This site is hand-written HTML and one small stylesheet. A couple of requests per page, no cookies, no tracking. Everything below is what makes those two files actually reach your screen.
Your browser asks a resolver where aurelien.goulon.net
lives. This zone is DNSSEC-signed, so the resolver does not just take the
answer on faith. It validates a signature chain back to the DNS root. If
anything in between tried to hand you a forged address, the chain would
break and the lookup would fail closed instead of quietly succeeding.
What comes back is a Cloudflare anycast address, one of the same handful of IPs that answer for millions of other domains. I do not choose which physical data center responds. BGP does that live, based on whichever announcement for that address is topologically closest to you. Someone in Calgary and someone in Marseille can be routed to two different buildings without either of us configuring anything.
Your browser opens a TLS 1.3 connection to that address. Cloudflare terminates the encryption at its nearest point of presence, rather than on a server I run, then negotiates HTTP/2 or HTTP/3 based on what your client supports. CAA records matter here too: they limit which certificate authorities may issue a certificate for this domain. A compromised or careless CA elsewhere on the internet cannot issue one just because it feels like it.
If Cloudflare already has this page cached, it responds immediately and
the next step never happens. Otherwise, it retrieves the content from the
origin: a static HTML file in a public Git repository, published by GitHub
Pages on every update to the main branch. No server for me to
patch, restart, or lose sleep over. The origin is a file, not a process.
The response comes back through the Cloudflare network, is cached for the next visitor, and reaches your browser as two files, nothing more. No render-blocking scripts, no third-party requests, no layout shift while something finishes loading.