Leahy & Co’s ownThe platform behind BuiltSite

Every BuiltSite website runs on a hosting platform I built and run: changes go live in minutes, the servers are locked down, and nothing is open to the internet.

The problem

BuiltSite builds websites for trades and small businesses, and every one of them needs somewhere to live. It has to be quick, hard to break into, and simple to change: a change to a client’s site should be live in minutes, and a mistake should be easy to undo.

What I did

I built the hosting platform every BuiltSite website runs on.

  • Each website runs in a sealed container. It can serve its pages and send its enquiry emails, and nothing else. It can’t change its own files, so there’s very little for an attacker to work with.
  • The server has no open doors to the internet. Visitors reach it through an outbound-only tunnel to Cloudflare, so there’s no port for anyone to knock on.
  • Every change goes through the same automatic steps: build it, deploy it, then check the site through the same path a visitor uses. The previous version is kept ready to put back.
  • The security settings every site needs live in one shared place, so a fix reaches every site at once.

What changed

  • A change to a client’s website is live a few minutes after it’s made, without anyone logging into a server.
  • Every site gets the same locked-down setup without anyone having to remember it.
  • Adding a new site is a short written checklist, not a project.
  • It runs every BuiltSite website, including builtsite.com.au.

Under the bonnet

  • Linux server, rootless Podman containers run by systemd (Quadlet)
  • Read-only containers, non-root, all capabilities dropped
  • nginx in front, with shared security headers and a per-site Content Security Policy
  • Cloudflare Tunnel: outbound only, no inbound ports
  • GitLab CI: build, push, deploy, then verify through nginx, with the previous image kept to go back to
  • Each site a static Node.js build with one small form endpoint
  • Form mail configurable per site: any SMTP relay, or Microsoft 365 over OAuth; Cloudflare Turnstile against bots

Services this touched

Got something like this?

A free chat about the problem, then a written quote before any work starts.