05Uses
What I use daily
The hardware on the desk, the environment the code is written in, and the services that run this site. The last group you can check yourself through this site's headers and the domain's DNS records.
Desk
One fixed workspace, chosen so that nothing needs thinking about again after it is bought.
- Machine
- Custom build · AMD Ryzen 9 9950X (16 cores / 32 threads) · 64 GB DDR5-6000
Sixteen cores were chosen not for one fast build but so a type-check, a dev server, a database container, and a browser under profiling can all be alive at once without any of them waiting on another. 64 GB is what stopped me closing windows to free memory.
- Graphics
- NVIDIA GeForce RTX 4070 Ti Super
Drives two 4K panels at once and takes over encoding while recording a demo, so capture does not eat the cores a build is using.
- Storage
- 2 TB Gen4 NVMe · 4 TB NVMe
The fast one for the system and active repositories, the large one for project archives and container images. Split so that “disk is full” never becomes a reason to postpone something.
- Displays
- 2× 27" 4K, one mounted vertically
The landscape one fits an editor and a browser side by side at a type size that does not strain; the vertical one holds logs, diffs, and long documents — three things whose natural shape is tall, not wide.
- Keyboard
- Keychron Q1 Pro · Gateron Jupiter Brown, PBT keycaps
Aluminium body and a gasket mount, so it sounds low and does not carry on a video call. The layout is programmed on the board itself, not through an app that has to keep running in the background.
- Mouse
- Logitech MX Master 3S
Its horizontal wheel gets used daily on wide tables, timelines, and diffs that run off the side of the screen.
- Audio
- Sony WH-1000XM5
The noise cancelling is what makes working in a loud room possible at all. Worn without music more often than with it.
- Microphone
- Shure MV7
Client calls are the part of the work most often ruined by something trivial. A clear microphone removes the single most wasteful sentence in any meeting: “sorry, you cut out — could you repeat that?”
- Chair
- Herman Miller Aeron
The largest expense at this desk and the only one never regretted. It is used for longer hours than the machine, and it will outlast it too.
- Desk
- Standing desk, motorised height
Not for standing all day — but so that changing position does not require a decision. A button that takes two seconds gets pressed; an adjustment that takes two minutes never does.
Second machines
What gets used when the work cannot wait until I am back at the desk — and when the main machine is the wrong place to check something.
- Laptop
- MacBook Pro 14" · M4 Pro · 24 GB
Not merely a spare. Safari and macOS cannot be tested from Windows, and both are the most frequent source of bugs that never appear on the main machine. This one catches them before a client does.
- Test devices
- An iPhone · one mid-range Android
The Android is deliberately not a flagship. Fast devices hide a heavy page until it reaches someone whose device is not fast — and in Indonesia that is most visitors. Every page I hand over has been opened on both of these first, over mobile data rather than home Wi-Fi.
- Tablet
- iPad Air · Apple Pencil
Used to reread designs and mark up revisions away from the editor. Judging a layout on a device I cannot edit from makes me read it like a user rather than its author.
Environment
- System
- Windows 11 Pro
- Shell
- PowerShell day to day, WSL2 when POSIX is needed
Two shells with a clear border: PowerShell handles anything touching Windows itself, WSL2 handles scripts that will later run on a Linux server. Running a deploy script in an environment unlike its destination is the easiest way to find a bug in the most expensive place.
- Runtime
- Node.js · npm · fnm to pin a version per project
The version is declared inside the project and switches itself the moment I enter the folder. Running a client's code on a runtime unlike their server produces bugs that only appear after release — the most expensive place to find one.
- Editor
- Cursor
A VS Code fork, so the extensions and keybindings carry over exactly — moving here demanded relearning nothing.
- Terminal
- Windows Terminal · WSL2 (Ubuntu)
One window holds a PowerShell tab and an Ubuntu tab side by side, so moving between them does not break the flow. Project files stay on the Linux side — keeping them across the filesystem boundary is the most common reason WSL feels slow, and people usually blame WSL for it.
- Typeface
- JetBrains Mono
Chosen because a zero and a capital O, and a one and a lowercase l, never get confused. Rereading an API key with one wrong character is how you lose half an hour to a mistake that never needed to happen.
