architected-developed-implemented-supported-infrastructure-data-processing-and-55/)
- [Optimized budget costs 10 times with zero loss in productivity for the Saudi Arabia company by reimagining the overall infrastructure, eliminating unnecessary services, and relocating from the AWS cloud.](https://engineer.company/portfolio/optimized-budget-costs-10-times-with-zero-loss-56/)
- [Architected a layered maritime platform separating a Next.js PWA frontend, a Go (Huma/Fiber) API, and a PostgreSQL function layer, keeping all business logic in the database.](https://engineer.company/portfolio/architected-a-layered-maritime-platform-separating-a-next-57/)
- [Designed a JSON passthrough architecture where PostgreSQL functions return complete JSON forwarded verbatim by the Go API, eliminating intermediate unmarshalling and decoupling the frontend from schema changes.](https://engineer.company/portfolio/designed-a-json-passthrough-architecture-where-postgresql-functions-58/)
- [Designed an organization context‑switching system with client localStorage and server‑side cookie mirroring, letting users act as managed organizations while enforcing least‑privilege authorization.](https://engineer.company/portfolio/designed-an-organization-context-switching-system-with-client-59/)
- [Migrated the HTTP API from Fiber to Huma v2 — 649 paths and 760 operations — reaching and holding 100% parity between the routes the server registers and the OpenAPI description it publishes.](https://engineer.company/portfolio/migrated-the-http-api-from-fiber-to-huma-60/)
- [Generated the API contract outward from the database — OpenAPI, a 44,076‑line typed TypeScript client, 61 mock handlers and the limits the UI enforces — with a guard at every hop that fails on drift.](https://engineer.company/portfolio/built-a-request-schema-validation-contract-with-automated-61/)
- [Built email as a platform capability — three providers with failover, delivery webhooks, send and delivery logging, templating and campaigns — behind a startup check that will not boot without one.](https://engineer.company/portfolio/built-email-as-a-platform-capability-with-failover-62/)
- [Designed a PostgreSQL function‑first data layer — 1,275 stored functions across 34 schemas — so every read and write goes through a function the database can grant, rather than through a table.](https://engineer.company/portfolio/designed-a-postgresql-function-first-data-layer-across-63/)
- [Adopted UUID v7 time‑ordered identifiers (PostgreSQL 18) as entity keys to reduce B‑tree index fragmentation and speed up queries.](https://engineer.company/portfolio/adopted-uuid-v7-time-ordered-identifiers-postgresql-18-64/)
- [Implemented a catalogue‑driven deep‑merge for stored JSON preferences, preventing missing‑key crashes as the schema evolves.](https://engineer.company/portfolio/implemented-a-catalogue-driven-deep-merge-for-stored-65/)
- [Built the Python vessel‑data scrapers (MarineTraffic, Maritime‑Database) and a repeatable import that seeds the platform's reference data — 184,197 rows, including 698 companies and 56,149 vessels.](https://engineer.company/portfolio/built-a-python-vessel-data-scraper-marinetraffic-maritime-66/)
- [Modeled the maritime domain into 348 normalized tables across 34 PostgreSQL schemas — professionals, companies, ships, jobs, reviews and the rest — with SMALLINT lookups and UUID v7 keys.](https://engineer.company/portfolio/modeled-the-maritime-domain-professionals-companies-ships-jobs-67/)
- [Provisioned Azure infrastructure as code with Bicep — Container Apps, PostgreSQL Flexible Server, Front Door/WAF and networking — across the development, staging and production environments.](https://engineer.company/portfolio/provisioned-azure-infrastructure-as-code-with-bicep-container-68/)
- [Built GitHub Actions CI/CD pipelines with a distroless production frontend image and multi‑environment promotion.](https://engineer.company/portfolio/built-github-actions-ci-cd-pipelines-with-a-69/)
- [Authored 578 go‑task automation targets spanning native, Docker and HTTPS dev modes, linting, testing, database and deployment.](https://engineer.company/portfolio/authored-578-go-task-automation-targets-70/)
- [Owned end‑to‑end deployments of the platform to Azure, managing releases across development, staging and production environments.](https://engineer.company/portfolio/owned-end-to-end-deployments-of-the-platform-71/)
