Alumni United 2026
Next.js, Tech lead•2025–2026
Alumni United 2026 is @america's one-day conference (the U.S. Embassy Jakarta's American cultural center, hosting Indonesian alumni of U.S. universities and exchange programs), and its date could not move.
A team of three developers went from an empty repository to event day in 141 days: registration opened 25 days before the event, session selection three days before, and on the Saturday itself staff checked nearly a thousand people through 23 QR points with no second chance.

Everything converged on one Saturday.
The event date (11 April 2026, venue capacity 800) was immovable. Every piece of the system had a deadline counted backwards from it: pre-registration, email-OTP accounts, breakout-session selection across 22 sessions with per-session capacity, QR tickets, and a mobile admin area for the staff working the doors.
The client is high-profile, so abuse protection had to be in place before public registration launched, not patched in after an incident. Attendees pick exactly one session per time block, which the interface had to make impossible to get wrong. And event-day operations are entirely mobile: staff scanning QR codes at a venue entrance and 22 session doors, in a hurry.
Thirteen rounds of client revisions landed between December and February, each one shipping without destabilising the release train. And the site had to outlive the event, converting cleanly into a static archive instead of rotting as a half-alive app.


Protection before launch, releases on rails.
- AServer-side API proxy with secret injection
One catch-all route handler runs rate limiting and captcha scoring, then forwards with a server-only secret header; backend and captcha secrets never reach the browser, and a backend 401 forces logout. Tokens live in httpOnly, secure, same-site-strict cookies read via server actions.
- BAbuse protection before launch, fail-open
Tiered per-IP, per-path Redis rate limiting (four tiers, registration on the strictest) plus reCAPTCHA Enterprise scoring on abuse-prone endpoints, added preemptively rather than after an incident. A Redis outage can't take registration down: the limiter fails open, trading strict enforcement for availability.
- CFlow state lives in the URL
The registration and email-OTP flow carries its state in URL parameters: the OTP link auto-submits, refresh is safe, and the resend timer holds. Session selection keeps its dialog state in the URL too, so a specific session is linkable. A client store would have died on refresh mid-registration.
- DAdmin tools built for a queue
The QR scanner requests maximum camera resolution, offers auto and confirm modes, blocks re-scans and plays success and error sounds, so staff working a queue listen rather than look at the screen. Behind it: a 13-column guest table with server-driven pagination and search bound to URL parameters, per-session capacity bars, CSV export and role-gated blast email.
- EA release train, then a freeze
Features flow through a staging branch that auto-deploys to Cloud Run with keyless workload-identity auth and SHA-tagged images; production deploys only from tagged releases, 42 of them. Each of the 13 client revision rounds was one pull request with a same-day tagged release. After the event, the dynamic route groups redirect home, leaving a clean static archive.

Three developers, one contract.
- A generated API contract. The backend's OpenAPI spec is vendored in the frontend repository and regenerated with Kubb in one script. Eleven schema-sync commits track backend changes; the three-developer contract never drifted.
- One session per time block. The selection interface enforces exactly one choice per block across 22 sessions, with per-session capacity, so the rule lives in the flow rather than in an error message.
- Infrastructure from zero. Cloud Run, Artifact Registry and workload identity federation on GCP, Redis, a Cloudflare-fronted asset bucket, reCAPTCHA Enterprise and the Vercel project were all provisioned as part of the build.


The day it was built for worked.
On event day, the venue entrance and all 22 session doors ran on the QR system: 1,046 check-ins across 23 scan points, from 850 accounts registered through the OTP flow. Two days before the event, the site's peak day saw 751 users with an average engagement of 140 seconds per active user.
Registration shipped 25 days before the event and session selection three days before; both held. The site now lives on as a static archive of the event.
Delivered through Noosa, where the same team ships its own ticketing product.
- Year2025–2026
- IndustryConference platform
- Client@america · delivered through Noosa
- RoleTech lead · team of 3 devs
- Scope of work/ Frontend / Platform / Infrastructure / CI/CD
- StackNext.js · TypeScript · Tailwind CSS · TanStack Query · Redis · reCAPTCHA · Kubb · GitHub Actions · GCP Cloud Run