For a more mature implementation of this concept, I would highly recommend having a look at Kore: https://kore.io
It has a sane architecture, and is fully privilege separated by default, with private keys isolated in a separate process. I've been using it lately to write REST APIs in C, and the experience has been awesome, it has great APIs to parse requests and easily construct responses.
It seems I cannot post a comment on your blog without being registered on Google+, so answering here instead.
I enjoy reading your articles on OpenBSD and would indeed appreciate it if you would move the content to your own server, as the blogspot cookies notification banner is pretty irritating :)
Indeed, there was no site configured on logswan.org when this was posted to HN. I made the required changes but due to the nature of DNS, it'll still return NXDOMAIN for some users until caches are cleared.