Skip to content
← Back home

build log

Learning in public

I am rebuilding one system to develop my full-stack skills. These notes explain the choices I made, what went wrong, and what each fix taught me. I use AI coding tools, but I define the requirements, review the changes, and decide what ships. These are progress reports from a learning project, not a claim that I already know every answer.

  1. Part 1 · 27 Aug 2026

    Why I rebuilt a dashboard that already worked

    A school already had a working operations system, so replacing it made no business sense. I rebuilt a limited, synthetic version instead to practise the parts of full-stack development I still wanted to learn.

    Architecture · NestJS · Postgres · Planning

  2. Part 2 · 29 Aug 2026

    Two bugs deep: a Google sign-in that refused to work

    The automated checks were green, but Google sign-in still failed. Tracing two separate bugs through the browser, server, and database became my most useful debugging lesson from the milestone.

    OAuth · Better Auth · Docker · Debugging

  3. Part 3 · 31 Aug 2026

    Three green checks that tested nothing

    Three deployment checks passed even though none of them exercised the failing database connection. The experience changed how I judge what a green check actually proves.

    Testing · Deployment · Postgres · AI agents

  4. Part 4 · 4 Sept 2026

    Seven bugs that lived between the tasks

    Each task passed its own review, but a final review still found seven problems where separate pieces met. It taught me why testing individual parts is not enough.

    Testing · Postgres · OpenAPI · AI agents

  5. Part 5 · 5 Sept 2026

    The only red run was the first one

    Twenty-three automated runs produced only one failure, even while sign-in and pay calculations were still wrong. The lesson was simple: a green check proves only what it was designed to test.

    CI · GitHub Actions · pnpm · Testing

  6. Part 6 · 7 Sept 2026

    The database says no

    A teacher must never be able to read another teacher's pay. I added a second layer of protection in Postgres, then tested the database's refusals directly instead of relying only on application code.

    Postgres · Row-level security · Authorisation · AI agents

  7. Part 7 · 8 Sept 2026

    Four bugs, four instruments

    Unit tests and code reviews passed, but four defects still appeared in the browser, clean build, container build, and deployment. Each failure showed me a different gap in the checks.

    React · Playwright · Docker · AI agents

  8. Part 8 · 14 Sept 2026

    The backup that would have eaten itself

    I added image-based deployments, secret rotation, encrypted backups, a restore drill, error tracking, and an operations guide. The most serious mistake was not in the code but in a restore instruction I had written myself.

    Backups · Postgres · Sentry · Docker · AI agents

  9. Part 9 · 16 Sept 2026

    Fourteen hours behind a green health check

    A database migration accidentally replaced the deployed app's password with a local one. Sign-in failed for fourteen hours while the health check stayed green, exposing a serious gap in my deployment checks.

    Postgres · Authorisation · Playwright · AI agents · Incidents

  10. Part 10 · 30 Sept 2026

    No problems this month

    The last milestone before version one closed was a page that lists every row that will bill wrong. The database refused two of the eight checks I designed, because it already made those rows impossible. The final review found the page could say 'No problems' for a month the app refuses to close. Then fifteen nights of backups, and version one.

    Postgres · Testing · React · AI agents · Backups