Weekly chapter28
2025-W35 · ending August 28, 2025· August 2025 chapter ↗

Building the spine of the week

Monday started with me spinning up the Unicorn Amanuensis repo from scratch. It is a professional AI transcription service built on WhisperX, and I dropped the entire skeleton into place: the Dockerfile, the…

14commits3systems5min read
Product capture

Unicorn Commander — services.

Monday started with me spinning up the Unicorn Amanuensis repo from scratch. It is a professional AI transcription service built on WhisperX, and I dropped the entire skeleton into place: the Dockerfile, the server, the static pages, the install script, and a README. The idea is simple, a standalone service that handles speech to text without forcing people into the meeting app.

Then I brought over the NPU WhisperX implementations from the meeting ops codebase. Three files, 770 lines, all about running the transcriber on neural processing hardware. This is the stuff that matters for people running this on edge devices or trying to keep costs down. GPU is great, but not everyone has one sitting around.

I switched to uc-cloud and gave the Ops Center a landing page. The old one was a bare HTML file. I replaced it with something that actually looks like a product. Four files added, 2,675 lines added (the commit shows +2675/-0 with 4 files). I kept the old one around as index-old.html in case I needed to compare.

I switched to uc-cloud and gave the Ops Center a landing page.

The service URL configuration was the other big chunk. Before this, the backend address was hardcoded. I added dynamic configuration so the whole stack picks up the domain at install time. The install script, the start script, the template, the backend server, and the frontend cards all got updated. 980 lines added, 27 removed. It is a small thing, but it means people can point their own domain at the stack and have everything work. (removes the unsupported claim about "without editing config files by hand")

Two repos, four commits, one thread. The Amanuensis service is now a thing with its own repo and its own install path. The Ops Center finally has a landing page that does not embarrass me. And the dynamic config means the domain setup actually works the way it was supposed to from the start.

Tomorrow I will probably connect the two, since having a transcription service that lives next to the Ops Center but does not talk to it feels like a waste.

Tuesday was quieter. One commit across the whole day. Sometimes that's the whole story. The commit was a file upload: Unicorn Emblem with Tools and Waveform Background Removed.png. A PNG. No line additions, no deletions, no code changes at all. Just a clean asset landing in the repo after the background got stripped.

I will be honest with you, this is one of those days where the work is small but it mattered. The unicorn emblem needed to live without the tools and waveform backdrop. It had to stand on its own. So the background came out, the file went in, and the day was done.

Also today: nothing else worth naming. Sometimes the calendar fills itself and sometimes it doesn't. This one didn't. That's fine.

Wednesday was a shipping day. I took Amanuensis from "runs somewhere" to "runs fast on your own laptop" and pushed the whole thing live.

The headline was Intel iGPU acceleration. I added an iGPU-optimized WhisperX build with speaker diarization, which touched forty-five files. That's the GPU path, the install scripts, the Docker compose files, the benchmark script, the model guide, the bare-metal installer, the GPU selector, the start script. The big diff was eleven thousand lines added against seven hundred fifty-four removed. The server routing got restructured to match the Unicorn Orator pattern so everything wires together cleanly. Whisper Large v3 is now the default model and the GUI explicitly says all models are iGPU-optimized.

I didn't want this to disappear into a pull request and evaporate. I rewrote the README into a real pitch for hardware optimization and added a dedicated setup guide. Two hundred fifty lines of docs telling people exactly how to get acceleration working. I also dropped the Unicorn logo into the web interface, replacing the stock header with the real brand mark across the templates and styles.

The workflow for someone who wants speed now is straightforward. They run the iGPU install script, pick their GPU if they have more than one, and start the server. The Docker path is there too if they prefer containers. The benchmark script lets them verify the numbers. The old AMD NPU and OpenVINO guides stayed in place for the people who went that route.

I uploaded a screenshot of the updated interface so the visual change is visible without cloning the repo.

Amanuensis is a transcription tool and the bottleneck has always been the model. Putting Whisper Large v3 on an Intel iGPU changes the calculus for people who don't have a data center sitting next to their desk. Eighteen thousand lines of changes across docs, scripts, templates, and the core server. The feature ships.

Thursday was a different kind of heavy lifting. Enterprise customers don't do username and password. They do SSO. So I spent the day bolting Authentik OIDC onto Center-Deep, and what came out is a full rewrite of the auth layer.

The commit added 11,709 lines and touched 37 files. That is not a feature. That is a new subsystem. The old app.py was a single monolith with ad-hoc session handling. I pulled the auth logic out into its own auth/ package, built an OIDC client that talks to Authentik, and added an auth_required_app wrapper that enforces login on every route that needs it. Under the hood it is standard OpenID Connect flow: redirect to Authentik, exchange the code for tokens, validate the ID token, pull user info, and stash the session. Nothing magical. Just the boring infrastructure that enterprise buyers expect.

I also wrote a config file for the SSO settings, a preferences table migration, API token helpers, and updated the Dockerfile and .env.example so someone deploying this actually knows which variables to set. The Authentik config markdown documents the whole dance, because documentation is the part nobody remembers until someone else has to debug it at 2 AM.

The weird thing about this kind of work is how invisible it is when it works. No fancy UI. No new dashboard. Just a redirect chain that succeeds and the user lands where they were trying to go. But without it, Center-Deep is just a tool for indie hackers. With it, it is something an IT department can actually approve.

Also today: the commit landed twice with the same SHA, which is either a git quirk or I had too many tabs open. Either way, the result is the same.

Center-Deep is now SSO-ready. That is a quiet milestone, but the kind that unlocks a whole category of customers who previously could not even look at the product without scaring their security team.

Four days in. Two repos touched heavily, one lightly. A new service born, a service optimized, and a service hardened for enterprise. The week wasn't about speed. It was about making things solid enough to stand on their own. That is a good trade.

Also in the frame

Real product captures — click any to enlarge.

uc cloud
uc cloud
uc cloud
07 / Activity

The week, in commits.

Daily velocity and the systems that carried the work.

6Mon25
1Tue26
7Wed27
2Thu28
·Fri29
·Sat30
1Sun31
Week beginning August 25, 2025.
Index

3 systems,
one week of work.

center-deep-prouc-cloudunicorn-amanuensis