The /explore page on this site is a live view into telemetry the site collects about itself. The writing pages are static HTML and use no database. The dashboard is a separate application backed by Supabase, where three ingestion streams feed public aggregate views. Refresh the page and it reads the latest completed ingestion runs.

This article is the legend for that page. If you landed here from /explore wondering what HP, CF, UM, and CMP mean, this is the answer. For the architecture underneath, see the companion colophon: which repos run which streams, why a Cloudflare Worker stitches them together, and how the page rolls back when something breaks.

Why I Run Production-Grade Personal Infrastructure explains why the site exists at all. About this site maps the system behind it. This piece explains what the site sees.

Why publish it

Most security and analytics telemetry stays private because the systems it describes have to stay private. The infrastructure I manage professionally is not something I can write about in specifics. The infrastructure I run for myself is. So when I argue that the gap between professional and personal practice is where blind spots form, the consistent move is to open the personal side.

The page is small. Three streams plus a few composite tiles, a few dozen tiles total. But it is honest about what is observable from a personal site running behind Cloudflare, with a small honeypot attached, and a self-hosted analytics beacon. One detail is worth flagging up front. The persistent bottom of the honeypot's long tail is /wp-login.php, and this site has never run WordPress. Nothing about that traffic cares. The probes never stop on a domain that has nothing to find.

What the streams show

Each stream covers a multi-week window. The honeypot has been running since the current deploy on April 15, 2026. Its window grew with the deploy clock and stood at 28 days when these figures were taken, on 2026-05-13; the tables below are that snapshot, and the honeypot has since moved to the same thirty-day rolling window as the other two streams. The Cloudflare and Umami streams are thirty-day rolling. The numbers as of writing: 30,100 honeypot events, 618 source addresses, 72 countries.

The Cloudflare stream covers thirty days of edge traffic. 54,723 requests, 4,396 blocks across 85 countries. Block in this dataset means a managed WAF rule, a custom rule, or a rate limit triggered. The longer-term plan is to push these logs into BigQuery using the same pattern that already runs for another project. Until that is wired, the numbers come from zone analytics directly.

The Umami stream covers thirty days of analytics on the site itself: 392 pageviews, 117 visitors, 164 visits, 106 bounces. Umami is self-hosted, runs on a Mac Studio in a closet, and is privacy-respecting by design. Running Google Analytics on a site that argues against pervasive tracking would be incoherent.

There is one detail that sits oddly until you know what it is. The number-two path on the honeypot table is /pixel.gif, and it is mine. It is the analytics beacon Umami fires on every page render. The honeypot classifies it as a canary. Filtering it would mean trusting my own classifier before showing the data. Better to leave it visible and explain it. The number-one path is /xmlrpc.php at 2,065 hits, a WordPress endpoint on a site that has never run WordPress. More on that in Table 2.

How to read it

Tiles on /explore are coded by source so they are never ambiguous. HP is honeypot. CF is Cloudflare. UM is Umami. CMP is composite, meaning a tile that joins more than one source. Numbers are Postgres views. They reflect the source tables at the moment you loaded the page.

The /explore page is not a product. It is a window into the same infrastructure the companion piece describes, run for the same reasons.