There is a new page on this site: /explore. It is a public, read-only view of what happens when a personal site runs a honeypot and a real edge network at the same time. Attack traffic against decoy endpoints, Cloudflare edge metrics, and legitimate human visitors - three independent vantage points on the same domain, refreshed on a minutes-scale cadence.

This post is the colophon for the stack underneath: which repos run which streams, why a Cloudflare Worker stitches them together, what gets refreshed when, and how the page rolls back when something breaks. A separate companion piece, What's Running at /explore, is the legend for the data itself - what every counter, code, and chart means.

What you will see

The page opens with four headline counters: events tracked, canary triggers, trap endpoints, and countries over the current window. The numbers move. They are not curated.

A reading-depth toggle in the header switches between Overview (headline widgets only) and Full depth (every chart described below).

Below the counters, four sections:

  • The contrast. The composite view. Attacker volume next to sampled edge requests next to real pageviews. The contrast is the point, which is why the page leads with it.
  • Attack traffic. Top attacked paths, canary trigger timeline, attackers by country, top hostile user agents, time-of-day patterns, and a sample of LLM-generated decoy responses. This is what the honeypot sees: requests to /.env, /admin, /wp-login, and dozens of other trap endpoints that have no legitimate reason to be hit.
  • Edge. What Cloudflare handles before anything reaches the origin: HTTP volume, traffic by country, status codes, cache status, firewall blocks over time, top blocked countries and paths, and a recent-requests sample.
  • Real visitors. Self-hosted Umami analytics. Real humans, measured without cookies, identifiers, or cross-site trackers.

What you will not see

No raw IP addresses. Source IPs are redacted to /24 for IPv4 and /48 for IPv6 inside the materialization query. The unredacted values never land in the database that serves the page.

No visitor tracking beyond pageviews and country. The Umami script does not set cookies, does not assign persistent visitor IDs, and does not share data with any third party.

No private data. The dashboard is read-only. Redacted events sit in a private schema, and owner-executed public views expose only the aggregate columns each tile needs. The browser's anonymous role can select those public views; it has no access to the private schema, ingestion table, or pipeline RPCs.

Why publish this

A site is mostly text. An infrastructure project produces signals. If the second one is running anyway, the signals should be visible. Two reasons specifically:

The first is honesty. Logs, counts, and traces are more credible than prose about logs, counts, and traces. The honeypot post that comes next will be easier to read with a live page sitting next to it.

The second is calibration. Most of the traffic to a personal site is not human. Showing the ratio - hostile, edge, legitimate, side by side - corrects the assumption that any of this is quiet. It is not.

The technical layer below covers what runs under the page.