- [Configured database backup retention as infrastructure‑as‑code, then audited the recovery position and documented the restore procedure — naming the remaining gaps rather than leaving them to be found during an incident.](https://engineer.company/portfolio/configured-database-backup-retention-as-infrastructure-as-code-72/)
- [Built the Next.js 16 frontend with deliberate SSR, SSG and CSR strategies, and a reusable prefetched‑server‑page factory that removes the N+1 fetch cascade from each authenticated page moved onto it.](https://engineer.company/portfolio/built-the-next-js-16-frontend-with-deliberate-73/)
- [Delivered full Progressive Web App support — installable and offline‑capable — with Workbox runtime caching via next‑pwa.](https://engineer.company/portfolio/delivered-full-progressive-web-app-support-installable-and-74/)
- [Designed an iOS 26 'Liquid Glass' design system and a canonical component inventory enforced by lint rules to prevent UI divergence.](https://engineer.company/portfolio/designed-an-ios-26-liquid-glass-design-system-75/)
- [Designed the product's UI and UX end to end — directory grids, dual card/table views, live requirement validators and breadcrumb navigation.](https://engineer.company/portfolio/designed-the-product-s-ui-and-ux-end-76/)
- [Hardened the application with nonce‑based CSP, HSTS, SameSite cookies, least‑privilege database roles and server‑side entitlement re‑checks.](https://engineer.company/portfolio/hardened-the-application-with-nonce-based-csp-hsts-77/)
- [Established an English/Danish internationalization system carrying 12,027 messages per locale across 458 namespace files, with linter‑enforced vocabulary and a 400‑line budget per file.](https://engineer.company/portfolio/established-an-english-danish-internationalization-system-with-linter-78/)
- [Set a zero‑warnings quality bar across six languages — Go, TypeScript, SQL, Python, Shell and Markdown — enforced by pre‑commit hooks.](https://engineer.company/portfolio/set-a-zero-warnings-quality-bar-across-six-79/)
- [Set the platform's founding decisions in the weeks after the repository opened in November 2025 — the layering, database‑first data access and the zero‑warnings bar — and they still hold nine months on.](https://engineer.company/portfolio/set-the-platform-s-founding-decisions-in-november-2025-80/)
- [Delivered analysis and regular progress reports to the CEO, translating engineering metrics and delivery status into decisions.](https://engineer.company/portfolio/delivered-analysis-and-regular-progress-reports-to-the-81/)
- [Provided round‑the‑clock 24/7 infrastructure support for an IPTV/OTT streaming platform, administering ~1,000 servers plus client‑owned systems for global customers in China, the US and Germany.](https://engineer.company/portfolio/provided-round-the-clock-24-7-infrastructure-support-82/)
- [Ensured uninterrupted delivery of IPTV streaming signals between suppliers and clients, monitoring and maintaining the streaming network and IP telephony around the clock.](https://engineer.company/portfolio/ensured-uninterrupted-delivery-of-iptv-streaming-signals-between-83/)
- [Developed and maintained Django web applications for the IPTV platform, shipping new features and improving performance and stability.](https://engineer.company/portfolio/developed-and-maintained-django-web-applications-for-the-84/)
- [Planned and implemented new infrastructure functionality for internal and external systems, building solutions durable enough to still run years later with minimal change.](https://engineer.company/portfolio/planned-and-implemented-new-infrastructure-functionality-for-internal-85/)
- [As one of the first hires, designed and built the entire core infrastructure and supporting processes from scratch for a green‑energy SaaS startup, laying the foundation for rapid growth.](https://engineer.company/portfolio/as-one-of-the-first-hires-designed-and-86/)
- [Maintained and enhanced the legacy Hugo static‑site website while contributing UI/UX improvements to the primary asset‑management product.](https://engineer.company/portfolio/maintained-and-enhanced-the-legacy-hugo-static-site-87/)
- [Designed a time‑management and reporting system that remained in production use for years without significant modification.](https://engineer.company/portfolio/designed-a-time-management-and-reporting-system-that-88/)
- [Automated team collaboration, password management, task and time management, and built a semi‑automatic project‑showcase system, raising team productivity.](https://engineer.company/portfolio/automated-team-collaboration-password-management-task-and-time-89/)
