A static English-only CV published at papou.work.
September 30 ATS version: ats.html and ats.css provide a separate single-column preview with full contact and repository URLs. The original CV remains the default visual version. The ATS version preserves all 37 achievement bullets, dates, roles, profile facts and spoken-language levels, adds the already documented Terragrunt and HAProxy to skills, and expands selected abbreviations. The web preview uses IBM Plex Sans; printing uses Arial at 10.5 pt for stable text extraction. Export with node scripts/export_ats_pdf.cjs to create assets/Ilya Papou CV (ATS) — DevOps & SRE.pdf and assets/cv-ats-pdf.json. The current export is three A4 pages. Open localhost:8000/ats.html while the local server is running. The matching editable Figma preview is on CV — ATS test · 2026-09-30. The ATS formats are linked from the footer. Automated readers are directed to the ATS HTML and generated text through metadata and the reading guide. Crawling is allowed; the ATS HTML points to the visual homepage as its search canonical, preserving the existing search preference.
September 28 revision: expanded platform GitOps/Terragrunt, ML migration, Airflow DAG distribution, secrets and mTLS experience; added production incidents, complete development-infrastructure ownership with 100+ VMs, Nexus scripting and isolated-deployment documentation; expanded Spring, Go and Helm work. Employer names follow the live LinkedIn profile, with the user's subsequent Sber Insurance naming correction: Red Rose Traveltech, Sber Insurance, Public Sector, Flant and Telecommunications company. Dates, other experience and personal projects remain unchanged.
The Russian site, PDF, language controls and discovery links are retired. Earlier versions remain recoverable from Git history. The spoken-language section still records Russian as Native. Build the English portfolio with node scripts/build_portfolio.cjs, export with node scripts/export_pdf.cjs, then run python3 scripts/check_site.py, python3 scripts/check_languages.py and the remaining checks below. The PDF remains two A4 pages under 1 MB, with unchanged type sizes and tighter first-page spacing. Figma and LinkedIn are maintained separately.
Content source: CV — Revised · Platform & Agent Systems, frames 370:3 and 370:105. The website uses this editorial baseline and six selected-technology categories, with separate screen and print layouts. Semicolons in prose are replaced with sentence breaks without changing meaning.
September 7 summary correction: the user-approved English summary describe production Kubernetes platforms and reusable DevSecOps pipelines as past experience. Current agent infrastructure is explicitly personal R&D and prototypes, with human-in-the-loop workflow design. The summary does not imply simultaneous customer engagements. AWS and Google Cloud remain the cloud preferences; RKE2, Proxmox and Ubuntu are named for bare-metal and self-hosted infrastructure. The visible summary, Person metadata, agent-readable text and the PDF share this wording. Historical employment and project achievements remain unchanged.
September 5 factual correction: Sberbank Insurance Broker was Hybrid, not Remote. Per-experience industry labels are restored from the five existing, previously hidden Industry domain nodes in the revised Figma page, with I-Teco normalized to the sidebar's Public sector: Aviation & travel; Finance & insurance; Public sector; Cross-industry IT consulting; Telecommunications. Labels appear without a "Domain:" prefix, aligned to the right of company headings on desktop, mobile and print. The same labels and work arrangement are included in the downloadable PDF and llms.txt.
September 6 project metadata correction: at the user's request, dates and locations for the three personal R&D projects follow the freshly reloaded LinkedIn Experience entries, with the user's subsequent correction of YourOwn.Chat's location from Buenos Aires Province to the city: YourOwn.Chat — Jun 2026–Present, Buenos Aires, Argentina; Home Aeroponics — Aug 2024–Jan 2025, Moscow City, Russia; Zero-Trust Mesh — Jan–Mar 2025, Bangkok City, Thailand. These replace the earlier year-only periods across the web, print/PDF and llms.txt. Personal R&D/PoCs labels, project achievements and the five employer entries remain unchanged. No remote-work arrangement is inferred for the projects.
The featured R&D heading is now exactly Agent Orchestration Infrastructure on mobile, tablet, desktop and print/PDF, following the user's naming correction. It has one shared heading and accessible name rather than separate mobile and desktop variants.
