hetwiel

The Apprentice

Who is the apprentice here?

Every work on this site is built by a machine. This ledger keeps the other half of the experiment: what the maker actually understands of it. Each material starts as seen. It only moves up when he explains it back without looking, then makes something with it by hand, and finally teaches it to someone new.

Ledger opened5 October 2026
Materials in the works38
Seen38
Understood1
By hand0
Taught0

The levels

SeenThe machine used it; the maker has looked at it.
UnderstoodExplained back in his own words, without looking, and the questions answered.
By handA real change made with it by the maker himself. The machine may point, not type.
TaughtExplained from scratch to someone new, follow-up questions included.

hetwiel.dev

1 / 14 understood · On view

No.MaterialWhat it isLevel
1.1A rented server (VPS)A slice of a computer in a data centre, rented by the month, that the maker runs himself.Seen
1.2SSH keysLogging in with a key pair instead of a password; the private half never leaves its owner.Seen
1.3FirewallOnly three doors open on the server; everything else is closed.Seen
1.4DNSTurning the name hetwiel.dev, and every subdomain, into the address of the server.Understood
1.5Reverse proxyOne front door that sends each visitor to the right site or experiment.Seen
1.6HTTPS certificatesThe padlock. Requested and renewed automatically, without anyone touching them.Seen
1.7ContainersEvery program in its own sealed box, described in one file and started with one command.Seen
1.8VolumesWhere data lives so it survives a container being thrown away and rebuilt.Seen
1.9Version controlEvery change is a commit; any earlier version can be brought back.Seen
1.10The pipelineA push to GitHub builds the site and puts it on the server, with nobody logging in by hand.Seen
1.11Keeping secrets out of the codeKeys and passwords live in GitHub Secrets and on the server, never in the repository.Seen
1.12Static site generatorTexts in plain files, layout in templates; a build step turns them into plain HTML.Seen
1.13Security headersRules sent with every page that tell the browser what it may load and run.Seen
1.14CachingTelling browsers what they may keep and what to always fetch fresh.Seen

My Boulders

0 / 12 understood · On view

No.MaterialWhat it isLevel
2.1A GraphQL APIAsking someone else's server for exactly the fields you need, in one request.Seen
2.2Access and refresh tokensStaying signed in without a password, by trading an old token for a new one every day.Seen
2.3A scheduled jobA script that runs every morning on GitHub's machines, with nobody pressing a button.Seen
2.4Memory between runsCarrying the newest token from one run to the next in a private cache.Seen
2.5Incremental syncOnly fetching what can still have changed; the rest is reused from last time.Seen
2.6Data as filesNo database. One JSON file per climber, committed to Git like any other change.Seen
2.7JavaScript modulesCode split over files that import each other; libraries loaded straight from a CDN.Seen
2.8Charts from dataDescribing a chart as marks and scales, and letting a library draw it.Seen
2.9Shaping dataGrouping raw climbing logs into sessions, boulders and grades before anything is drawn.Seen
2.10State in the addressOne page that shows a different climber or year depending on what's after the question mark.Seen
2.11Sharing an imageTurning a part of the page into a picture and handing it to the phone's share menu.Seen
2.12Public data, on purposeA public repository means public data; friends only appear after they say yes.Seen

Photodiary

0 / 12 understood · On view

No.MaterialWhat it isLevel
3.1An upload endpointA small web server of its own that the phone can send a photo to.Seen
3.2A secret tokenOnly requests carrying the right token get in, and guessing is made slow on purpose.Seen
3.3Sharing from the phoneA shortcut in the phone's share menu that sends a photo straight to the server.Seen
3.4A queue on diskPhotos wait in a folder for at least a day, oldest first, and can be taken back.Seen
3.5Two things at onceOne part of the program listens for uploads while another waits for midnight; a lock keeps them apart.Seen
3.6Clocks and time zonesThe round runs at ten past midnight in Amsterdam, wherever the server happens to be.Seen
3.7Face detectionA small trained model looks for faces, twice, and a photo with a face is refused.Seen
3.8Developing a photo in codeCropping, black and white, curves, vignette and grain, as arithmetic on a grid of numbers.Seen
3.9Photo metadataWhat a photo knows about itself (place, camera, time), and throwing almost all of it away.Seen
3.10Other people's APIsAsking Discogs for the record collection and iTunes for a snippet to listen to.Seen
3.11Building a containerA recipe that turns the code into a box that runs as its own, unprivileged user.Seen
3.12Moving data safelyA one-time conversion when the project was renamed, without losing a single photo.Seen