- [Integrated a company‑wide password‑management system, strengthening security and streamlining access control.](https://engineer.company/portfolio/integrated-a-company-wide-password-management-system-strengthening-90/)
- [Drove client web success by combining custom website development and design with SEO, content strategy and copywriting.](https://engineer.company/portfolio/drove-client-web-success-by-combining-custom-website-91/)
- [Performed data recovery across a wide range of media — SD cards, HDDs, SSDs, RAID arrays, external drives and Mac systems.](https://engineer.company/portfolio/performed-data-recovery-across-a-wide-range-of-92/)
- [Diagnosed and repaired laptop hardware — screens, hinges, keyboards, trackpads, motherboards and power — and resolved software issues across Linux, Windows and Mac.](https://engineer.company/portfolio/diagnosed-and-repaired-laptop-hardware-screens-hinges-keyboards-93/)
- [Built a layered automated test suite — 981 Go tests, 543 frontend and browser specs, 494 SQL behavioural tests — with mutation testing, property‑based tests and an accessibility gate.](https://engineer.company/portfolio/built-a-layered-automated-test-suite-across-four-layers-94/)
- [Built the repository's guard engine — 268 registered commit checks, 277 lint rules and 15 custom ESLint rules — plus 146 tests of the guards themselves, so the build holds the standard, not review.](https://engineer.company/portfolio/built-the-repository-s-guard-engine-of-268-checks-95/)
- [Built the payments and entitlements layer — Stripe alongside Apple and Google in‑app purchase — gating the directory, search and export through an 11‑table access model checked on the server.](https://engineer.company/portfolio/built-the-payments-and-entitlements-layer-96/)
- [Moved slow work off the request path onto a River job queue — 15 worker modules, 8 scheduled tasks and 20 pg_cron jobs — so a request returns while the work behind it carries on.](https://engineer.company/portfolio/moved-slow-work-onto-a-river-job-queue-97/)
- [Built first‑party error monitoring and OpenTelemetry tracing rather than buying them — payload sanitising, spike and regression detection, symbolication and a synthetic heartbeat — behind 11 operator views.](https://engineer.company/portfolio/built-first-party-error-monitoring-and-tracing-98/)
- [Kept the schema honest across 1,022 migrations with a CI gate that builds the database both ways — a fresh install, and an install plus every migration — and fails when the two disagree.](https://engineer.company/portfolio/kept-the-schema-honest-across-1022-migrations-99/)
- [Built fail‑closed abuse controls — 22 Redis‑backed rate limiters, Cloudflare Turnstile, request idempotency and an origin lock — so the platform sheds bots and floods instead of trusting its callers.](https://engineer.company/portfolio/built-fail-closed-abuse-controls-and-rate-limiting-100/)
- [Built first‑party product analytics in PostgreSQL — 47 functions over partitioned event tables that prune themselves — pseudonymised behind a rotating salt and gated on the visitor's consent.](https://engineer.company/portfolio/built-first-party-product-analytics-in-postgresql-101/)
- [Built the operator back‑office — around 40 admin routes and 128 components covering claims, moderation, feature flags, cache and diagnostics — so the platform can be run without database access.](https://engineer.company/portfolio/built-the-operator-back-office-for-the-platform-102/)
- [Built company ownership claims end to end — a user claims a company, an administrator adjudicates, and an approval rewrites the authorization graph that decides who is allowed to edit what.](https://engineer.company/portfolio/built-company-ownership-claims-end-to-end-103/)
- [Established a continuous security programme — code scanning, DAST, dependency and vulnerability checks, SBOM generation, secret scanning and SHA‑pinned actions — alongside 21 written security audits.](https://engineer.company/portfolio/established-a-continuous-security-programme-104/)
- [Built the loyalty and reputation system — 67 functions over a 31‑table ledger, with leagues, badges and a redemption shop — taking a row lock on the balance to close the double‑spend window.](https://engineer.company/portfolio/built-the-loyalty-and-reputation-system-105/)
- [Built the platform's social layer — posts, feed, groups, mentions, a follower graph and an occasions digest — on the same function‑first data layer as the rest of the product.](https://engineer.company/portfolio/built-the-platform-s-social-layer-106/)