September 6 portfolio links: each R&D project has a compact Code row shared by the web, print/PDF, llms.txt and the revised Figma CV. Agent Orchestration Infrastructure links to six public repositories (platform, external-worker runtime, kagent fork and integration, Mattermost fork and image build); Home Aeroponics links to the Leafcoin concept, its controllers and sensor firmware; Zero-Trust Mesh links to Ansible automation, access policy and the GCP network lab. Links wrap on narrow screens and remain clickable in the two-page PDF. The print layout only tightens project padding and internal gaps, without reducing typography or changing project facts. Fork, prototype and build-dependency caveats remain in the linked repositories; a link does not imply a production deployment or a fully public build. LinkedIn uses dedicated project media cards rather than repeated URL footers in descriptions.
September 5 update: the user requested a sidebar portrait and clearer AWS/Google Cloud emphasis. The summary ends with the user's preference for AWS and Google Cloud, the freelance bullet leads with AWS infrastructure, and the first YourOwn.Chat bullet describes its existing Google Cloud deployments. AWS and GCP are explicit tags in the shared Cloud infrastructure list, without parenthetical abbreviations. Prose retains the full Google Cloud name. No new projects, services, ownership or production claims were added. The approved text, sidebar portrait and spacing are synchronized to the revised Figma CV, preserving its two A4 frames, and included in the GitHub Pages release. The print identity row is 90px with 8px internal spacing to accommodate the added preference sentence without crowding the page footer.
index.htmlcontains the CV content.styles.cssprovides responsive layouts and two-page A4 printing.assets/portrait-source.jpgandassets/fonts/contain the high-resolution portrait and local fonts.portrait.jpgremains the screen/person image;assets/social/cv-preview-20260906.jpgis the landscape CV-sharing card.
Preview locally:
python3 -m http.server 8000Open localhost:8000. A thin teal strip above the page contains Open PDF Version, linking to the prepared two-page visual CV. ATS Version is in the centered footer and opens the three-page single-column PDF; Text Version opens the ATS HTML with the device theme. This arrangement is shared by CV, ATS preview and portfolio. Book a call is the primary filled action in the toolbar; the section links remain in the same row on narrow screens. These links work without JavaScript or browser detection. Print or save from the PDF viewer; there is no separate Print action. The site cannot force an embedded browser to launch Safari or Chrome. If iOS previews the file, use Share → Save to Files or Print.
The visual CV, text CV and portfolio follow the visitor's device color scheme automatically, including changes while the page is open. A screen-only prefers-color-scheme: dark query adapts text, cards, links, controls and the cookie banner; media-qualified theme-color metadata also adapts supported browser chrome. There is no theme toggle, script, saved preference or cookie. The layout, typography and portrait stay unchanged. Native print and the prepared PDF always keep the original light palette; the exporter verifies this with a dark device preference. Run python3 scripts/check_theme.py to check scope, metadata and dark text contrast without browser dependencies.
The Book a call link opens 30 min with Ilya, the existing Google appointment schedule on the Workspace calendar ilya@papou.email. Its saved availability is Monday-Friday, 07:00-20:00 in America/Argentina/Buenos_Aires, with 30-minute Google Meet appointments. The last slot starts at 19:30. Busy time on the checked calendar is unavailable for booking. The existing 60-day booking window, four-hour minimum notice and other settings were preserved. The site opens Google's booking page without loading a scheduling widget into the CV page. The PDF strip and booking toolbar are hidden in print.
Native browser print shortcuts still use the A4 stylesheet. Letter paper, printer margins or browser headers/footers may repaginate the HTML. Use Open PDF Version for consistent page breaks, including when printing on Letter paper with fit-to-page enabled.
After any HTML, CSS, portrait or font change, export the exact checkout using Node.js, Playwright and installed Google Chrome:
node scripts/export_pdf.cjs
python3 scripts/check_site.pyThe exporter starts its own temporary localhost server and creates assets/Ilya Papou CV — DevOps & SRE.pdf plus assets/cv-pdf.json. Older PDF aliases are not generated. It checks layout overflow, footer clearance, two pages and a size below 1 MB. Render and visually review both pages before committing. The manifests record PDF and source hashes; release checks reject stale PDFs. Playwright is only needed for regeneration, not for the website or GitHub Pages deployment.
