Skip to content

Alumni United 2026

Next.js, Tech lead•2025–2026

Alumni United 2026 is @america's one-day conference (the U.S. Embassy Jakarta's American cultural center, hosting Indonesian alumni of U.S. universities and exchange programs), and its date could not move.

A team of three developers went from an empty repository to event day in 141 days: registration opened 25 days before the event, session selection three days before, and on the Saturday itself staff checked nearly a thousand people through 23 QR points with no second chance.

Alumni United 2026: landing page
Challenge

Everything converged on one Saturday.

The event date (11 April 2026, venue capacity 800) was immovable. Every piece of the system had a deadline counted backwards from it: pre-registration, email-OTP accounts, breakout-session selection across 22 sessions with per-session capacity, QR tickets, and a mobile admin area for the staff working the doors.

The client is high-profile, so abuse protection had to be in place before public registration launched, not patched in after an incident. Attendees pick exactly one session per time block, which the interface had to make impossible to get wrong. And event-day operations are entirely mobile: staff scanning QR codes at a venue entrance and 22 session doors, in a hurry.

Thirteen rounds of client revisions landed between December and February, each one shipping without destabilising the release train. And the site had to outlive the event, converting cleanly into a static archive instead of rotting as a half-alive app.

1,046
QR check-ins in one day
141
Days, empty repo → event day
5,803
Site users, Jan–Sep 2026
1,052
Pre-registrations captured
Landing page: the conference introduction
Landing page: the conference introduction
Road to the conference: launch, regional events, event day
Road to the conference: launch, regional events, event day
Approach

Protection before launch, releases on rails.

  • A
    Server-side API proxy with secret injection

    One catch-all route handler runs rate limiting and captcha scoring, then forwards with a server-only secret header; backend and captcha secrets never reach the browser, and a backend 401 forces logout. Tokens live in httpOnly, secure, same-site-strict cookies read via server actions.

  • B
    Abuse protection before launch, fail-open

    Tiered per-IP, per-path Redis rate limiting (four tiers, registration on the strictest) plus reCAPTCHA Enterprise scoring on abuse-prone endpoints, added preemptively rather than after an incident. A Redis outage can't take registration down: the limiter fails open, trading strict enforcement for availability.

  • C
    Flow state lives in the URL

    The registration and email-OTP flow carries its state in URL parameters: the OTP link auto-submits, refresh is safe, and the resend timer holds. Session selection keeps its dialog state in the URL too, so a specific session is linkable. A client store would have died on refresh mid-registration.

  • D
    Admin tools built for a queue

    The QR scanner requests maximum camera resolution, offers auto and confirm modes, blocks re-scans and plays success and error sounds, so staff working a queue listen rather than look at the screen. Behind it: a 13-column guest table with server-driven pagination and search bound to URL parameters, per-session capacity bars, CSV export and role-gated blast email.

  • E
    A release train, then a freeze

    Features flow through a staging branch that auto-deploys to Cloud Run with keyless workload-identity auth and SHA-tagged images; production deploys only from tagged releases, 42 of them. Each of the 13 client revision rounds was one pull request with a same-day tagged release. After the event, the dynamic route groups redirect home, leaving a clean static archive.

Mobile: landing, about and a regional-event recap
Mobile: landing, about and a regional-event recap
Details

Three developers, one contract.

  • A generated API contract. The backend's OpenAPI spec is vendored in the frontend repository and regenerated with Kubb in one script. Eleven schema-sync commits track backend changes; the three-developer contract never drifted.
  • One session per time block. The selection interface enforces exactly one choice per block across 22 sessions, with per-session capacity, so the rule lives in the flow rather than in an error message.
  • Infrastructure from zero. Cloud Run, Artifact Registry and workload identity federation on GCP, Redis, a Cloudflare-fronted asset bucket, reCAPTCHA Enterprise and the Vercel project were all provisioned as part of the build.
Speakers and moderators
Speakers and moderators
FAQ: registration questions answered on the page
FAQ: registration questions answered on the page
Outcome

The day it was built for worked.

On event day, the venue entrance and all 22 session doors ran on the QR system: 1,046 check-ins across 23 scan points, from 850 accounts registered through the OTP flow. Two days before the event, the site's peak day saw 751 users with an average engagement of 140 seconds per active user.

Registration shipped 25 days before the event and session selection three days before; both held. The site now lives on as a static archive of the event.

Delivered through Noosa, where the same team ships its own ticketing product.

  • Year2025–2026
  • IndustryConference platform
  • Client@america · delivered through Noosa
  • RoleTech lead · team of 3 devs
  • Scope of work/ Frontend / Platform / Infrastructure / CI/CD
  • StackNext.js · TypeScript · Tailwind CSS · TanStack Query · Redis · reCAPTCHA · Kubb · GitHub Actions · GCP Cloud Run
Elian Richard