... is not an API. There's no authentication, cookies, transactions, client-side scripts, or PHP. No dynamic content is generated in response to HTTP requests. It is rather generated in response to back-end events, such as pushing a new version of a package into the package repository, which cause reconstruction of the content with redo, a simple rebuild tool. So the server software itself is a simple static HTTP server. It's a slightly improved version of Daniel J. Bernstein's publicfile, in fact.
... does not put server logs, server scripts, or anything else like those in the content tree. The only things in the content tree are content files and directories. Indeed, the content server daemon runs as one user and its logger daemon runs as another, which owns the log files with only access to their owner.
... has strictly size-capped, auto-rotated, logs with the log writer doing the rotation. There's no logrotate window of opportunity for exceeding the log size. (http://jdebp.eu./FGA/do-not-use-logrotate.html) The logs are also completely independent from other non-server logs.
... runs on a dedicated machine that does not have other, non-public, services. There's no unnecessary MySQL server running on it, for example. Nor a mail system.
... is also mirrored over FTP and GOPHER. The FTP server is again an improved version of Daniel J. Bernstein's publicfile, and the GOPHER server is my addition to the same. They don't implement non-anonymous FTP, FTP uploads or filesystem modifications of any sort, or GOPHER searches, and work from (solely) the same content tree as the HTTP server. The GOPHER menus are built by the content rebuild subsystem, not by the GOPHER server.