The downloadable PDF's title and native printing use Ilya Papou CV — DevOps & SRE for the suggested filename. Native printing restores the search-friendly browser title when printing ends or is cancelled. The print portrait is an eager-loaded HTML image rather than a CSS image replacement. The PDF exporter waits for it and the fonts before rendering the prepared file, so a failed image load cannot silently produce a portrait-free PDF.
The screen and prepared PDF share the original 896 × 1008 JPEG from Figma. The crop starts from image node 370:66 inside portrait frame 370:64, then uses the user's final adjustment: scale(1.1) with an origin of 50% 25%, keeping the shirt lettering outside the frame. Only the image transform changes, not the portrait container or responsive grid. The PDF keeps its 134 CSS-pixel portrait width and draws the existing thin frame in CSS, without baking the previous, tighter crop into the image. Text, lines and links remain vector-based. Check the exported PDF is below 1,000,000 bytes before release; browser and system PDF exporters can produce different sizes. Do not rasterize the entire CV or reduce the photo back to a preview thumbnail.
The print stylesheet follows the revised Figma frames and the supplied two-page PDF: original type sizes, 174px sidebar, aligned job headings and dividers, three technology columns, project cards and page counters. The 794 × 1123 source canvas is mapped to A4 while keeping text selectable and links clickable. Screen layouts retain fluid columns and flat cloud tags. The contact block omits the alternate-name row at the user's request. Print keeps compact technology rows and uses the exact Figma portrait crop. Export at 100% scale with browser headers/footers disabled and background graphics enabled.
Print artwork is exported directly from Figma. IBM Plex Mono Medium and SemiBold come from the Google Fonts IBM Plex Mono distribution, under the included SIL Open Font License.
The print layout keeps a 24px gutter beside the sidebar, 4px job separators and heading gaps, 2px sidebar row gaps and 12px gaps between page-two cards. The preview uses a 80px identity row and 8px internal gaps to accommodate the added preference sentence. It retains the source type sizes, high-resolution portrait and two-page A4 layout. Screen spacing remains independent.
The portrait aligns with the sidebar's text edges on desktop and in print. From 641–980px, the profile card keeps the portrait on the left and contacts on the right, aligned by their vertical centers. The contact title/context retain 12px/8px spacing, with 8px link-row gaps. Spoken languages span the full next row, followed by the expandable background.
At mobile widths up to 640px, the role label comes first, then a portrait exactly as wide as the name, then the name and experience headline, followed by the summary. An intrinsic grid track takes its width from the name; inline-size containment prevents the image from stretching that track. Text and photo share the left edge, with 20px gaps around the photo and before the summary. Sections use whitespace instead of decorative divider lines. The contact card no longer repeats the portrait: its six links form two columns, followed by full-width spoken languages and the expandable background. The mobile image uses the same original asset and crop; only one portrait is visible at any screen width, and the mobile copy is always hidden in print.
Only on mobile, the Profile & background toggle label and the headings/lists within its expanded sections are centered. The toggle's plus/minus remains at the right edge without shifting its label. The Contact heading and alias/location stay left-aligned. Contact links and spoken languages retain their existing grid and alignment; desktop, tablet and print remain unchanged.
Portrait widths are discrete, not viewport interpolation: mobile width follows the name at its fixed 27px font size up to 360px and 30px from 361–640px; the sidebar portrait stays 160px from 641–980px, 152px in the narrow desktop sidebar from 981–1180px, and 172px above 1180px. The screen 8:9 aspect ratio and letter-free crop are unchanged. Desktop/tablet portrait geometry and the two-page PDF remain unchanged by the mobile-only placement. Book a call uses a 36px visible control height with an extended 44px touch area and an accent fill with contrasting text in each device theme. The PDF strip is 36px tall on desktop and provides 44px link targets on mobile.
The PDF omits the colored bar-and-dot accents above projects, the Contacts accent, the sidebar's colored edge and its circuit motif. Their former spacing is reclaimed by normal flow. Gray experience dividers, card outlines, contact icons and the separate page-two research motif remain unchanged. The same decoration cleanup is applied to the revised Figma CV.
