← All work

Project 2026Evolving

memorization

A flashcard app built to study Spec-Driven Development with GitHub Spec Kit. Every requirement is cited by a test, and an AI architect orchestrated AI workers under a written constitution.

11
specs, each approved before any code
11
constitution principles
100%
requirements cited by a test

Why it exists

This started as coursework for Trends in Software Engineering. The product, flashcards grouped into decks and practiced in study sessions, is deliberately simple. The subject is the process: can Spec-Driven Development keep an AI-assisted codebase honest?

The process

Every feature went through the same seven steps, in order:

Step What it produces
specify User stories, requirements and success criteria. No technology
clarify Up to five questions to the Product Owner, each with a recommendation
plan Technical decisions and contracts, checked against the constitution
tasks Small tasks, each with its own test and linked to the requirements it fulfills
analyze Gaps, duplicates and conflicts, found before any code exists
implement Code written by workers, reviewed and integrated by the architect
converge Proof that every requirement is cited by a test

The roles were explicit: I acted as Product Owner, Claude Code as architect (driving Spec Kit, reviewing every diff, integrating), and DeepSeek workers wrote the code, each in an isolated worktree. A written constitution sits above the specs: no implementation before approval, verification over assertion, honest minimal scope, secrets never in the repository, and a test for every requirement and a requirement for every test.

Architecture

flowchart TD
    U([Browser]) -->|HTTPS| CF[CloudFront]
    CF -->|/ and assets| S3[(S3<br/>React SPA)]
    CF -->|/api/* + origin secret| L[Lambda<br/>Fastify API]
    L -->|secrets on cold start| SSM[SSM Parameter Store]
    L -->|verified TLS| DB[(Neon<br/>PostgreSQL)]
  • One API, two runtimes. The same Fastify app runs locally on SQLite and in the cloud on PostgreSQL (Neon), behind a storage port with two real adapters.
  • CloudFront as the single entry point. It serves the React SPA from S3 and forwards /api/* to a Lambda, injecting an origin secret without which the Lambda answers 403.
  • Secrets in SSM Parameter Store, read once on cold start. Infrastructure in OpenTofu.
  • Passwords salted per user, HMAC-SHA256 with a server secret, then scrypt, so a database leak alone reveals nothing.
  • Tests in Vitest and Testing Library, plus Playwright end-to-end in a real browser against the real API and database.

What’s next

Spaced repetition, so the app decides what you study next instead of shuffling, and a reworked interface. Both go through the same spec-first flow.