Peter D. BethkeSiteShell.netSpring Hollow Publishing, Inc.

A selection of work

Open source

Readable code, checkable claims.

01
Go
Elastic-2.0
Code →Live →

corral

Prove your tests would catch it.

Corral breaks your code on purpose and checks whether your tests notice. It plants faults that violate a stated guarantee, runs your own suite against each one in a sandbox, and reports how many it killed — measured by execution, never taken on a model’s word.

The constraint underneath is nemo iudex in causa sua: the party that did the work never certifies the work, and a run where the critic model matches the writer model is refused. It ships as one command, corral certify --local, against your own provider key with no server.

Unedited output of autonomous corral runs is preserved as evidence, defects included: corral-run-js-lru-cache and corral-run-python-ratelimit.

02
Python
zero runtime dependencies
Code →

kirby-cost

The HERO System 6E build and cost engine, ported from scratch.

A from-scratch port of the HERO System 6E character build and cost engine, validated to 100% parity with the reference implementation across 656 fixtures, every character exact on every object. Parity is a release gate, not a one-time claim.

Ships no licensed Hero Games content. Part of the Kirby engine line, three separate zero-runtime-dependency Python libraries: kirby-cost costs a build, kirby-combat resolves 6E combat, and kirby-sheet reads a HERO Designer character and writes it back out as JSON, text, HTML, PDF, or .hdc. The credential here is the parity number, and it is checkable because the code is public.

03
SQL
Sigma Public
Code →Live →

sigma-rbac-lab

Application-level RBAC on Sigma Public, verified against a SQL oracle.

Scoped grants, a multi-tenant read/write boundary, and a scoped agent, all verified against a SQL oracle. Every research lab carries its own VERIFY.md, so a skeptical reader can read the code, run the oracle, and use the live workbook — three things to check, not one to take on faith.

The RBAC I built, distinct from the erd-to-schema experiment where an AI assistant rebuilt a schema from a diagram.

04
SQL
Sigma Public
Code →Live →

erd-to-schema

A working RBAC schema rebuilt by an AI assistant from a mermaid ERD image.

What Sigma’s assistant rebuilt from a mermaid ERD image and two prompts, with a SQL oracle that verifies its output. This one tests a tool; sigma-rbac-lab is the system I built myself — worth keeping straight, since they are both RBAC and both live on Sigma Public.

05
TypeScript
Node
Code →

agent-indexing-lab

The indexing study behind Your codebase is the prompt.

The repo backing the article, carrying its own oracle and VERIFY.md so the study’s claims can be checked rather than taken on faith.

06
Python
no dependencies
Code →

sportspicker-core

A contest contributes exactly its budget to the championship, whatever rule is chosen.

Dependency-free scoring and aggregation for pick’em contests, written to be an audit subject for corral — the guarantee that corral enforces is exactly what corral audits it against. Included precisely because it shows the corral thesis applied to my own code.

Platform & product work

Private systems, described as case studies. Happy to walk through them — ask and I will show you what I can.

07
Django
DRF
TypeScript
SvelteKit
Happy to walk through it — just ask

ProductBinder / WebOffice — private · commercial · in development

A multi-tenant publishing platform.

Product and listing management, a CMS with inline page and navigation editing, an events subsystem with full RFC 5545 recurrence, and a commerce layer covering rate cards, campaigns, invoicing, and accounting sync.

A Django/DRF core behind a versioned TypeScript SDK, consumed by a SvelteKit admin and server-rendered public sites. Fifteen-plus coordinated repositories with a cascading CI/CD pipeline onto self-hosted infrastructure. The largest system in the portfolio and the clearest evidence of working at platform scale — which is why it headlines despite not being clickable.

A commercial platform I’m building. It runs in production for a regional media business and is not yet on the market.

08
Cloudflare Workers
multi-provider AI
Happy to walk through it — just ask

Media Library

The media and AI engine underneath ProductBinder and Kirby.

A Cloudflare-Worker CDN with on-the-fly resize and AVIF negotiation, async video pipelines, multi-provider AI generation behind one adapter, semantic search, and a quarantine-first safety pipeline: Safe Browsing, then ClamAV, then NSFW ML, then CSAM hashing, then lifecycle expiry.

Deployed twice as separate tenant instances, powering two product lines.

09
MCP
Happy to walk through it — just ask

Agent write-governance (MCP)

AI proposes; a deterministic, auditable layer decides.

An MCP surface over the production schema: schema-validated, permission-checked, dry-run-by-default with before/after diffs, and an immutable per-call audit trail.

Now absorbed into corral.

10
FastAPI
Foundry VTT
Live →Happy to walk through it — just ask

Kirby VTT platform

FastAPI services around Foundry VTT.

Campaign generation, procedural maps, and a combat assistant, where a deterministic engine with seeded, auditable RNG resolves every outcome — the same result every time, from the same seed.

