BardBits › About
About
BardBits is a growing set of small web projects. Each one is meant to be genuinely useful on its own — the point is the thing itself, not a demonstration of anything.
This page is for anyone curious about how it is put together. If you came here to name a cottage, you can safely ignore all of it.
Written with Claude Code
Every line of this site — the generators, the infrastructure, the deploy pipeline, the privacy policy — was written in collaboration with Claude Code, working against a real AWS account rather than a sandbox. That is worth stating plainly because it is unusual today and will not be for long.
It was not a matter of asking for a website and accepting what appeared. The interesting parts came from disagreement: an OIDC trust policy that silently matched nothing until the real token claim was read out of CloudTrail, a deploy that pruned old files before uploading the new ones and briefly served pages whose stylesheet had already been deleted, a CloudFormation property that nests in the API and flattens in the template. Those were found by checking rather than by assuming, and the fixes are in the history.
How it runs
Static files in a private S3 bucket, served through CloudFront. No servers, no database, no backend. Every project lives under its own key prefix in one bucket behind one distribution, so adding a project costs nothing in infrastructure.
- Defined as code. The bucket, the CDN, DNS, TLS, the edge routing and the logging are all CloudFormation. Nothing was clicked into existence in a console.
-
Deployed by pushing. A merge to
mainbuilds and publishes the site. No AWS credential is stored anywhere: GitHub proves its identity per run through OIDC federation and receives keys that expire within the hour. The account holds no access keys at all. - Prerendered. Pages arrive as real HTML with the content already in them, then hydrate. Search engines and people with JavaScript disabled see the same thing.
- One function at the edge handles the canonical hostname, redirects from URLs the site used to use, and directory indexes — because a CloudFront behaviour permits exactly one.
What it deliberately does not do
There is no analytics, no advertising network, no third-party script of any kind, and no cookie set by this site. A Content-Security-Policy enforces that in the browser rather than leaving it to good intentions.
Server logs record which pages are requested and what fails, and the visitor's IP address is deliberately not among the fields collected. That cost something — it makes some questions unanswerable — and it was still the right trade for a site that has no need to know who anyone is. The privacy policy describes exactly what is kept and for how long, and every claim in it was checked against the running site rather than asserted.
The source
All of it is public at github.com/BardBits/BardBits, including the parts that are unflattering. The commit messages explain why things are the way they are, which is usually the part that goes missing.