Self-hosted Retool on AKS, all in Terraform, fed by public data with a citation for every source
A working Retool platform I built and run on Microsoft Azure, the way a firm would operate one: a production instance and a nonprod upgrade lane on Azure Kubernetes Service, private Postgres, secrets in Key Vault and a self-hosted Infisical, and a scheduled pipeline that loads only data that is legal to publish.
Live dashboard (public): demo.retool.maxmccann.us,
with ingestion pods, company risk and sources.
Retool itself: retool.maxmccann.us and nonprod.retool.maxmccann.us (sign-in required). The figures below are rendered from the same read-only published layer the
Retool apps query.
Icons: Microsoft Azure Architecture Icons (used per Microsoft's icon terms); Kubernetes icon set (Apache-2.0/CC-BY-4.0). Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL Community Association of Canada, and used with their permission. Cloudflare, Retool, Infisical, Let's Encrypt and GitHub are shown by name only.
Employers must file a WARN notice before a mass layoff or plant closing. These are every notice in the Illinois DCEO monthly reports since 2020, loaded fresh by the pipeline.
| Company | Notices | Employees affected | Latest notice |
|---|
| County | Notices | Employees affected |
|---|
Every source carries its licence and what was filtered out before anything left the publisher. A licence I could not verify is labelled as such rather than assumed.
| Source | Basis | Filters applied at ingest | Last load |
|---|
verified licence read on the publisher's own page · owner decision no licence published; my judgement, recorded as such · unverified no licence found yet
The platform is composed from Retool's official Terraform modules for Azure. Reviewing every plan before applying it caught three defects in them, each patched in a vendored copy, with the proof written down and a note to drop the patch when upstream fixes it: