Work index

Systems / Personal system / Private repository

Web context gateway

A private search and crawl service my machines and AI agents share, with hard crawl budgets and per-client tokens.

Year
2026
Relationship
Personal system
Role
Design and build
Diagram of the web context gateway: CLI, Codex, and Claude clients connect to one gateway, which reaches SearXNG and Firecrawl on an internal network
Fig. 01 Architecture diagram. One owned gateway in front of internal search and crawl services.
01

Overview

What it is

My AI workflows depended on separate hosted search and scraping services, each with its own schema, limits, and outages. The gateway gives every trusted machine and agent one API for search, page-to-Markdown, site maps, and bounded crawls. It runs on a small always-on Linux box that is never exposed to the internet.

02

Scope

What it includes

  1. 01

    Web search through self-hosted SearXNG

  2. 02

    Scrape, map, and crawl through self-hosted Firecrawl

  3. 03

    REST, MCP, and a CLI over one gateway

  4. 04

    A separate revocable token for each client

03

Role

My role

I built it alone in July 2026: the Go gateway, the CLI, the MCP adapter, the deployment, and the qualification suites.

04

Build

Technical notes

Gateway
A small Go service owns auth, policy, normalized responses, REST, and MCP. SearXNG and Firecrawl sit on an internal container network with no host ports.
Capacity
The host has two cores and 8 GB of RAM, so the gateway runs one crawl and one browser page at a time and sheds load past that.
Safety
Every submitted or discovered URL is treated as hostile input, and crawled content is only kept when a request opts in.
Qualification
Unit, integration, race, live REST and MCP, security, load-shedding, restart, and restore suites all pass.
  • Go
  • SearXNG
  • Firecrawl
  • Docker
  • Tailscale
  • MCP
05

Selected work

Development work

  1. 01 Architecture
  2. 02 Go Gateway
  3. 03 CLI
  4. 04 MCP Adapter
  5. 05 Deployment
  6. 06 Qualification
06

Results

Results

  • Qualified for three clients, each with its own revocable token: the CLI, Codex, and Claude Code.