Skip to content

Site Operations and Monitoring

John A. Paz edited this page Oct 2, 2026 · 6 revisions

Site operations and monitoring

Owner: John Paz. Parent issue: #24.

Approved scope

  • Public status and tested outage/recovery alerts: #30. Availability, build activity, and audience engagement are distinct signals. Show timestamps and Unknown/stale states.
  • Owner-first /admin dashboard: #31. Simple branded public introduction, protected dashboard and restricted data, selectively revocable read-only sharing. No client-only password gate or private data in public static assets. Authentication/routing provider remains to be selected. Toolbar navigation is handled in a separate session.
  • Analytics: #32. Traffic sources, popular content, resume downloads, portfolio engagement, outbound and contact clicks. Clicks are not completed inquiries.

Accepted analytics decision — October 2, 2026

John resumed this workstream and requested analytics first. He subsequently approved tracking staging in a separate GA4 property. This supersedes the earlier analytics-last sequence and no-staging-tracking requirement for this workstream. Local development and /admin remain excluded.

Two dedicated properties and HTTPS web streams were created under the existing Paz Web Development account:

Environment Property Measurement ID
Production johnapaz.com — Production G-1ESYN701VR
Staging johnapaz.com — Staging G-68CVWTTNZ4

Reporting timezone is New York, currency USD. Enhanced measurement and Google Signals are off. Advertising personalization is disallowed in all regions. User/event retention is 14 months, with reset on new activity off. Mia’s property was unchanged.

Implementation and verification

PR #45 contains consent-gated configuration-driven tracking, persistent consent/withdrawal controls, privacy disclosure, minimized events, and separate hostname/environment gates. IDs are public identifiers; no reporting credentials are stored in source. An authenticated provider link may serve as an interim shortcut; the agreed admin dashboard includes embedded reports through a protected backend as described below.

Local consent/withdrawal/payload/isolation checks passed, including all V2 layout coverage. Both Jekyll configurations and link/metadata checks passed in run 37010262464. Staging GA4 Realtime received page_view and portfolio_click for / and /coding/; consent rejection and withdrawal persist after reload with no external Google tag. PR #45 is merged into v2, followed by the V2 layout fix at 0affc089aefc87b3e1271b089f38dba5101fec06. The parallel toolbar/theme staging revision fc885eb6876126fb6392d2fd6592ce286c334519 incorporates this implementation.

Production PR #46 was approved by John and merged into main at e7cc0d0e233dfacbea0162ddc74ad09d244960c1. Pages deployment 37011400025 succeeded. Production Realtime received two page_view events (/ and /coding/) and portfolio_click. Live production uses G-1ESYN701VR; no external Google tag loads before consent or after withdrawal and reload. The first smoke test exposed automatic scroll collection: enhanced measurement had not persisted off during initial setup. It is now confirmed off in both properties after completing the confirmation dialog; early verification data includes that scroll event. Broader manual event coverage, physical Fold6 review and the protected /admin reporting dashboard remain follow-ups. Do not mark #32 complete yet. Source setup/rollback instructions: docs/analytics.md.

Admin dashboard analytics reporting — October 2, 2026

John confirmed that live GA4 collection should feed the branded /admin dashboard. Admin dashboard ticket #31 now contains the reporting acceptance criteria; analytics ticket #32 owns collection and event validation. The reporting connection is not built yet.

Use the GA4 Data API through a protected backend, with reporting credentials held only on the server and least-privilege access. Apply owner and explicitly granted, revocable read-only permissions to report endpoints as well as the dashboard. Select the backend/authentication provider and confirm exact /admin routing alongside the existing Jekyll/Pages deployment before implementation.

Keep production property 557084016 and staging property 557077138 in clearly labeled separate views; staging test traffic must never enter production totals. Show visitors/active users, sessions, traffic sources, trends, popular pages/content and available resume_download, portfolio_click, outbound_click and contact_click counts, with explicit metric definitions. Include date ranges, previous-period comparisons, reporting timezone and last successful refresh. Cache aggregate reports with a documented refresh cadence and handle quota/failure conditions. Show loading, empty, delayed, stale and error states without presenting missing data as zero or cached data as real-time.

Reports reflect visitors who opt into analytics. Contact clicks indicate interest, not completed inquiries; newly collected data and consent rates limit historical comparisons. Validate report totals against GA4 for both environments, metric/event mappings, logged-out denial, owner/read-only access and revocation. Physical Fold6 checks remain required. The toolbar entry point is being handled in a separate session.

Dashboard staging implementation — October 2, 2026

John approved direct staging publication. PR #48 adds a minimal /admin entry and an explicitly labeled, synthetic-data dashboard preview at /admin/preview/ on staging. Prod/Staging tabs, 7/28/90-day periods, previous-period comparisons, saved 1/2/3 widget columns, metric definitions, audience trends, channels, popular pages, manual events, devices, countries and operations shortcuts are implemented. Narrow layouts reduce columns automatically. The currently selected navigation/theme work is preserved. No private GA4 data is published, and the production build excludes the sample dashboard.

A proposed Cloudflare Access + Worker reporting backend is prepared and unit tested, but not provisioned or deployed. Keep the existing Pages /admin introduction; a private dashboard hostname can provide sign-in without migrating the public site. Exact protected same-origin /admin routing would require a separate DNS/proxy decision. No infrastructure changes or paid services have been made. Sign-in remains disabled until configured.

The Worker protects HTML/assets and reports, validates signed Access identity and the owner/read-only allowlist on every request, fixes property selection server-side, caches reports for five minutes and labels failed-refresh data stale for up to 30 minutes. It uses a least-privilege GA4 service account held only as runtime secrets. Removing an allowed reader denies subsequent requests after the configuration update. No guests are configured.

Local staging/production safe builds and internal-link checks passed; five backend tests passed for auth/signature/expiry/issuer/audience checks, revocation, period math, environment isolation, report mappings and read-only endpoints. Staging deployment 37015476958 succeeded at d2065ffc52b5345e00fb23a87c0fb22f330c842e. Browser review verified the landing, both environment tabs, dates preserving environment selection, one/two/three columns, keyboard tabs, refresh and saved column preference, with no desktop overflow. Physical Fold6/mobile browser testing remains pending. The backend directory is excluded from both Pages builds.

Remaining: Cloudflare hostname/Access application and owner policy; Google Cloud Analytics Data API and Viewer service account access to both properties; runtime secrets; deployed login/sharing/revocation checks; GA4 total reconciliation; source/deploy comparison and independent monitoring; physical Fold6 review. #31 stays open. Setup and implementation record.

Clone this wiki locally