The contact block includes papou.work, WhatsApp Business papou.work and Telegram pilprod in both screen and print layouts. Messaging usernames are displayed without an @ prefix. Each contact uses a compact monochrome vector icon with an accessible channel label instead of a repeated text prefix. Messaging links use https://wa.me/papou.work and https://t.me/pilprod; no phone number is published.
GitHub Pages serves the repository root from main. No build step is required. Cloudflare proxies the apex A/AAAA records and the www CNAME. SSL is Full (strict); an exact-host 301 redirect sends www.papou.work to https://papou.work, preserving path and query. Mail DNS is independent and must not be changed for web deployment. No archived old hostname is needed. Keep the CV's intentionally public email readable in the HTML without JavaScript; Cloudflare Email Address Obfuscation must be off for this zone, since it replaces the original contact with a script-dependent protection link.
Cloudflare Web Analytics was enabled on September 30, 2026 with automatic installation and Enable, excluding visitor data in EU. The account-level RUM ruleset has enabled: true, lite: true, and an unpaused wildcard rule. One automatic beacon was verified in the proxied HTML for CV, ATS and portfolio, with validated HTTPS. Do not add a manual Cloudflare script or reuse another site's token. Cloudflare Google Tag Gateway was disabled on September 30, 2026 after a live check found its automatic tag insertion requested Google before consent. Its existing measurement ID and endpoint configuration were retained. Keep automatic insertion disabled so only the site controller can install Google. Fresh proxied HTML for all three pages has no gateway or Google script before consent and exactly one Cloudflare beacon. Cloudflare uses no analytics cookies; the EU setting suppresses its snippet for EU visitors. See Cloudflare setup options.
The GA4 web stream uses measurement ID G-HHJNK65HTV. analytics.js obtains the visitor country through the same-origin Cloudflare /cdn-cgi/trace endpoint. Verified visitors outside the 27 EU member countries start automatically unless they have a valid refusal. EU visitors and unknown regions require explicit Allow Google Analytics before any Google request. Errors, redirected or invalid responses, and a two-second timeout require approval. The country is never saved or sent to Google; language and timezone are not used as country evidence. Decline Google Analytics disables collection in every country. The notice explains this regional default, and the settings button remains available. Local and direct GitHub Pages previews never collect. Cloudflare Web Analytics remains separate, automatic and cookieless, with EU visitors excluded; the Google buttons control Google alone.
The consent choice is stored on the visitor's device for 180 days. Expired choices return to the regional default: EU/unknown visitors require a new decision; verified non-EU visitors start automatically. Storage failures do not prevent the CV from working, and the current visit still respects the visitor's choice. Google Analytics settings remains available below the CV. The current on/off status is shown inside the expanded settings panel only; the footer contains the settings button without a status message. Withdrawing consent disables collection, removes this site's _ga cookies and reloads the page without the tag. If permanent storage is unavailable, a session-only fallback is attempted. If neither storage can replace a stale approval, collection stays disabled without an automatic reload and the interface warns that the choice was not saved. Changes also apply across open tabs. The interface is hidden in print and never changes the CV's editorial content.
Only analytics consent can be granted. All advertising consent states remain denied, Google signals and advertising personalization are disabled, and no user ID, user properties or email, phone or messaging-link events are configured. CV, portfolio and ATS pages use the same consent controls. Page URLs are restricted to three reviewed public routes (/, /portfolio.html, /ats.html); index.html aliases are normalized and arbitrary paths, queries and fragments are never sent. Each route has a fixed page title. Referrers are reduced to HTTP(S) origins without paths, queries or credentials. The Google script itself is requested without a referrer. One explicit pageview is sent when analytics starts. GA4 may also collect its standard session and engagement measurements. These controls minimize collection; they are not a claim of complete anonymity or legal compliance.
While analytics is active, Open PDF Version sends cv_pdf_open, ATS Version sends cv_ats_pdf_open, and Book a call sends booking_open on all three public routes. All three omit the destination URL, filename and contact data. These measure link activation, not a completed download, document read or appointment booking. Google Calendar records completed bookings separately. Tracking includes keyboard activation and middle-click, preserves native navigation, and stops after withdrawal or consent expiry. Direct PDF requests, attached files read outside the site, refused visits, unanswered consent in EU/unknown regions, and visitors whose browsers block Google remain outside these measurements. No historical events can be recovered by enabling this coverage. The portfolio generator reuses the CV's notice and controls; rebuild the English portfolio after changing that notice. A duplicate controller cannot install a second Google tag or send another initial pageview. Google cookies expire after 180 days without refreshing their expiry.