Public project site at kirbyvtt.org; the kirby-cost, kirby-combat, and kirby-sheet engines are its open-source core.

11
Authentik
OIDC
Happy to walk through it — just ask

Self-hosted identity

Two independent Authentik deployments, one per product line.

Per-tenant branded OIDC/SSO, run as two independent Authentik deployments serving the two product lines separately.

12
AWS
Google Pub/Sub
Live →Happy to walk through the public site — just ask

Cella

A twenty-year arc: sole engineer through a company’s growth, then its integration into a global platform.

Cella could not afford an IT department. I was the whole function, through the company’s growth from under $10M to over $100M in revenue. The substance of the engagement was an enterprise-scale staffing application with extensive third-party integrations and custom APIs, later architected and maintained on AWS — the public website was its visible surface, not its subject.

Workflow management for HR and staffing teams across multiple business entities and regions: a full CRM plus job lifecycle from hiring through ad placement, application, fulfillment, and follow-up, invoicing tied into Crystal Reports and Great Plains accounting, talent-facing dashboards for timesheets and HR documents, and a role-scoped back end with selective access to sales, invoicing, and administration — the same shape of scoped, multi-tenant permission system as the RBAC research labs, built on the stack of the time.

Cella became part of Randstad US Technologies Group, and I went with it — the system built for a small company conformed into a multinational’s. That integration work is its own entry below.

cellainc.com is still live today.

Peter, with his innate intelligence and deep knowledge of technology, was able to clearly understand our business needs, translate them into the technological equivalent and deliver the results that allowed us to grow to over $100 million in revenue… he was the first and only person we would call.

Rossi Bonugli, co-founder, Cella, Inc. (now part of Randstad US Technologies Group)

Peter is extremely professional, collaborative and a partner in the truest sense of the word… I highly recommend Peter and wouldn’t hesitate to work with him again.

Conor Smith, former co-CEO, Cella, Inc.
13
Google Cloud
Pub/Sub
cross-border data harmonisation
Happy to talk through the architecture — just ask

R-One integration architecture — Randstad USA · 2023–2024

Conforming US source systems into a global platform’s warehouse.

As integration architect I built the server that abstracted multiple US source systems behind a common layer and streamed them, via Google Pub/Sub, into the Netherlands-based R-One platform’s data warehouse. Cross-border data harmonisation, owned from concept through initial build.

The harder half was not the pipeline. I set the R-One USA integration strategy and roadmap and aligned executives and several teams across data domains — the work of getting independent groups to agree what a field means before any of it can be conformed.

It is the same problem as every engagement on this page, at multinational scale: take what one system knows and reshape it into what another one needs.

His leadership, creative problem-solving, and dedication during major global integrations and feature rollouts truly make him an invaluable asset. No matter the challenge, Peter ensures the team stays on track, always ready to lend a hand regardless of his own workload… I deeply appreciate his steadfastness in defending our team’s decisions under pressure.

Agon Vuniqi, colleague at Randstad; now Senior Software Engineer (AI) at Bloomberg

Peter has been an amazing asset to several teams at Randstad. He’s engaged, thorough and incredibly knowledgeable. I would have Peter on any of my teams.

Robin Hayes, scrum master and project manager, Randstad
14
JD Edwards
Oracle
Happy to discuss the approach in general terms — just ask

Product-data transformation for a specialty-chemicals manufacturer

Clean, correctly-shaped data out of JD Edwards for a compliance-document system.

A product-data transformation API feeding a compliance-document system: it navigates JD Edwards’ opaque, denormalized schema and produces clean, correctly-shaped datasets for the downstream application that generates the compliance documents.

The client runs a traditional Oracle relational warehouse, migrating to SQL Server, with Power BI on top; I work upstream of the reporting layer. The credential is the transformation layer against one of the hardest ERPs in the industry to extract from.

Ask Charles

Featured by Sigma.

15
Live →Featured by Sigma

Ask Charles

A data-center site selector that ranks all 3,144 U.S. counties.

Featured by Sigma on their own account: “Meet Ask Charles, a new AI app built in Sigma.”

Every county scored on the factors that actually decide a data-center site — industrial power price, water stress, community opposition, interconnection-queue difficulty, climate risk, labor, incentives — each from public data, with the date of that data recorded. A 0–10 importance slider per factor reranks the composite live, and a grounded advisor re-reasons as the priorities change.

The finding is the interesting part: the data refuses to pick Northern Virginia, disqualified not by its resources but by its success — the worst community opposition in the country and the most gridlocked interconnection queue. The cheapest power on the map, New Mexico at 5.9¢/kWh, is a water-stress trap. No county wins on every axis.

The app publishes its own audit layer — the source behind every factor, a note flagging where a number is going stale, and a log of what was deliberately left out.