The big one. We had four separate apps - admin, home, diver, forms - and a fifth service surface, each its own deploy, each with its own copy of the auth dance, each a place for the cookie to get lost between subdomains. It was death by a thousand redirects. So we folded all of it into one host-routed app that serves admin., diver., forms., service., and the marketing site by looking at the hostname.
We also ripped Neon Auth out entirely mid-merge and made the Firebase __session cookie the only auth in the building. If you want to know how that went, there is a commit note that just says "Firebase env fix for the login loop" - that was a morning spent watching users bounce between sign-in and the app forever because one environment variable disagreed with another. Merges are where you find out how many assumptions you had quietly hardcoded.
Shipped
- Merged admin / home / diver / forms / service into one app (Phases 0-5), routed by domain
- Stripped Neon Auth; Firebase __session is now the sole auth mechanism
- Diver Portal v3: a full editorial redesign, re-skinned screen by screen - dashboard, dive-log, certs, travel, service, calendar, enrollments, rentals, training, feed, the works
- A whole shop marketing engine in the API: asset library, AI captioning, a drip planner, Meta/Google connections, audience segments, mass broadcasts, tracked links
- Automated the DAN insurance enrollment we had been doing by hand - new class enrollees now get swept in automatically (and yes, I had to tune the batch size down twice to fit under a 60-second function ceiling - the first version was too greedy and kept timing out)
- First commits of plunkx-platform and plunkx-public - the multi-tenant product, out loud now
- Kept the merged app's serverless bundles under Vercel's 250 MB limit, which is its own dark art