In software engineering, there is an instinctive developer urge toward centralization: take the blog, the interactive learning portal, the client games, and the on-premise GPU inference engine, and shove them all into a single monolithic framework like Next.js or Django. But in systems design, bundling disparate workloads into a single monolith creates a fragile house of cards.
The Incompatible Physics of Mixed Workloads
A comprehensive technical ecosystem contains subsystems with fundamentally contradictory operational profiles:
- Static Editorial & Thought Leadership (blog.vikramsamal.com): Demands sub-20ms global Time-to-First-Byte (TTFB), zero origin compute load, infinite horizontal scaling, and complete resilience against traffic spikes.
- Interactive AI Learning & Vector RAG (learning.vikramsamal.com): Requires session-aware Python application runtimes, local SQLite state databases, Chroma vector storage, and private on-premise GPU inference.
- Browser-Based Games & Tools (arcade.vikramsamal.com): Static client bundles that run client-side state machines entirely within the user's browser runtime.
[The Zero-Trust Multi-Subdomain Architecture]
[Global User Request]
│
▼
[Cloudflare Edge Anycast / DNS Router]
├──► blog.vikramsamal.com ──► Cloudflare Pages Edge (0ms Origin Load)
├──► arcade.vikramsamal.com ──► Cloudflare Pages Edge (Static Web Bundles)
│
└──► learning.vikramsamal.com ──► Cloudflare Zero-Trust Tunnel (QUIC)
│
▼ (Outbound-Only Encrypted Tunnel)
[Private On-Prem Server: Port 5001]
├── Flask App Engine
├── Local SQLite & Chroma DB
└── Private Ollama GPU Runner
Zero-Trust Ingress: Eliminating Public Attack Surfaces
Connecting on-premise AI hardware to the public internet traditionally required fragile port-forwarding rules, dynamic DNS daemons, and open inbound firewall ports. This created severe attack vectors for automated scanners and denial-of-service attempts.
By establishing an outbound-only encrypted Cloudflare Tunnel using the QUIC transport protocol, the private server never opens a single inbound listening port to the public internet. If a malicious actor floods the editorial blog, Cloudflare's Anycast edge absorbs the traffic with zero impact on the private inference server. If the local GPU runner undergoes maintenance, the editorial and arcade surfaces remain 100% operational globally.
The Architectural Rule
Clean system design begins with clean perimeter boundaries. When you isolate workloads by their natural operational profiles, you eliminate failure propagation and achieve true architectural sovereignty.