Showcases
The projects I'd point you at first, each on one page: the problem, the decisions and what they cost, the proof, and when not to use it.
- How I work One person, around 150 repositories and a lot of AI agents: specs first, every claim checked, and a human who signs for every line.
- Estate architectural patterns The design rules nearly every library and tool here follows, why each one was adopted, and what each one costs.
- How it's tested Tests that have been watched failing, suites that prove themselves against backends that lie, and checks for the things a unit test can't see.
Flagships
- go-tool-base The framework the rest of the estate is extracted from: everything a Go application needs around the part that's actually yours, whether it runs for a second or a month.
- Signing and trust Release signing whose private key never leaves your key store, verification that cross-checks two places an attacker would have to break at once, and encrypted reports nobody holds the key to.
- Media in pure Go Current FFmpeg as a sandboxed WebAssembly engine and as a native driver built from the same code, run from a Go program with no CGO, nothing to install and no temp files, and every artefact signed.
- colophon Release orchestration that tags the commit which actually landed.
- chat One small interface over ten AI providers, and you only compile the ones you use.
- config Layered configuration that knows where every value came from, and writes a change back without wrecking your file.
Foundations
- AWS account foundation Two OpenTofu modules that take a fresh AWS account to somewhere safe to build: state, keyless CI sign-in, guardrails and alerts.
- Build images Small CI images, one per kind of job, built the same way twice, rescanned every night, and kept current by bots that have to cut a release when anything inside changes.
- Docs at estate scale A docs site for every project that warrants one, all built by one pipeline component, shaped the same way, written for the machines that now read them most, and checked against the code.
- errors An errors package with nothing but the standard library under it, and the handler that turns an error into something a user can act on.
- Git and forges One contract for releases, merge requests and the rest across GitHub, GitLab, Gitea and Bitbucket, and git itself in pure Go, safe to share across goroutines, in memory or on disk, with no forge's SDK in your build.
- rust-tool-base go-tool-base's sibling in Rust: the same outcomes for a command-line tool, built the way Rust wants rather than ported line by line.
- Secure artefact delivery Every model and runtime a tool downloads, mirrored, signed and checked against a signed index before a byte of it is used.
- The pipeline One CI component library for about 150 repositories, and a runner fleet that costs nothing while it's idle.
- Web front ends Svelte for every web UI in the estate, compiled into the Go binary it belongs to and typed against the same API the command line uses.
More
- Agent skills The way of working, packaged: a public marketplace of skills for AI coding agents, with a security gate on every change and versions that can't silently stall.
- controls Two layers for long-running Go programs: a controller that starts, watches and stops the services a program needs, and a supervisor for workers that come and go, with the common services registered in a single call.
- keryx The content machine behind this blog: covers, narrated reels and a post for every social network, generated, approved and sent on schedule.
- krites A local-first photo culler that judges a wedding's worth of frames on your own machine, and tells you why it judged each one the way it did.
- mcp Expose a Go tool's commands and services to AI agents over MCP, without loading every schema into the conversation before anyone types.
- messaging One message bus for Go services, with seven backends behind it and a conformance suite that won't let any of them lie about what they do.
- phpbotscout A support bot for the community Discord that answers from the docs with citations, and treats every question it can't answer as a documentation gap.
- Secrets in use A credential arrives as a source rather than a string, the order it's looked for in is decided once by the application, and whatever leaves the process is scrubbed on the way out.
- Transport stack Hardened service plumbing as one set: servers, clients, TLS, auth and middleware that share their defaults instead of each guessing at them.