personal · own platform · 2026-08 to 2026-09

Multi-venture platform: one login, per-app entitlements, every tool its own service

A Next.js shell owns identity, per-app entitlements and access codes. Caddy forward_auth gates each tool, and each tool runs as its own process or container, in any language. I cut it over from serverless to one hardened VPS on 2026-08-20.

problemconstraintswhat I builtoutcomestackredacted screenshot

Problem

Every tool I shipped needed auth, access control and hosting. The aim was one gated front door that makes the next tool cheap to add, for 10-20 invited users and with no public signup.

Constraints

What I built

fig 1. The forward_auth seam. A tool only has to trust one header set.

Outcome

dateresult
2026-08-18Initial commit. First in-shell tool and the trading tool live
2026-08-19A tool served 502s to every logged-in user for 12 hours. Full audit; the architecture doc was rewritten because the documented setup had never run; live config committed; nightly backups added and a restore verified
2026-08-20Cutover: one shell on the VPS behind Caddy, the serverless host retired, Postgres closed to the internet on three layers, the ufw/Docker gap closed
2026-09-12Landing page recovered from files that existed in no repo, committed as a baseline, reworked and deployed. The trading WebSocket 502 open since 2026-08-19 was fixed in the v0.3.0 working tree

26 commits, 23 of them 2026-08-18 to 2026-08-20 · adding a tool took ~11 steps, 10 with no tooling; one flag-driven install-venture script replaced two per-tool scripts (v0.3.0)

Stack

Next.js 16React 19TypeScriptPostgreSQL 16Drizzle ORMCaddy 2Dockersystemd

Redacted screenshot

fig 2. Mock admin with placeholder users and a dummy code. Emails, ports and brand prefix are redacted.
evidence: brain/projects/aimr-platform.md · brain/projects/platform-lite.md · brain/_meta/night-run-2026-09-23-recruiter-view.md · brain/cv.md