A private service managed from Telegram:
invite-only, containerised, HTTPS from day one
A control plane for a private network service: a Telegram bot with a Mini App, invite-only access with admins and invited members, a containerised stack (database, migrations, control API, brain, bot) behind a shared reverse proxy with automatic certificates, no ports exposed, secrets with strict permissions. Built as our own tooling on a shared server with three other projects without touching them.
What it shows
How we run infrastructure for clients: one shared reverse proxy owning ports 80 and 443, each project in its own folder, network and compose project, no databases or internal services published, secrets in files with strict permissions, a written server rulebook and a change journal. The service itself is a private tool; the operations pattern is what we sell.