Workflow
The part that does not show up in a screenshot, and the part that decides whether a project can still be picked up a year later — by me or by someone else.
- Version control
- Git · linear history, commit messages that explain the reason
Rebase rather than merge, so the history reads as a record of changes and not a log of saves. Commit messages answer why, not what — the what is already in the diff, and the why lives only in the author's head until it is written down.
- Code quality
- TypeScript strict · ESLint · Prettier, run before every commit
Not personal discipline but a hook that refuses the commit. A rule that depends on remembering gets broken on exactly the busiest day — the same day the most expensive mistakes are made.
- Testing
- Playwright for critical flows, Vitest for logic
Not chasing a coverage percentage. What gets tested is the path where breakage means lost money or lost data — sign-up, payment, and export. The rest is tested by reading it.
- Supporting services
- Docker · database versions matched to production
Each project's database and queue run in containers on exactly the versions its server uses. After that, “it works on my machine” stops being a sentence anyone can use.
- API client
- Bruno
Its request collections are plain files inside the repository rather than the contents of an account on someone's cloud. They get reviewed, they get versioned, and they outlive anyone's subscription.
- Database client
- TablePlus
Chasing a bug by looking at the actual rows is almost always faster than inferring it from logs. Connections to production databases are saved read-only.
- Secrets & credentials
- 1Password
Client credentials never sit in a plain text file, a chat history, or an .env that gets sent along. At handover, ownership is transferred rather than copied — so my access actually ends instead of merely going unused.
- Notes
- Obsidian · plain Markdown files
Each project's notes are files on disk, not rows in a service that may one day shut down. Decisions recorded when they are made are the only way to answer “why was it built like this” two years later.
Home server
Runs at home around the clock, with not a single port forwarded to the internet.
- Machine
- Custom build · Ryzen 7 5700X · 64 GB ECC · line-interactive UPS
ECC was chosen because this machine holds the only copy of some things, and memory that is quietly wrong is the kind of damage that shows up in no log at all. The UPS is not there to keep working through an outage but to shut down cleanly — a brief power cut is the most common way a ZFS pool gets corrupted.
- Hypervisor
- Proxmox VE
Every service sits in its own container or VM, with a snapshot taken before each change. Undoing a failed upgrade becomes a one-minute job instead of an all-nighter.
- Storage
- ZFS · 4× 8 TB RAIDZ1 · NVMe cache
RAIDZ1 survives one dead disk with nothing lost. More importantly, ZFS checksums catch bits that flip quietly — the kind of damage ordinary RAID diligently copies to its mirror.
- Backups
- Restic to object storage · 3-2-1 rule
RAID is not a backup. What actually saves you is not a second disk in the same box but a copy outside the house that does not vanish along with everything else when I mistype one command.
- Network
- 2.5GbE · separate VLAN for IoT devices
Cheap smart devices are the weakest part of any home network and the least often updated. They sit on their own VLAN and cannot see a single machine that matters.
- Remote access
- Tailscale (WireGuard)
No ports are forwarded from the router and this server has no public address — so there is nothing to scan. Exposing an admin panel to the internet for convenience is a mistake that only needs to happen once.
- What runs on it
- Repository mirrors, a CI runner, a staging environment, a photo archive, and internal notes
Staging running here means a client can see and approve a change before a single line touches production. The repository mirrors exist so work does not stop when a third-party service is down.
Running this site
All of it is checkable from outside — through this site's headers or the domain's DNS records.
- Hosting
- Vercel
Deploys from a push to main, static pages revalidated hourly — no server to babysit.
- Domain
- Jagoan Hosting, nameservers on Vercel
Registrar and DNS kept apart on purpose: certificates and site records follow the deploy, while owning the domain does not depend on the host.
- Inbound mail
- ImprovMX
Forwarding, not a mailbox. An address on my own domain without one more inbox to maintain.
- Outbound mail
- Resend
Used by the contact form. SPF and DMARC are in place, so what it sends does not land in spam.
- Data
- Upstash Redis
Read counter and form rate limiting. The only state this site keeps.
- Code
- GitHub
Also the source of the activity figures on the home page and /now — pulled through the API, not retyped.