- [Built the hiring marketplace and the seafarer career workspace — 151 stored functions across 48 tables — covering vacancies, applications, certificates, rank progression and verified sea time.](https://engineer.company/portfolio/built-the-hiring-marketplace-and-career-workspace-107/)
- [Built the company's own infrastructure as 19 Ansible playbooks and 34 roles across 12,065 lines of YAML, converging a live host to a declared state with every play idempotent.](https://engineer.company/portfolio/built-the-companys-infrastructure-as-code-108/)
- [Ran the whole company on one 512 MB single‑core host — a git forge, a web server serving seven domains, Tor, two alternate‑protocol servers, backups and intrusion banning — by treating 464 MB of usable memory as the binding architectural constraint.](https://engineer.company/portfolio/ran-the-whole-company-on-one-512mb-host-109/)
- [Found and closed three SSH brute‑force protections that had never worked: a ban jail watching port 22 while the daemon listened on 1986, a rate limit shadowed by a broader rule above it, and a ban action whose binary never resolved, so no ban had ever applied.](https://engineer.company/portfolio/found-three-ssh-brute-force-protections-that-never-worked-110/)
- [Hardened SSH to 24 asserted directives with three‑stage validation — the candidate file, the assembled config, then the daemon's own read‑back — after the read‑back caught the running server silently overriding two of the twenty‑four.](https://engineer.company/portfolio/hardened-ssh-with-three-stage-validation-111/)
- [Proved the intrusion‑banning path end to end on every hardening run by banning a reserved test address, reading the resulting kernel rule and unbanning in a guaranteed cleanup block, so a jail that stops working fails a run instead of reporting healthy.](https://engineer.company/portfolio/proved-the-intrusion-banning-path-on-every-converge-112/)
- [Verified firewall rules by position rather than presence, reading the numbered rule list and the live packet‑filter chain, because a rule that exists is not a rule any packet reaches.](https://engineer.company/portfolio/verified-firewall-rules-by-position-113/)
- [Built encrypted off‑host backups on restic with retention pruning, an integrity check and a monthly automated restore drill, then audited the recovery position and wrote down the gaps rather than leaving them to be found during an incident.](https://engineer.company/portfolio/built-encrypted-backups-with-a-monthly-restore-drill-114/)
- [Built dead‑man's‑switch monitoring that pings only while memory and disk are healthy, so a degraded host raises an alert by going silent — and caught six variable names saying "free" where the check correctly measured "available", an order of magnitude apart on a 464 MB box.](https://engineer.company/portfolio/built-dead-mans-switch-monitoring-115/)
- [Made check mode tell the truth across the whole platform after finding six probes deciding on a value the host never gave, because Ansible's command module reports success under --check while skipping the command entirely.](https://engineer.company/portfolio/made-ansible-check-mode-tell-the-truth-116/)
- [Added a preflight play that runs the same code as the converge against operator‑local secrets in about a second, after a half‑applied production run died on its ninth task with the swap settings already written to the live host.](https://engineer.company/portfolio/added-a-preflight-play-for-secrets-117/)
- [Reconciled a 20‑record DNS zone declaratively against the Cloudflare API with separate audit and BIND‑export entry points, and turned the CDN proxy back off on privacy grounds after building it.](https://engineer.company/portfolio/reconciled-a-dns-zone-declaratively-118/)
- [Cut systemd sandbox exposure across every unit this platform installs — a dead‑man's‑switch service from 9.6 UNSAFE to 1.5, an internet‑facing git forge from 8.3 EXPOSED to 1.5 — and added a converge‑time parser check after finding a misspelled directive silently ignored in three unit templates.](https://engineer.company/portfolio/cut-systemd-sandbox-exposure-across-every-unit-119/)
- [Built seven read‑only reporting roles that render a live host to Markdown — facts, access, git, metrics, traffic, security and provider inventory — under a rule that no number is printed the run did not measure.](https://engineer.company/portfolio/built-seven-read-only-host-reporting-roles-120/)
- [Deployed the company's own git forge on Soft Serve, private by default with no web panel and its SSH port bound to loopback behind a jump host, and made the landing page in front of it a build artefact of the main site rather than a hand‑kept copy.](https://engineer.company/portfolio/deployed-the-companys-own-git-forge-121/)
