SYSTEMS
What everything actually runs on — 1 machine in a house, and 5 managed platforms doing the parts that are not worth owning.
Conceptual by construction. The content schema runs every string on this page past a check that refuses IP addresses, internal hostnames, ports, remote-access URLs and anything shaped like a credential — so the architecture is publishable and the attack surface is not. That is a build failure rather than a review comment, because review is a person remembering and this failure mode is quiet.
INVENTORY · 6
- RUNNING
Apple platforms
PLATFORM · Managed and on-device
Where the native side of the lab runs: on-device inference, sync without a server, and distribution that does not need one either.
- CloudKitSync for Collect with no backend to operate, which is the reason it has survived without maintenance.RUNNING
- On-device modelsInference inside Aeroslip that never leaves the phone, so there is no per-request cost and no network path to fail.BUILDING
- The trade is real: no server to run, and no way to change behaviour without shipping a build through review.
- RUNNING
GitHub
PLATFORM · Managed
Source of truth for every repository in the lab, and the scheduler for the jobs that keep generated content fresh.
- RepositoriesThe lab's roster, published and held back alike, asserted by a test so the count cannot quietly drift.RUNNING
- ActionsCI on every push, the contribution-calendar refresh, and the post-deploy production check.RUNNING
- Action logs on the public repository are public. Nothing that identifies an account or carries a token is printed into them.
- RUNNING
Notion + Super.so
PLATFORM · Managed
The publishing platform behind the writing sites: Notion is the editor and the database, Super renders it as a real site, and a CDN carries the shared brand layer across both.
- NotionWhere the writing actually happens, so publishing is not a separate act from drafting.RUNNING
- Super.soRenders the Notion tree as a site with custom CSS, which is the whole reason this stack survives contact with taste.RUNNING
- CDN-hosted brand layerOne stylesheet served to both sites, so a brand change is a single file rather than two copy-pastes.RUNNING
- The trade is honest: almost no engineering, and a hard ceiling on what the pages can do. For writing, the ceiling has not been hit.
- RUNNING
Proxmox Cluster
COMPUTE · The house
The hypervisor everything self-hosted runs on. One machine in the house that makes a new environment free at the margin, which is what decides whether an idea gets tried at all.
- ContainersThe long-lived services. Cheap enough that leaving one running is not a decision.RUNNING
- Virtual machinesAnything that needs its own kernel rather than a shared one.RUNNING
- ZFSSnapshots underneath everything, which turns a bad upgrade into a two-minute problem.RUNNING
- Scheduled backupsRestored from rather than merely configured. The distinction is the whole point.RUNNING
- Media librarySelf-hosted music and video. The tagging pipeline is the part that keeps going stale.RUNNING
- Conceptual only. Addresses, ports and hostnames are refused by the content schema rather than left to a reviewer to notice.
- It is the least glamorous system here and the one the most other things depend on.
- RUNNING
Supabase
SERVICE · Managed
Postgres, auth and realtime for Stagger — the one project here with live multi-user state to keep consistent.
- PostgresNine tables, row-level security on all of them, and the drinks ledger's one real rule enforced as a check constraint rather than a promise in application code.RUNNING
- RealtimeStandings recompute from raw rows and push to every phone over a websocket, so nothing polls.RUNNING
- Realtime rejects the newer publishable key and fails silently; the live leaderboard needs the legacy anon JWT. That cost an evening and is written down here so it costs nobody else one.
- RUNNING
Vercel
PLATFORM · Managed edge
Production for zckr.dev. A push to the default branch is the deploy; there is no other release step and no runtime to babysit.
- Static hostingEvery page on the site is generated at build time and served as a file.RUNNING
- Serverless functionsThe only routes that run: the REST API, the MCP server, A2A, SOAP, and the markdown mirrors.RUNNING
DEPENDS ON github · THE PROJECT →
- The build is the gate. A content file that fails its schema fails the deploy, which is the intended behaviour rather than an inconvenience.
6 systems · 16 services · what runs on what →