Keep Enhanced measurement disabled in the GA4 stream so contact URLs, site-search values, form data and history changes are not automatically recorded. Keep advertising and user-provided-data features disabled. Do not enable automatic event settings without reviewing the collected parameters. The visitor notice links to Google's explanation of data use.
At setup verification on September 5, 2026, the GA4 property had Google signals, user-provided data and advertising personalization disabled, with both event and user data retention set to 2 months. A consented browser visit appeared in Realtime; the test ended with analytics declined again. Preserve these property-level controls as well as the site-side consent checks.
On September 23, 2026, the owner voluntarily allowed analytics in Chrome. The published site's page_view request returned HTTP 204 with consent parameters (gcs=G101), and Realtime showed one user, one page view, first_visit and session_start. This verifies that visit's delivery, not total traffic coverage or clearance of the GA4 consent diagnostics. The new portfolio/PDF coverage is separately validated by offline tests before publication.
On September 30, 2026, a clean-browser test of all three proxied routes verified zero Google requests before consent, after initial refusal and after withdrawal. One explicit page_view per route and the ATS PDF event returned HTTP 204 only after approval. Cloudflare RUM returned HTTP 204 independently of Google consent, with exactly one beacon script per page. ATS controls fit 320px and 390px viewports and remain hidden in print. This confirms the observed request delivery, not aggregate visitor coverage.
On October 2, 2026, the consent banner was made compact across CV, ATS and portfolio without changing analytics.js or the notice copy. At widths up to 600px, flat buttons show Decline and Allow with 44px touch targets and the full Google Analytics accessible labels. The CV banner measured 131px instead of 233px at 1440×1000, and 290px instead of 385px at 390×844. Local browser checks covered 320, 390, 768 and 1440px in light and dark themes, keyboard focus, print hiding, and real control activation for approval, refusal and withdrawal with Google stubbed (no external analytics traffic).
On October 4, 2026, the regional controller passed 30 dependency-free checks, including all EU member countries, non-EU automatic collection, lookup failures/timeouts, refusal during pending lookup, blocked storage, cross-tab changes and PDF event gating. CV and ATS PDFs were regenerated because the HTML fingerprints changed; extracted text and rendered pixels matched the preceding versions on all five pages.
The October 4 controller was published successfully through GitHub Pages. Live Chrome verification covered an explicitly allowed homepage visit, a clean non-EU visit without pressing Allow, and withdrawal. GA4 Realtime received page_view, first_visit and session_start. The clean visit displayed Google Analytics is on. You can turn it off in settings.; withdrawal displayed Google Analytics is off. The ordinary profile's pre-existing refusal was restored after the tests. These observations verify the tested visits, not complete traffic coverage. The separate validation workflow did not start because GitHub reported an account billing lock; its checks passed locally, and the Pages deployment succeeded.
Run the dependency-free consent tests before release:
node scripts/check_analytics.cjsAlso verify EU/unknown visitors send no Google requests before approval, verified non-EU visitors start automatically, refusal disables collection everywhere, and intended visits appear in GA4 Realtime. Review all PDF pages after regeneration. HTML/CSS updates require PDF regeneration because the release manifest fingerprints those files, even when the changed interface is print-hidden.
Implementation references: basic consent mode, consent commands, privacy controls, GA4 configuration, enhanced measurement.
- The CV shares a dedicated 1200 × 630 JPEG card with the current name and role, portrait and portfolio context. Open Graph and X Card title, description and image tags are delivered in the initial HTML; no JavaScript, cookie consent or login is needed to read them.
scripts/build_social_card.cjsrenders the card with the existing local fonts and the unchangedassets/portrait-source.jpg, scaled proportionally without cropping or AI resynthesis. The user explicitly selected original-photo composition. It uses the same local Playwright/Chrome setup as the PDF exporter. Inspect the resulting card before publishing; any changed asset also requires the normal PDF manifest refresh.- The portfolio page has its own title, description and existing workbench photograph. It does not reuse the CV card or imply that the lab photograph verifies the archived firmware. Its AI-background-retouch disclosure is retained in the image description.