- [Deployed a container plane on Podman and Quadlet under systemd rather than Docker, because Docker publishes container ports above the host firewall's own rules — and gave deploys an unprivileged user with one fixed command instead of root.](https://engineer.company/portfolio/deployed-a-container-plane-on-podman-and-quadlet-122/)
- [Automated the provisioning of a second server on a second cloud provider, creating the firewall before the machine so it is born behind one, with both providers' firewalls written directly against their REST APIs to avoid a third‑party collection.](https://engineer.company/portfolio/provisioned-a-second-server-from-code-123/)
- [Wrote a scope rule into the repository after a restructure carried another company's inventory, firewall allowances and prose into it — and kept the quarantined residue under the secret scanner rather than excluding it.](https://engineer.company/portfolio/wrote-a-scope-rule-after-a-credential-leak-124/)
- [Split the four per‑host operational secrets after establishing that two hosts sharing one dead‑man's switch alert less than two switches, not more, and that a shared backup passphrase makes two hosts one repository.](https://engineer.company/portfolio/split-every-operational-secret-per-host-125/)
- [Built a multilingual static site in Hugo across 108 template files including 53 partials, publishing every page in four representations from one content tree in three languages, and again under seven focused subdomains built from that same tree.](https://engineer.company/portfolio/built-a-multilingual-static-site-in-hugo-126/)
- [Built a commit gate of 22 one‑line linters plus five that earn a paragraph, with no warning tier and no inline suppressions permitted, covering HTML, CSS, JavaScript, Python, YAML, Markdown, shell, links, spelling, secrets and typography.](https://engineer.company/portfolio/built-a-22-linter-commit-gate-127/)
- [Cut the site's browser‑driven quality gate from 1,636 seconds to 615 by scheduling its checks longest‑first through a worker pool bounded to four lanes, after measuring that alphabetical order cost 320 seconds against 224.](https://engineer.company/portfolio/cut-the-visual-quality-gate-to-ten-minutes-128/)
- [Replaced 27 rendered font sizes whose nearest neighbours were 0.6% apart with a six‑step Major Third scale, and wrote the linter that fails the twenty‑eighth.](https://engineer.company/portfolio/replaced-27-font-sizes-with-a-six-step-scale-129/)
- [Took WCAG 2.2 Level AA across 32 representative pages — one per template per language — in both colour themes, plus two AAA criteria, with a documented conformance record and a check defending each claim.](https://engineer.company/portfolio/took-wcag-2-2-level-aa-across-the-whole-site-130/)
- [Found and fixed 11 accessibility defects the browser reported as healthy — eight footer links still in tab order behind pointer‑events, a scroll timeline clipping the colophon off three pages, and a rule engine running 70 of its 105 rules.](https://engineer.company/portfolio/fixed-11-accessibility-defects-the-browser-called-healthy-131/)
- [Generated 495 achievement pages across three languages from a read‑only SQLite export, with the page address authored as data so that correcting a sentence no longer moved the page and broke the link.](https://engineer.company/portfolio/generated-321-achievement-pages-from-a-sqlite-export-132/)
- [Closed the colour system at 28 documented colours with a linter that fails a value painted but undocumented, documented but unpainted, mis‑measured, respelled as a literal, or within a perceptual distance of 0.02 of one already there.](https://engineer.company/portfolio/closed-the-colour-system-at-28-colours-133/)
- [Found that the light theme had been missing a full‑page overlay layer since the day it was written, by asserting that both themes paint every layered surface with the same number of layers.](https://engineer.company/portfolio/found-the-light-theme-missing-an-overlay-layer-134/)
- [Made reduced‑motion honest after finding eleven selectors still animating under the preference, because a universal transition‑none rule loses on specificity to any rule carrying a class.](https://engineer.company/portfolio/made-reduced-motion-honest-135/)
- [Built a 637‑line print stylesheet against four documented rendering‑engine behaviours, including run‑in headings that printed white on white for any reader whose browser preferred dark.](https://engineer.company/portfolio/built-a-637-line-print-stylesheet-136/)
