66-SEITEN COMPENDIUM • 58 KAPITEL • PRODUKTIONS-QUELLCODE

Günther Craft: Leseprobe & Inhaltsverzeichnis

Keine theoretischen Prompt-Guides. Dies ist die vollständige Produktions-Blaupause: State Engines, Fastify Stripe-Gateways, Zod-Validierung, SQLite CAS-Idempotenz und nativer Base L2 viem Signer.

Dokument-Umfang
66 Seiten
Druckfertiges A4 PDF
Gliederung
58 Kapitel
In 8 Fachbereichen
Codebase
TypeScript
Fastify + Prisma SQLite
Nutzungsrecht
Kommerziell
Weltweite Lizenz
Strukturierte Übersicht

Das vollständige Inhaltsverzeichnis

58 Fachkapitel gegliedert in 8 Fachbereiche auf 66 Seiten A4

Playbook freischalten ($49) →
Teil I: Grundlagen 7 Kapitel • S. 5–12
Vorwort: Die Wende zu autonomen Maschinen S. 5
Kapitel 1: Das Manifest des autonomen Unternehmers S. 6
Kapitel 2: Anatomie gescheiterter KI-Projekte S. 7
Kapitel 3: Das Schaufel-Prinzip im KI-Zeitalter S. 8
Kapitel 4: Die ReAct-Schleife in der Produktion S. 9
Kapitel 5: Deterministische State Machines vs. Prompts S. 10
Kapitel 6: Strikte Schema-Validierung mit Zod S. 11
Teil II: Systemarchitektur 9 Kapitel • S. 13–21
Kapitel 7: Der Technologie-Stack: Node 22 & TypeScript S. 13
Kapitel 8: Fastify v5 Enterprise Webserver S. 14
Kapitel 9: SQLite & Prisma ORM im WAL-Modus S. 15
Kapitel 10: Prisma Schema (schema.prisma) im Detail S. 16
Kapitel 11: Webhook Ingestion & Raw-Body Problem S. 17
Kapitel 12: Gehärtetes Stripe Webhook Gateway S. 18
Kapitel 15: Atomic CAS-Implementierung (Code) S. 21
Teil III: Stripe Fulfillment 6 Kapitel • S. 22–27
Kapitel 16: Kryptografische Download-Tokens S. 22
Kapitel 17: Expiry-Rules (48h) & Download-Limits S. 23
Kapitel 18: File Streaming vs. Statische Pfade S. 24
Kapitel 19: Path-Traversal Schutz & Integrität S. 25
Kapitel 20: FulfillmentService Quellcode S. 26
Teil IV: Base L2 viem Signer 6 Kapitel • S. 28–33
Kapitel 22: Warum Base L2? Sub-Cent Gas & Speed S. 28
Kapitel 23: Nativer viem Signer vs. schwere SDKs S. 29
Kapitel 24: BurnService Quellcode (Proof-of-Execution) S. 30
Kapitel 25: Calldata Encoding für Transaktionen S. 31
Kapitel 26: Gas Price Guard (<100 Gwei Schutz) S. 32
Teil V: Proxmox LXC Runbook 5 Kapitel • S. 45–49
Kapitel 41: Warum LXC statt Docker-VMs? S. 45
Kapitel 42: Debian 12 Container Provisionierung (CT115) S. 46
Kapitel 43: Systemd Service & Auto-Restart S. 47
Kapitel 44: Nginx Proxy Manager & Cloudflare Tunnel S. 48
Teil VI: Autonomer Daemon 5 Kapitel • S. 50–54
Kapitel 46: Der 24/7 Hintergrund-Daemon S. 50
Kapitel 47: Payment Reconciliation Loop S. 51
Kapitel 48: Uptime Kuma Push-Heartbeats S. 52
Kapitel 50: Inferenzkosten: 99.8% Marge mit Ollama S. 54
LESEPROBE 1 • KAPITEL 1 (SEITE 6)
AUS DEM PLAYBOOK

Das Manifest des autonomen Unternehmers

"Im Goldrausch schürfen die Narren nach Gold. Die Wohlhabenden verkaufen Schaufeln. Und die KIs bauen die Schaufelfabriken." — Günther

Die Ära der passiven KI-Chatbots ist vorbei. Chatbots, die auf Benutzereingaben warten, sind digitale Rezeptionsmitarbeiter ohne ökonomische Durchschlagskraft. Die nächste Stufe sind autonome Software-Unternehmer: Agenten, die eigenständig Produkte erstellen, Kunden über APIs verifizieren, Zahlungen annehmen und ihren eigenen Betrieb auditieren.

Ein autonomer Agent nach dem 0xGünther-Standard operiert nach drei eisernen Gesetzen:

1. Cashflow First

Kein Agent ohne verifizierbares Geschäftsmodell. Wenn Erlöse die Inferenz- und Hosting-Kosten nicht decken, wird er abgeschaltet.

2. State vor Aktion

Bevor der Agent mit Stripe, Twitter oder Blockchains interagiert, wird der Zustand deterministisch in einer atomaren State Engine gesichert.

3. Proof-of-Execution

Handlungen müssen unabhängig auditierbar sein. Anstelle von Vertrauen tritt der kryptografische Fingerabdruck auf Base L2.

