Overview
This site runs on infrastructure I provisioned and configured by hand rather than on a managed platform. It is a two server distributed deployment on Oracle Cloud, with the application and database separated onto isolated hosts that communicate over a private network. The goal was to build, and fully understand, the layer that platforms like App Service hide: virtual machines, networking, a reverse proxy, process management, and TLS.
The Problem
Managed hosting platforms make deployment easy but hide how it actually works, which leaves gaps in understanding networking, servers, and security. I wanted to build the whole stack myself so I could reason about every layer, from the virtual network up to the certificate, and run a production grade site at near zero cost.
Architecture & Key Work
- ▹Provisioned two ARM based Ubuntu virtual machines on Oracle Cloud, splitting the compute allowance into a dedicated application server and a dedicated database server
- ▹Designed the network from scratch with a Virtual Cloud Network, subnets, and CIDR ranges, placing both servers on a private subnet so the database is never exposed to the internet
- ▹Configured defense in depth firewalls across two layers, the cloud security list and host level iptables, and debugged real rule ordering and routing issues between them
- ▹Installed and configured PostgreSQL with the pgvector extension on the database server, reachable only from the application server over the private network, ready for vector search and agentic workloads
- ▹Deployed Django using the production standard stack of Nginx as a reverse proxy in front of Gunicorn, with systemd supervising the process and restarting it on failure or reboot
- ▹Served static assets efficiently through WhiteNoise and user uploads through an Nginx media path
- ▹Registered a custom domain, moved DNS to Cloudflare, and secured all traffic with auto renewing Let's Encrypt certificates issued through Certbot, including multi subdomain coverage
- ▹Administered both servers entirely over SSH with key based authentication, and kept secrets out of version control using environment files and a clean gitignore
Results & Impact
- ✓Runs this live portfolio on a self built, encrypted, production grade stack at effectively zero hosting cost
- ✓Separated application and database tiers onto isolated hosts on a private network, a real distributed systems pattern
- ✓Built the same architecture that managed platforms automate, making their behavior transparent rather than a black box
- ✓Diagnosed and resolved real production issues across networking, firewalls, DNS propagation, and configuration through systematic log analysis