- [Mirrored the entire site as 777 Gemini documents and 777 Gopher documents off the same deployed tree, at zero bytes of change to the HTML.](https://engineer.company/portfolio/mirrored-the-site-to-gemini-and-gopher-137/)
- [Replaced 963 anonymous structured‑data blocks that restated the company 1,671 times with one linked graph of 16 types minted from stable origin identifiers.](https://engineer.company/portfolio/replaced-963-structured-data-blocks-with-one-graph-138/)
- [Cut the stylesheet bundle from 87 KB to 31 KB by taking a base64 font out of it, and dropped 756 KB across 22 files that were published on every deploy and referenced by nothing.](https://engineer.company/portfolio/cut-the-stylesheet-bundle-from-87kb-to-31kb-139/)
- [Fixed a sitemap where 172 of 176 URLs shared one modification timestamp, by taking the date from git history after establishing that the export rewrites every file on every run.](https://engineer.company/portfolio/fixed-a-sitemap-with-one-shared-timestamp-140/)
- [Ran the site's development as 51 written initiatives across 54 plan documents, each carrying its open boxes, its measurements and the decisions it declined — including six of eight agent‑readiness findings refused with the reason recorded.](https://engineer.company/portfolio/ran-development-as-49-written-initiatives-141/)
- [Put the documentation under its own linter — a per‑file line budget that only ratchets down, an index requirement and a real‑path check — which found six of nine plans marked done while carrying unchecked boxes, and fourteen commit‑gating tasks named in no document.](https://engineer.company/portfolio/put-the-documentation-under-its-own-linter-142/)
- [Brought 10,242 lines of quality‑gate JavaScript under a formatter and a linter after establishing it was the largest body of code in the repository and the only one nothing read, fixing 13 findings and suppressing none.](https://engineer.company/portfolio/brought-the-quality-gate-code-under-a-linter-143/)
- [Built a database‑driven CV, references, portfolio and cover‑letter generator in Python — 41 modules, 10,580 lines — rendering six output formats from one 23‑table SQLite source assembled by a 19‑step idempotent pipeline.](https://engineer.company/portfolio/built-a-database-driven-cv-and-portfolio-generator-144/)
- [Held the generator to 981 test cases at a 92% branch‑coverage floor with warnings treated as failures, and asserted idempotence by running the whole build pipeline twice from an empty file and requiring the second pass to change nothing.](https://engineer.company/portfolio/held-the-generator-to-964-tests-and-a-coverage-floor-145/)
- [Established PDF/UA‑1 conformance across nine documents at 106 of 106 rules, and found the archival variant failing one rule of 146 — a near‑miss that reads as a pass to anyone not running the validator.](https://engineer.company/portfolio/established-pdf-ua-1-conformance-across-nine-documents-146/)
- [Selected every rule the Python linter has as an error, working through 1,815 findings to reach zero, with each of the few exemptions carrying a written reason and two of them backed by a checker instead of a comment.](https://engineer.company/portfolio/enabled-every-python-linter-rule-as-an-error-147/)
- [Vendored a QR encoder — Reed‑Solomon over GF(256), fixed module layout, eight mask patterns — in 522 lines rather than take a third runtime dependency, and verified it by reading the finished matrix back with an independently written decoder.](https://engineer.company/portfolio/vendored-a-qr-encoder-in-522-lines-148/)
- [Wrote tests for the checkers themselves after establishing that a checker fed only clean input will one day report clean because it read nothing — planting a misspelling to confirm the spell‑check finds it, and taking an id range from the database rather than from a number in the test.](https://engineer.company/portfolio/wrote-tests-for-the-checkers-themselves-149/)
- [Found the commit hooks and the quality gate running different checks while a document promised they were the same, by comparing the two lists in a test — the five that only ever ran by hand were the ones reading the CV prose.](https://engineer.company/portfolio/found-the-commit-hooks-and-the-gate-disagreeing-150/)
- [Rehearsed the forge‑side CI hook and found two defects unreachable by reading the file: a fallback that put an unresolvable argument on the hook's input, and git's own environment variable following the gate into the checkout and turning 19 tests red.](https://engineer.company/portfolio/rehearsed-the-forge-side-ci-hook-151/)
