Building Blue Canoe
The infrastructure, engineering decisions and evidence behind the current Blue Canoe platform.
This collection follows the work in the order it became possible: the network edge, the internal back channel, authoritative DNS and DNSSEC, the replacement mail platform, and the systems built on those foundations.
- Pre-Tik and Post-Tik: The Router That Unblocked EverythingHow replacing a constrained ISP router unlocked Blue Canoe's wider DNSSEC, mail and network programme.
- 10Gb Where It Matters: Building the Back ChannelWhy Blue Canoe separated ordinary service traffic from a 10Gb backend network for replication, backups and infrastructure operations.
- Prepare to Be Wrong: What the MikroTik Installation Actually Taught UsHow incomplete information, a wrong assumption and a simple cooling fix reinforced Blue Canoe's evidence-led engineering approach.
- The Exchange Caught Fire: An Acceptance Test We Didn't OrderHow an exchange fire, a recovery VLAN error and an awkward support path tested the new MikroTik edge more convincingly than any benchmark.
- The DNS Server Nobody Can SeeHow Blue Canoe separated DNS source state from public secondaries, learned from migration failures, and built a checked, portable publication process.
- DNSSEC: Trust Has to Leave Your NetworkHow Blue Canoe connected locally signed DNS zones to the public chain of trust, then used DNSSEC to authenticate DANE across three live mail servers.
- Green Has to Mean SomethingWhy internal DNS agreement is not enough, and what an external production report actually proves.
- The Mail Server Factory: Build for the Day It BreaksHow Blue Canoe built a repeatable three-node mail platform with preflight checks, recorded evidence, recovery planning and replaceable servers.
- Thirty Mailboxes, No Leap of FaithHow Blue Canoe reconciled a mailbox migration by account identity rather than reassuring totals.
- Going Live Was the Short PartThe preparation, staged controls and production lessons behind Blue Canoe's mail cutover.
- Ten Policies That Were Really OneHow ten apparently separate MTA-STS policies turned out to share one backing file.
- Publishing DANE Was the Easy PartWhy publishing a TLSA record was only the start of keeping DANE correct through certificate renewal.
- The Report That Found a Fault in ItselfHow a daily mail report exposed both a transient lookup failure and a defect in its own email.
- Two Photographs and a Lot of TrustThe information, trust and collaboration behind rebuilding The Motorsports School website.
- A Site Designed for One JobWhy the TMS replacement was designed around one business rather than a platform comparison.
- The Office Got QuieterWhat TMS's own feedback and dated search evidence showed after the website rebuild.
- Successful Does Not Mean FinishedHow a successful production system supplied the evidence for designing its replacement.
- Before the Form, Understand the BusinessHow a small partner-onboarding tool helped separate business questions from booking-system implementation.
- A Payment Is Not a BookingWhat the next booking core has to establish before money and capacity can become a confirmed booking.