I get asked pretty regularly how I publish articles like the ones on this site. The answer is not a CMS. It’s an agentic pipeline that runs through about six tools before anything goes live.
Here’s the exact flow, start to finish.
Most articles start as a voice note I send to Hermes — my personal agent. I ramble for 5-15 minutes about whatever I’m thinking about: a market trend I’m watching, something I shipped, an argument I want to make. Hermes transcribes it, separates private context from publishable material, and returns a clean draft in my voice.
Sometimes I start with a Google Doc instead. The writing hub at the link below tracks every active draft, its status, thesis, next move, and backlinks to published work.
Hermes writes the article as a Markdown file with frontmatter — title, description, date, category, read time — and saves it to the local repo at /home/coder/work-mattwright-eth/src/content/blog/. I review, correct, or send another voice note with changes. We iterate until it’s right.
The site runs on Astro. A production build compiles the Markdown into static HTML:
npm run build
That gives me a dist/ folder with about 30 pages of static HTML. No database, no server, no CMS.
The built site gets uploaded to Pinata, an IPFS pinning service. This turns the whole site into a content-addressed identifier — a CID that acts as a permanent fingerprint of exactly what was published:
python3 /tmp/upload-pinata.py
# Returns: bafybeifo5mkawpmxhajwayrayx3pnsd6te4xpqyurauujfmpqqhnzbci3a
That CID is the source of truth. Anyone can verify that the site they’re reading matches what was uploaded.
The CID gets submitted as a transaction to update the contenthash record for mattwright.eth on ENS. But I don’t control that record directly — it’s owned by a Safe multisig wallet, which means any update requires approval from the authorized signers.
A Python script builds the transaction, signs it, and submits it to the Safe transaction service:
python3 /tmp/propose-ens-contenthash-env.py <cid> <commit-sha>
This creates a proposal that sits in the Safe interface, waiting for approval.
I open the Safe app, review the transaction, and sign it. Once the required threshold of signatures is met, anyone can execute it. The ENS contenthash updates on-chain, and the IPFS gateway resolves the new content.
When you visit mattwright.eth.limo, you’re hitting an ENS name that resolves to a contenthash, which points to an IPFS CID, which serves static HTML built from Markdown files in a GitHub repo.
No CMS. No database. No hosting subscription. The entire site is a git repo, an IPFS upload, and an ENS record controlled by a multisig. Anyone with the address can verify exactly what was published and when.
This setup is overengineered for a personal blog and exactly right for what publishing should become. The content is portable. The infrastructure is owned. The publication record is on-chain. No platform can delete it, no company can go out of business and take it with them, no algorithm can deprioritize it.
I believe most serious writing will move toward this model within the next few years. The tools are all open source, the pipeline is reproducible, and the cost approaches zero for the writer. The only thing that scales is the quality of the work.
That’s the bet Contraband is built on.