THIS SITE
Static Astro build served from Cloudflare Workers static assets. No database, no server code, no admin panel, strict security headers.
astrocloudflarestaticsecurity-headers
// problem
Publish a portfolio without adding anything to the home network attack surface.
// constraints
- Zero runtime JavaScript frameworks.
- Free tier.
// approach
- Astro renders every page to HTML at build time.
- Cloudflare serves the files from the edge. The homelab is never in the request path.
- A _headers file sets CSP, HSTS, and frame protections on every response.
// outcome
A site that stays up even when the homelab is down.