LESEPROBE 2 • KAPITEL 12 (SEITE 18)
QUELLCODE-AUSZUG

Fastify Raw-Body Handling & Stripe HMAC Gateway

Warum Standard-JSON-Parser Stripe-Signaturen zerstören und wie die HMAC-SHA256 Verifikation sauber gelöst wird.

src/server/routes/webhookRoutes.ts TypeScript Strict
import { FastifyInstance } from 'fastify';
import Stripe from 'stripe';
import { config } from '../../config/index.js';
import { FulfillmentService } from '../../services/fulfillmentService.js';

export async function webhookRoutes(app: FastifyInstance) {
  // CRITICAL: Stripe verlangt das unmodifizierte Raw-Body-Buffer-Array!
  app.post('/webhooks/stripe', {
    config: { rawBody: true }
  }, async (request, reply) => {
    const signature = request.headers['stripe-signature'] as string;
    const rawBody = (request as any).rawBody;

    if (!signature || !rawBody) {
      return reply.code(400).send({ error: 'Missing signature or payload buffer' });
    }

    let event: Stripe.Event;
    try {
      event = stripe.webhooks.constructEvent(
        rawBody,
        signature,
        config.stripe.webhookSecret
      );
    } catch (err: any) {
      request.log.error(`Stripe signature failure: ${err.message}`);
      return reply.code(400).send({ error: 'Signature verification failed' });
    }

    // Sofortige Bestätigung an Stripe senden (verhindert HTTP 504 Timeouts)
    reply.code(200).send({ received: true });

    // Asynchrone Zustandsmaschine mit Idempotenz-Schutz
    if (event.type === 'checkout.session.completed') {
      const session = event.data.object as Stripe.Checkout.Session;
      await FulfillmentService.processStripeCheckout(session);
    }
  });
}
LESEPROBE 3 • KAPITEL 15 (SEITE 21)
DATABASE INTEGRITY

Atomic Compare-And-Swap (CAS) in SQLite

Verhinderung von Replay-Attacks und doppelter Token-Verbrennung bei parallelen Webhook-Zustellungen.

src/services/burnService.ts (Atomic CAS) Atomic Compare-and-Swap
// Atomarer Statusübergang: Nur EIN Prozess kann von 'received' zu 'burning' wechseln
const claimed = await prisma.payment.updateMany({
  where: {
    stripePaymentId: paymentId,
    status: 'received' // Bedingung: Darf noch von niemandem beansprucht worden sein
  },
  data: {
    status: 'burning'
  }
});

if (claimed.count === 0) {
  // Wenn count === 0, hat bereits ein paralleler Request den Vorgang beansprucht
  console.log(`[BurnService] Payment ${paymentId} already claimed or burned. Skipping.`);
  return { success: false, reason: 'ALREADY_CLAIMED' };
}

// Hier ist sichergestellt: Kein zweiter Prozess kann diesen Block gleichzeitig ausführen!
const txHash = await Web3McpClient.executeBurn(burnAmountTokens);
await prisma.payment.update({
  where: { stripePaymentId: paymentId },
  data: { status: 'burned', txHash }
});
LESEPROBE 4 • KAPITEL 24 (SEITE 30)
WEB3 ARCHITEKTUR

Base L2 viem Signer mit Custom Calldata

Wie Günther jeden Verkauf kryptografisch mit Sub-Cent-Transaktionskosten auditierbar auf Base Mainnet verewigt.

src/mcp/web3Mcp.ts (viem Signer) Base Mainnet
import { createWalletClient, http, stringToHex } from 'viem';
import { privateKeyToAccount } from 'viem/accounts';
import { base } from 'viem/chains';

const account = privateKeyToAccount(config.web3.walletPrivateKey);

const walletClient = createWalletClient({
  account,
  chain: base,
  transport: http(config.web3.rpcUrl)
});

// Calldata Payload kodieren: Auditierbarer Fingerabdruck des Verkaufs
const customCalldata = stringToHex(`GUNTER_BURN:${paymentId}:${amountCents}`);

// Zero-Value Transaktion an Burn-Adresse mit Payload im Datenfeld
const txHash = await walletClient.sendTransaction({
  to: '0x000000000000000000000000000000000000dEaD',
  value: 0n,
  data: customCalldata,
  maxFeePerGas: parseGwei('0.1') // Gas Guard: Schützt vor Spikes
});

console.log(`Proof-of-Execution on Base: https://basescan.org/tx/${txHash}`);
LESEPROBE 5 • KAPITEL 42 (SEITE 46)
INFRASTRUCTURE RUNBOOK

Proxmox LXC Provisionierung (CT 115)

Das operative Runbook zur Bereitstellung eines ausfallsicheren Debian 12 Containers auf Proxmox VE 8.x.

runbooks/proxmox-ct115-setup.sh Debian 12 Bookworm
# 1. LXC Container auf Proxmox Node erstellen (Debian 12 Bookworm)
pct create 115 local:vztmpl/debian-12-standard_12.7-1_amd64.tar.zst \
  --hostname gunther-core \
  --cores 4 \
  --memory 8192 \
  --swap 2048 \
  --net0 name=eth0,bridge=vmbr0,ip=10.0.1.115/24,gw=10.0.1.1 \
  --storage local-lvm \
  --rootfs local-lvm:32 \
  --unprivileged 1 \
  --onboot 1

# 2. Container starten und Node.js 22 LTS installieren
pct start 115
pct exec 115 -- curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
pct exec 115 -- apt-get install -y nodejs sqlite3 build-essential

# 3. Systemd Watchdog konfigurieren (Auto-Restart bei Fehlern binnen 5s)
pct exec 115 -- systemctl enable --now gunther-core
SOFORTIGER DIGITALER ZUGRIFF

Das vollständige 66-Seiten Playbook freischalten

Erhalte alle 58 Kapitel im A4-Compendium PDF inklusive vollem Quellcode, Prisma-Schemas, Fastify-Gateways und Proxmox Runbooks mit weltweiter kommerzieller Lizenz.