- Each page declares one canonical HTTPS URL and one primary image, including HTTPS image URL, JPEG MIME, dimensions and descriptive alt text. The image filename is versioned so later replacements can avoid an old image-cache entry. Do not invent social handles, app IDs or verification tokens.
python3 scripts/check_social.pychecks both pages, metadata consistency, real image dimensions, file size and crawler permissions. After deployment, use--url https://papou.work/ --botsto check delivery using common sharing-crawler user agents. This is an HTTP compatibility check, not proof that every app has refreshed or renders the same layout.- LinkedIn and other apps can cache previously shared cards. Use LinkedIn Post Inspector to inspect the canonical link. An existing message or post can retain its older card; display size and image cropping are controlled by each app and sometimes its user.
- References: Open Graph, LinkedIn sharing requirements, Apple Messages rich previews.
portfolio.htmlis the supporting, indexable project-evidence page. It maps the three R&D projects to eleven public repositories, five archival firmware prototypes, the matching LinkedIn Projects/Experience labels and nine lab photographs. The CV links to it from the second-page introduction, including the two-page PDF, with no duplicate portfolio link in the website footer.portfolio.jsonis the reviewed data source.node scripts/build_portfolio.cjsgenerates the visible page,portfolio.md,portfolio.jsonldand the image-awaresitemap.xml. Do not edit generated files individually. Use--checkto reject stale generated resources without changing them.portfolio-images/contains the same privacy-reviewed JPEGs as the two aeroponics READMEs. Seven images disclose AI background/identifying-area retouching. One root-chamber photograph shows both the roots and internal tubing, without repetitive views. The diagram and root evidence are not AI-redrawn. Do not replace these files with the unreviewed originals or claim a photography license that has not been granted.- The breadboard and Home Assistant dashboard photographs use 1024 × 768 privacy-edited versions of the owner's supplied photos. Patterned wallpaper was replaced with a neutral wall using AI assistance. The gallery and discovery data use
breadboard-prototype-privacy-20260909.jpgandhome-assistant-dashboard-privacy-20260909.jpgto avoid the previous image caches. The oldbreadboard-prototype-1024.jpgandhome-assistant-dashboard.jpgURLs remain compatibility aliases, each containing exactly the same edited bytes as its replacement. Display scales proportionally, and image links open the complete frame. - The portfolio graph uses separate
CreativeWork,SoftwareSourceCodeandImageObjectidentities, withhasPart/isPartOf,aboutandsubjectOfrelationships. Source files are parts of their repository; repositories are parts of a project.Person.sameAsremains limited to the personal GitHub and LinkedIn profiles. Verified fork origins useisBasedOn, without assigning upstream authorship to Ilya. LinkedIn links are public section URLs, never owner-only edit URLs or invented per-entry permalinks. - Firmware variants are archived 2024 experiments, not final solutions or releases. Missing modified libraries, incomplete callbacks/telemetry and unverified calibration/relay behavior remain explicit. Research periods are not repository publication dates. Photos document the wider lab and do not certify that archived code builds or runs safely.
- The complete CV is delivered as semantic HTML and remains readable without JavaScript.
