Portfolio

Work samples.

Solo builds across different domains and stacks — from architecture through to a working product. Most are live and deployed. ProAct is the one that ties directly to the maintenance domain.

ProAct

Predictive maintenance planning.

Work sample — predictive maintenance planning, built solo in 2026.

A platform for predictive maintenance planning: assets in hierarchies, recurring maintenance tasks, and automated email reminders with HMAC-signed one-click links, so a task can be completed or postponed without logging in. Role-based access, invite-only accounts, audit log, soft-delete with a recycle bin, CSV import/export, bilingual DE/EN, rate limiting.

Tech stack
Python · FastAPI · SQLModel · SQLite · React · TypeScript (strict) · Tailwind/DaisyUI · Vite · JWT/bcrypt · multi-stage single-image Docker (non-root)
What it demonstrates
285 automated tests (232 pytest, 53 Vitest). A clean service-layer architecture, secure token design, role-based access with an audit log, and bilingual i18n from the data model up.
Timescale
Four weeks, solo — from kickoff to a working application.

Source code is private. A guided code walkthrough is available on request via screen-sharing, NDA-friendly.

WatchVault

Encrypted file vault on a smartwatch.

The watch acts as a dumb encrypted carrier while all cryptography and plaintext handling occur exclusively on the PC. Pairing between the two devices is established via a 6-digit code valid for five minutes. The software is complete, tested, and verified on the Amazfit T-Rex 3 as of release 0.20.3.

Tech stack
Python 3 PC tool (age encryption, scrypt KDF, local HTTP server, pipx CLI) · Zepp OS mini-program (API level 4.0, @zeppos/zml, PIN UI, sandbox storage) · JS side-service bridging HTTP ↔ BLE file transfer
What it demonstrates
Applied cryptography, BLE and cross-device protocol design, threat-model-driven architecture, and working within tight wearable hardware constraints.
Timescale
This project followed a 14-phase development process from 26.05.2026 to 22.09.2026, resulting in a system verified on the Amazfit T-Rex 3.

Gitea Backup & Restore

A three-tier backup design for a self-hosted Gitea instance.

Architecture diagram of the backup flow: local staging, offsite NAS sync, external copy, plus the alerting and restore-drill safety net.

A three-tier backup design for a self-hosted Gitea instance: checksummed local staging, an offsite sync to a NAS that stays powered off ~99% of the time (the actual air gap), and mail alerts on any silently failed run. Every stage verifies itself and the stage before it before anything is trusted or an older copy pruned.

Tech stack
Bash + systemd timers · checksummed staging with periodic scrub · rsync + Wake-on-LAN · generation-based retention (weekly/monthly/yearly) · mail alerting
What it demonstrates
Defense-in-depth thinking for infrastructure that has to be correct unattended, not just fast — integrity gates before, during and after every run, and an air-gap design.
Timescale
Design and implementation complete, verified against itself.

Claude Code Setup Backup

A whole AI-tooling setup as a five-minute restore.

Portable backup and restore for a customized Claude Code setup — a token-usage governor, an automated session-handoff loop, and a set of custom skills and hooks. An idempotent sync script plus a weekly background job that only commits when something actually changed.

Tech stack
Bash + rsync · macOS background job (launchd) · git, change-only commits
What it demonstrates
Automation discipline — idempotent, change-detecting, safe to re-run — and security-conscious scoping: live credentials and per-machine session state are deliberately excluded from the backup, each by name, with a stated reason.
Timescale
Built incrementally alongside the tooling it protects; the weekly job has been running unattended since.

Contents shown here are the mechanism, not the real configuration — no raw personal setup data.

growatt-bridge

A home hybrid inverter, talking to Home Assistant on my own terms.

A self-built Modbus bridge between a home hybrid solar inverter and Home Assistant: reads live power, battery and grid data over Modbus and publishes it via MQTT auto-discovery, backed by a documented, code-generated register map and a mock mode for development without live hardware.

Tech stack
Python · Modbus TCP · MQTT (Home Assistant discovery) · Docker · pytest
What it demonstrates
Full-stack hardware integration, from wiring and protocol-level debugging to a safety-guarded write path (whitelist, bounds, rate limiting, status gate, readback-verify) and dashboard sensors derived from real field measurements rather than datasheet assumptions.
Timescale
Live on real hardware since 2026-08-03; the read path is verified, the write path stays gated off by default.

Site/network details are deliberately generic here — this describes the mechanism, not the specific installation.

Lager-FDS

Booking-and-payment platform.

A German self-storage rental platform — browse units on a map, book and pay online, with a full admin back office. A booking-and-payment platform built in a stack that was new to me.

Tech stack
Laravel 13 + Filament 5 admin (PHP 8.4) · Blade + Alpine.js + Tailwind v4 · MariaDB (prod) / SQLite (dev) · PayPal Commerce Platform · Leaflet + OSM · Matomo · Pest + Playwright
What it demonstrates
Payment-provider integration, admin-panel engineering, a unit and e2e test pipeline, and a real production deploy to German shared hosting — in an unfamiliar stack.
Timescale
Roughly three to four weeks to a first bookable MVP.

benjamin-becht.de

Fast, privacy-first static site.

This site itself — a fully static, bilingual, privacy-respecting site that loads almost instantly and has a tiny attack surface.

Tech stack
Astro 6 (static) · Tailwind v4 (@theme tokens) · Self-hosted @fontsource fonts · Content-collection blog (Markdown, no database) · Email-only contact (no form) · Hand-authored EN/DE i18n · Sitemap + RSS
What it demonstrates
Static-site architecture, an enforced performance budget, zero-JS-by-default delivery, and privacy by construction — no trackers, no CDNs.
Timescale
Roughly one week to a deployable bilingual site.

Get in touch

Interested in a walkthrough?

I'm looking for a permanent role and am happy to walk through any of this on a call.

Contact