Every pillar, one tag. The range, not a skills list.
A catalogue of the guards I actually ship: typed confirmations, blast-radius escalation, pay-to-play gating, ordered workflows, and read-only by default.
Why I run everything as Dockerized TypeScript in one repo, and how that lets a single person ship more surface area than a small team.
Dokku swaps to a new container before it is actually ready, so requests hit a half-booted app. A CHECKS file makes Dokku wait for a real healthcheck to pass.
The thing you want an agent to drive only has a CLI. execFile it, hand back stdout, and put bounds on the call so it cannot eat your process.
You cannot POST a plaintext Actions secret. You fetch the repo public key, seal the value with libsodium, then PUT the ciphertext.
An MCP server that drives a Dokku PaaS over SSH.
An MCP server for Google Search Console properties, sitemaps, and analytics.
An MCP server for Netlify sites, deploys, and build debugging.
An MCP server for MongoDB backups, restores, and read queries.
An MCP server for S3 buckets, objects, and static website hosting.
An MCP server for GoDaddy domains and DNS records.
An MCP server for Cloudflare DNS, zones and records.
An MCP server for GitHub Issues, Actions, Environments, and repo secrets.
whisper_schedule