Agentic SDLC Harness & Self-Hosted Infrastructure
Harness engineering — built the infrastructure that builds software: an orchestrated SDLC pipeline and dual-access Mac Mini self-hosting setup.
Overview
Most AI engineering demonstrations stop at "I prompted a model." This project is about the layer underneath: the harness that turns a spec file into a reviewed, committed, production-merged feature — reliably, repeatably, and with a human in the loop at each gate. The SDLC pipeline is a set of structured Claude Code slash commands that drive spec work through a defined sequence: plan → breakdown → implement → test → review → document → wrap-up. Each phase runs in an isolated git worktree, writes a predictably-named report, and gates the next phase on passing validation. Parallel tasks run in separate worktrees and merge in dependency order. The pipeline has been running against real production specs — it is not a demo. The self-hosting layer pairs with the pipeline: a Mac Mini acts as a two-face server. Cloudflare Tunnel exposes the Next.js portfolio publicly at learn-agentic-ai.com without opening a port on the home network. Tailscale provides a private overlay network for local development, internal tooling, and admin access. The site runs on Node.js 22 behind the tunnel; builds are triggered manually and the process restarted in-place — no Kubernetes, no cloud spend, no operational complexity beyond what is needed. The design intent is simplicity at each layer: 18 composable commands rather than a monolithic orchestrator, git worktrees rather than a custom job queue, Cloudflare Tunnel rather than a load balancer. Harness engineering is about making the routine reliable so that the interesting work — the actual AI engineering — can move fast.
Technical Stack
Orchestration
- ▸Claude Code
- ▸Bash
- ▸Git Worktrees
- ▸SDLC Commands
Infrastructure
- ▸Mac Mini
- ▸Cloudflare Tunnel
- ▸Tailscale
- ▸Node.js 22
Application
- ▸Next.js 15
- ▸TypeScript
- ▸React 19
- ▸Tailwind CSS
Key Features
18 composable SDLC slash commands covering the full spec lifecycle: plan → implement → test → review → document → wrap-up
Parallel-safe execution with isolated git worktrees per task — each task gets its own branch, context, and working tree
Multi-phase pipeline with hard gates: each phase reads the prior phase's output file; test and review phases gate document and merge
Dual-access Mac Mini: Cloudflare Tunnel for public portfolio traffic, Tailscale for private development and admin access
Zero-port-forwarding public hosting — Cloudflare Tunnel outbound connection, no inbound firewall rules required
Dependency-ordered merge: parallel worktrees complete independently and merge in spec-defined order
Structured report artifacts at each phase — every spec run produces a permanent, inspectable audit trail
Validation suite integration: lint, TypeScript type gates (two configs by design), content validation, and full Jest run required before any PASS verdict
Code Examples
Technical Challenges
Designing pipeline phases that are independently re-entrant — any phase can be re-run after a fix without corrupting prior-phase outputs
Keeping worktree isolation clean: shared node_modules and Next.js cache across worktrees without cross-contamination
Structuring the two-face network so that public and private traffic never interfere and the setup survives Mac Mini reboots reliably
Defining phase boundaries that are meaningful to a human reviewer, not just a machine — each gate should represent a real quality checkpoint