Thareq Yusuf

Colophon

This site is static HTML built by Hugo, served by nginx on one small VPS, with Cloudflare in front as the cache. There is no framework, no tracker and no cookie. The only third-party request is the GitHub Discussions widget at the bottom of posts, and it doesn’t load until you scroll to it.

Serving path

reader ── Cloudflare edge (cache, TLS, HTTP/3) ── nginx origin (TLS, mTLS from edge only)
  • Origin: one DigitalOcean droplet in Singapore (SGP1) running nginx. Port 443 accepts only Cloudflare’s IP ranges and requires Cloudflare’s client certificate (authenticated origin pulls).
  • Deploys: a push to main builds the site in GitHub Actions, rsyncs it into a new release directory, swaps a symlink atomically, and purges the edge cache.
  • Fonts: Archivo for text and Fragment Mono for code and measurements. Both are self-hosted and licensed under the SIL Open Font License.

Cache policy

PathBrowserEdgeWhy
HTML pages60 s7 daysDeploys purge the edge, so a long edge TTL is safe
Fingerprinted CSS/JS1 year, immutable1 yearThe file name changes when the content does
Fonts (-v1.woff2)1 year, immutable1 yearVersioned by file name
RSS feeds15 min1 hourReaders poll; keep it cheap
/__probeneverneverIt’s a measurement

The probe

The panel at the bottom of each page measures the request that delivered it. The numbers at the bottom of every page explains each field and its caveats. In short:

FieldSourceUnit
Served fromcolo= in /cdn-cgi/traceedge code
Your round trip to the edgecfL4 in Server-Timing (TCP or QUIC RTT) if present, otherwise the fastest of 5 HTTP requests to the edgems
Edge to originnginx $tcpinfo_rtt from /__probems
Time to first byteNavigation Timing, responseStart − requestStartms
ProtocolnextHopProtocol, plus tls= from the trace—
Edge cachecf-cache-status and age from a HEAD request for this URL—