OpenAPI on Cloudflare Workers, backed by KV and Durable Objects
A contract-first API I designed for videos, channels, organizations, creators, vendors and ecommerce, one service on Cloudflare Workers. Every route extends a single PlatformOpenApiRoute base class; Zod schemas come from the same Prisma types the database uses, so the OpenAPI spec it produces is generated, not hand-maintained. That spec feeds a typed client the admin app, storefront and player all consume instead of three hand-written SDKs. Role and permission checks are resolved centrally and cached in KV, invalidated on every role change, so a hot path doesn't re-derive access on every request. Organization, creator, vendor and superadmin all hit the same endpoints through one actor/scope layer, including an "acting on behalf of" mode, instead of each handler hand-rolling its own tenant check. Heavier stateful work (checkout sessions, notification fan-out) is delegated over service bindings to Durable Objects sitting behind it.
Cloudflare Workers · Hono · OpenAPI 3.1 · KV · Durable Objects · Prisma/Kysely
Checkout that survives a hibernating socket
A cart had to stay in sync across a video player's iframe and the host page's cart dropdown, through reconnects, not just while the tab stayed open. Built as a Durable Object WebSocket hub on the Hibernation API: sessions rebuild from getWebSockets() on cold start, updates debounce before they fan out, and the object self-destructs on a schedule tied to how many people are still connected.
Durable Objects · WebSocket Hibernation
Provisioning a tenant without a runbook
A new tenant needs a fully configured Supabase project (schema, RLS policies, triggers, auth hooks) without anyone running commands by hand. Built as a 9-step Cloudflare Workflow: create the project, poll for health with linear backoff, run the migration SQL, wire the auth hooks, store the generated secrets in KV.
Cloudflare Workflows · Supabase provisioning
One decode, four renditions, no upscaling
A self-hosted GPU pipeline replaced Cloudflare Stream for a high-traffic customer. Each server pulls jobs from Google Pub/Sub when it has capacity, so adding a machine adds capacity. On each one, three BullMQ stages (download, transcode, distribute) feed a single decode into per-rendition NVENC encodes in one FFmpeg filter graph, with a CPU fallback and a portrait-aware, fps-derived quality ladder. 10,000+ videos processed. Output is served from S3-compatible storage (Cloudflare R2 and Backblaze B2) instead of Stream. Together with the self-hosted transcoding, that cut video hosting cost by over 75%.
FFmpeg / NVENC · BullMQ · Google Pub/Sub · R2 · Backblaze B2
Splitting one payment four ways, in the background
A marketplace order has to pay out the platform, the vendor, the creator and the organization, each on its own fee tier. Built as a Cloudflare Queues consumer sitting between the order and the Stripe transfer: it retries on missing data instead of failing the order, and groups each split with transfer_group and source_transaction so Stripe's own ledger reconciles back to the order, not just to the account.
Stripe Connect · Queue-driven transfers
Migrating a query layer one endpoint at a time
Moved an API's query layer from Prisma to Kysely one endpoint at a time, writing a custom Kysely plugin that rewrites boolean columns to MySQL tinyint at the AST level, so the two ORMs could disagree about types without anyone noticing.
Prisma → Kysely · Custom AST plugin
Making a view count mean something
View counts are easy to inflate. Built a watch-time plugin that only counts a view after 2.5 seconds of sustained playback inside 5-second segments, adjusted for playback rate and deduped with a running set so a seek-back can't double-count. A separate Deno KV service caps it at two counted views per device fingerprint per day, checked with retries before the number reaches a dashboard.
Video.js plugin · Deno KV fingerprinting
Moving 83 TB between clouds, signed by hand
A Cloudflare Worker moved an 83 TB video library from Amazon S3 to Backblaze B2 in about 7 to 8 days, averaging roughly 1 Gbit/s. Every request is signed by hand (AWS SigV4 with Web Crypto, no AWS SDK). A Durable Object drives resumable multipart copies through storage.setAlarm(), so it survives a Worker's CPU and wall-clock limits one chunk at a time. Queues and a cron trigger retry failures, with D1 as the job registry behind a live dashboard.
AWS SigV4 (Web Crypto) · Queues · D1 · Durable Object alarms
Turning one API write into pre-rendered JSON
Every storefront page view used to mean a live API call. For content that's mostly static and read far more than it's written, that's the wrong trade. A coordinator Durable Object dedupes incoming writes and dispatches a small fleet of generator Durable Objects (one per entity, channel and homepage) that pre-render each write to a static JSON file. Pages read that file instead of hitting the API, and each write purges only the specific cache URLs it affected, not the whole cache.
Durable Objects (7-class fan-out) · Targeted cache purge
Taking over a live video platform
Inherited a video platform with about 300,000 unique views a day and ran it alone. Moved its MongoDB from a self-hosted VPS to Atlas and upgraded it from 6 to 8. Re-hosted the API, web app and admin on 4+ servers in different regions: Cloudflare Load Balancing with geo-steering in front, an Nginx reverse proxy on each server spreading traffic across 15+ PM2 instances, deploys through GitHub Actions.
MongoDB Atlas · Cloudflare Load Balancing · Nginx · PM2 · GitHub Actions
Retiring .html URLs across a live Magento catalog
A Magento 2 storefront's catalog URLs still carried a legacy .html suffix from years of accumulated rewrites. Built a custom module with console commands that walked the URL-rewrite table, stripped the dead .html history and re-pointed non-.html catalog URLs, plus a Hyvä (Tailwind) theme layer with its own slider view models, widgets and setup scripts on top.
Magento 2 · Hyvä / Tailwind · Custom console commands
A subscription picker Magento's UI framework wasn't built for
Magento's product page has no native concept of "subscribe and save" pricing. Built a Knockout.js component, with observables wired straight into Magento's own price-utils, that recalculates the displayed price live as a shopper switches between one-time and subscription options. Plus a service-worker route served through Magento's own router and layout XML instead of a static file.
Magento 2 · Knockout.js / RequireJS · Custom router
An admin that polls its own transcoder
A Vue 3 and Pinia admin for a video platform needed to show, live, where an upload actually was in a multi-stage GPU pipeline, not just "processing." Built polling into the admin every 10 seconds against transcoder status, chunked uploads via flow.js, a moderation queue for comments, and a Supabase auth wrapper handling password resets without hand-rolling session logic.
Vue 3 · Pinia · Supabase · flow.js chunked uploads