←Back to Home

ENGINEERING NOTES

Engineering Notes

Long-form notes on infrastructure, architecture, and systems work.

2026-09|DevOps · CI/CD · VPS

Production Infrastructure Deployment

How I set up a reproducible production environment with Caddy, PM2, and GitHub Actions.

Production Infrastructure Deployment

Deployed the production infrastructure for the current stack across VPS and managed services. The goal was a reproducible, observable environment with minimal manual intervention.

Stack

  • VPS: Ubuntu 22.04 LTS
  • Process manager: PM2
  • Reverse proxy: Caddy
  • CI/CD: GitHub Actions
  • Secrets: .env files on server + GitHub Environments

Steps

  1. Provisioned the VPS and hardened SSH access.
  2. Configured Caddy to terminate TLS and reverse-proxy to app ports.
  3. Set up PM2 process definitions with restart policies and log rotation.
  4. Wired GitHub Actions to deploy on push to production.
  5. Added health checks and uptime monitoring.

Outcome

Zero-downtime deploys and faster rollbacks. Deployment time dropped from manual steps to under two minutes.

2026-09|Go · MongoDB · Automation

Automated MongoDB Backup System

Building a reliable backup pipeline with Go, mongodump, Drive uploads, and email alerts.

Automated MongoDB Backup System

Built an automated backup system for MongoDB with scheduled exports, Drive uploads, retention policy, and failure alerts.

Stack

  • Runtime: Go
  • Backup: mongodump
  • Storage: Google Drive
  • Scheduling: Cron
  • Alerts: Email

Design

The exporter runs as a standalone binary. It dumps the target database, compresses the archive, uploads it to Drive, and keeps a local retention window. Failures trigger an email alert.

Challenges

  • Keeping Drive uploads idempotent so reruns do not create duplicates.
  • Managing memory usage during large dumps on a small VPS.
  • Handling credential rotation without restarting the job.

Result

Reliable backups with verified restore tests and much less operational anxiety.

2026-08|TypeScript · Architecture · MongoDB

Himu Lingua Architecture

Refactoring Himu Lingua into a cleaner layered architecture with explicit boundaries.

Himu Lingua Architecture

Refactored Himu Lingua to a cleaner layered architecture with explicit boundaries between UI, app logic, and data access.

Stack

  • Language: TypeScript
  • Runtime: Node.js
  • Database: MongoDB

What Changed

  • Separated concerns into domain, application, and infrastructure layers.
  • Introduced explicit contracts between layers to reduce coupling.
  • Improved testability by removing hidden side effects from core logic.
  • Replaced ad-hoc data access with a consistent repository pattern.

Impact

Faster feature delivery, fewer regressions, and easier onboarding for contributors.

2026-08|Node.js · Security · HLS

Protected Video Infrastructure

Restricting video playback to authorized users with signed URLs, encryption, and observability.

Protected Video Infrastructure

Worked on the protected video infrastructure to restrict playback to authorized users and devices.

Stack

  • Backend: Node.js
  • Storage: Cloud object storage
  • Playback: HLS with encrypted segments
  • Auth: JWT-based device authorization

Approach

  • Signed playback URLs with short expiration windows.
  • Rotated encryption keys per release window.
  • Logged playback events for abuse detection.
  • Added device-binding checks to reduce credential sharing.

Lessons Learned

Security is only as good as the weakest link. Key rotation and observability matter more than encryption alone.