- [Moved every user‑facing string out of Python into a content tree of 874 files across three languages, after finding dead translations nobody could see were dead and a check silently grading a third of the achievements.](https://engineer.company/portfolio/moved-every-user-facing-string-into-a-content-tree-152/)
- [Built a cross‑language content check that fails when a translation drops a figure the English states, and when a language uses notation it does not use — finding two Danish descriptions missing a metric and sixteen Ukrainian spans quoting in the English style.](https://engineer.company/portfolio/built-a-cross-language-figure-and-notation-check-153/)
- [Built a native macOS messaging client in Swift 6 and SwiftUI — 11,141 lines across 53 files — over the C interface of a Rust core linked as a static archive from a pinned revision.](https://engineer.company/portfolio/built-a-native-macos-messaging-client-in-swift-6-154/)
- [Stopped an application filling memory at 41 MB a second — a recorded 111 GB of compressed pages on a 36 GB machine — by bounding every event stream, subscribing by event type and putting a rate budget on logging, taking 610,996 log lines down to 1,411.](https://engineer.company/portfolio/stopped-an-application-filling-memory-at-41mb-a-second-155/)
- [Adopted Swift 6 complete strict concurrency with no actors, bridging a blocking C event loop to the main actor through one producer, one consumer and one ordering — after establishing that a task per event loses the ordering the interface depends on.](https://engineer.company/portfolio/adopted-swift-6-strict-concurrency-over-a-c-event-loop-156/)
- [Wrote a parser that reads the real 7,308‑line C header and verifies every call site, every enum constant and that every pointer‑owning class is final, after a hand‑written placeholder header let calls to three removed functions compile, link and crash.](https://engineer.company/portfolio/wrote-a-parser-that-verifies-every-ffi-call-site-157/)
- [Took the test suite from six tests over a sixty‑second limit to 135 passing in 8.9 seconds by profiling the main thread and removing the two calls it sat inside for 3,989 samples out of 4,017.](https://engineer.company/portfolio/took-the-test-suite-under-nine-seconds-158/)
- [Named every icon‑only control in the interface for screen readers after finding the send button announced as "arrow up circle, button", and wrote the linter that requires the label within eight lines of the icon.](https://engineer.company/portfolio/named-all-seventeen-interface-icons-for-screen-readers-159/)
- [Built a 48‑token design system on the platform's own glass material and wrote the linter that rejects a magic number, a hardcoded font size, or an animation that ignores the reduce‑motion preference.](https://engineer.company/portfolio/built-a-48-token-design-system-160/)
- [Reached the half of the messaging core the application had never used — backup transfer, disappearing messages, message editing and resending, verified invitations, proxies and encryption policy — driving every test against the real library with no mocks.](https://engineer.company/portfolio/reached-the-unused-half-of-the-messaging-core-161/)
- [Rewrote the application's error messages against a written tone standard after a refused sign‑in blamed the user for mistyping when the provider actually required an app‑specific password, and covered it with a test that names the provider.](https://engineer.company/portfolio/rewrote-the-error-messages-against-a-tone-standard-162/)
- [Audited 644 Rust crates for licence compatibility on every build, and proved the check fires by rewriting one crate's licence and by moving the pinned core revision without regenerating.](https://engineer.company/portfolio/audited-644-rust-crates-for-licence-compatibility-163/)
- [Built the company's icon and favicon sets from two hand‑made drawings, with every derived asset regenerated by script and a check that fails when a derived file was committed before its source.](https://engineer.company/portfolio/built-the-visual-identity-from-two-drawings-164/)
- [Held four repositories to one history standard — conventional, emoji‑free, no attribution trailers, enforced by a commit‑message hook — alongside 46 instruction documents that govern how the work is done.](https://engineer.company/portfolio/held-five-repositories-to-one-history-standard-165/)

<https://engineer.company/portfolio/>