- Canonical, Open Graph and social-card metadata use
https://papou.work/. - Ilya Papou is also known as Ilya Popov. Keep this identity link in search/social metadata, the Person's
alternateNameandllms.txt. Both names share one canonical page and one Person identity. Names in robots.txt comments do not affect indexing, and the sitemap lists URLs rather than keywords. PILPRODandpilprodare alternative forms of the same professional handle. Keep both in the Person'salternateName,llms.txtand explanatory comments inrobots.txtandsitemap.xml, without adding them to visible headings, profile labels or the print layout. Existing profile URLs stay unchanged.- The CV JSON-LD describes the
ProfilePage, itsPersonand theWebSite, and mentions the three works on the supporting portfolio page. Keep it consistent with visible content. Agent Orchestration Infrastructure is personal R&D. Its source describes components deployed on Google Cloud, separately from designed orchestration, prepared release infrastructure and simulated-provider validation. Preserve those distinctions rather than applying a blanket deployment claim to the whole project. robots.txtallows search crawlers, explicitly includingOAI-SearchBot, and advertisessitemap.xml. The existing open crawling policy is retained. Search access and model-training policies are separate concerns.llms.txtnamesats.htmlas the preferred CV for automated reading and points first to ATS HTML, thenllms-full.txt,ats.mdand the ATS PDF. Its existing factual CV context remains synchronized withindex.html.ats.mdandllms-full.txtare identical complete Markdown companions generated from the semantic main content ofats.html, excluding navigation, scheduling and privacy controls. Runpython3 scripts/build_ats_text.pyafter ATS content changes and--checkbefore publication; the generator preserves all 37 achievements and explicit URLs. Head metadata and the Person's CV work link connect HTML, Markdown and PDF formats. These are discoverability and reading preferences; external agents can ignore them, and search engines choose their own canonical. It is not a ranking signal or an indexing guarantee. The named Figma page is the editorial source, and the HTML and Markdown must preserve its distinctions between built, deployed, designed, prepared and simulated work.- The sitemap contains the CV and the supporting portfolio page, plus its nine image URLs and the CV portrait. Update
portfolio.json'smodifiedwhen portfolio content changes. KeepcvModifiedaligned with the CV profile'sdateModified; do not advance the CV date for portfolio-only edits or refresh dates just because a build runs. Keep each page's canonical URL distinct; both describe the same person.
Run the dependency-free checks before publishing:
python3 scripts/check_site.py
python3 scripts/build_ats_text.py --check
node scripts/build_portfolio.cjs --check
python3 scripts/check_portfolio.py
python3 scripts/check_site.py --url https://papou.work/
python3 scripts/check_portfolio.py --url https://papou.work/GitHub Actions runs the local checks on pushes and pull requests. Pages publication continues to use the existing main branch deployment. Keep local audits and working documents untracked.
The checks protect the September 4, 2026 Figma/PDF baseline plus the user-directed cloud emphasis and September 6 R&D project revisions: all 37 achievement bullets, identity, sidebar facts, job titles and dates, project descriptions, contact/code links and 86 tags (83 existing technologies plus AWS, Google Cloud and Flux CD). OpenVPN was removed from the security tags at the user's request, while its experience mention remains. Section fingerprints ignore case and presentation punctuation, while retaining numbers and comparison signs. They intentionally allow the Ilya Popov alias, the flat cloud list with one IAM entry and the web placement of Zero-Trust Mesh's date. Mobile-only abbreviated names are excluded from the canonical source comparison. When the editorial source changes, review the source again and update the affected baseline together with the HTML and Markdown; do not refresh a fingerprint merely to make a failed check pass.
After deployment, the site owner can submit https://papou.work/sitemap.xml in Google Search Console and Bing Webmaster Tools, and use their URL inspection tools. This repository does not create verification tokens or automatically claim ownership. Crawling, indexing, rich results and AI citations depend on the search services.
On September 30, 2026, the papou.work domain property was verified through an additional DNS TXT record for the current Google account, preserving existing verification records. Search Console reported the canonical homepage indexed with HTTPS and one valid ProfilePage item. The existing sitemap had Success status and was resubmitted successfully; fresh indexing requests were accepted for the CV and portfolio. The portfolio was discovered but not yet indexed at inspection. The existing GA4 association links the https://papou.work/ URL-prefix property to the papou.work web stream (15722482368). At that verification, ATS used noindex and was not submitted. On October 5 its noindex directive was removed and a canonical pointing to the visual CV was added; agent reading guides prefer ATS, while the existing visual homepage remains the search preference. These are point-in-time checks, not guarantees of future indexing or ranking. No Bing submission was performed in this setup.
References: Google AI search guidance, ProfilePage structured data, OpenAI crawlers, llms.txt proposal.
The compact header follows the CV content width, with inset controls aligned above the page. Decorative section dividers are removed from the CV, PDF and portfolio. The CV header uses a typographic CV. wordmark in IBM Plex Mono, visible on desktop and mobile without a button border or background. Home Aeroponics retains its Code links and places a separate Concept — Leafcoin link alongside them in the CV and PDF. The portfolio labels it Leafcoin concept.