Skip to content

Secure applications & operations

FRC 1086 Team Portal

A managed operations platform for FIRST robotics teams

I built TeamPortal to connect member operations, access management, and sensitive-record handling for robotics teams. The managed platform gives each team its own deployment and databases, with Discord, Google Workspace, and calendar integrations supporting day-to-day operations.

TeamPortalProject overview
  • PeopleMember workflowsOnboarding · activities · records
  • ApplicationAccess & dataPermissions · encryption
  • ConnectionsTeam servicesDiscord · Google Workspace
Member workflows, application-owned permissions, and connected team services.
My role
Lead Software Engineer
Period
Dec 2025 – Present
Platforms
Web / API
Status
active

Tools & technologies

ViteReactTypeScriptTanStack RouterTanStack QueryZustandTailwind CSSHono

FULL_STACK (40)

ViteReactTypeScriptTanStack RouterTanStack QueryZustandTailwind CSSHonoDrizzle ORMBetter AuthCloudflare PagesCloudflare WorkersCloudflare D1Cloudflare ContainersVitestWranglerreact-markdownLucide ReactESLintMermaidKaTeXopentype.jsresvgqrcodesql.jscmdkreact-easy-croplinkedomTiptapSimpleWebAuthnDevSecOpsSystems IntegrationAutomationCloud SecurityCI/CDGitHub ActionsPlaywrightGoogle Workspace APIDockerCloudflare

Impact & Results

  • Delivered an application grounded in the operational needs of a 100+ member nonprofit.
  • Established a repeatable product architecture with distinct team identity, data, configuration, and integrations.
  • Connected member operations and access management within a shared application model.
  • Made the product available to explore through a public demo using fictional records.

Overview

TeamPortal is a managed operations platform for FIRST robotics teams. I designed and built it around the work of keeping a team running: onboarding members, managing access, coordinating activities, and protecting student and mentor records. Blue Cheese Robotics, a 100+ member nonprofit where I lead IT operations, is the flagship deployment.

The platform supports multiple teams through separate Cloudflare deployments, databases, authentication secrets, and configuration. Shared storage uses tenant-specific prefixes. Its integrations connect Discord, Google Workspace, calendars, and competition data to portal workflows, while the application remains responsible for its own permissions.

A separate public demo uses fictional team data in browser-local SQLite. It demonstrates the product without connecting visitors to a production tenant.

Role Summary

  • Owned requirements, architecture, implementation, and operational support as lead software engineer and platform architect.
  • Used my work leading Blue Cheese Robotics IT to identify recurring onboarding, permissions, and member-record problems.
  • Designed cross-cutting authorization, integration, and release workflows alongside the member-facing features.

Non-Technical Summary

Robotics teams need more than a website: they need reliable ways to bring people onboard, coordinate activities, and handle records responsibly. TeamPortal brings these workflows together in a configurable application.

Blue Cheese Robotics is the first deployment. The product separates each team's identity and infrastructure so that other teams can adopt it without inheriting Blue Cheese-specific settings or records.

Highlights

  • Designed and shipped a member operations platform, connecting nonprofit IT requirements to application architecture, deployment, and ongoing support.
  • Built server-owned, default-deny permissions and separate encryption boundaries for medical and other sensitive member data.
  • Integrated Discord and Google Workspace workflows with the portal's roster and access model.
  • Evolved a single-team application into a managed platform with separate deployments, databases, and configuration for each team.

Quick Highlights

  • Managed tenancy with separate team deployments and databases.
  • Default-deny permissions, field-level encryption, and separately keyed medical records.
  • Discord, Google Workspace, calendar, and competition-data integrations.
  • Automated delivery checks and a fictional-data public demo.

Technical Breakdown

The frontend uses React, TypeScript, Vite, and TanStack Router. A Hono API runs on Cloudflare Workers with D1 databases through Drizzle, R2 storage, and Better Auth sign-in.

Server-owned permission and module registries centralize access decisions and feature availability. Medical records use a separate database and encryption key; other sensitive fields have their own encryption boundary. Audit records support investigation and operational visibility.

External services are integrated through application-owned workflows. Discord identity linking and roster reconciliation connect communication roles to membership; Google Workspace and calendar integrations support team operations. Delivery workflows include security scanning, dependency checks, artifact checks, and deployment gates.

Systems Used

  • React, TypeScript, Vite, TanStack Router, and Hono.
  • Cloudflare Workers, D1, R2, Drizzle ORM, and Better Auth.
  • Discord, Google Workspace and Calendar, and The Blue Alliance.
  • GitHub Actions, Vitest, Playwright, and security checks.
  • Browser-local SQLite through sql.js for the public demo.

Deep Dive

The central architectural decision was to make a team's deployment the main tenancy boundary. Provisioning uses a validated manifest to generate configuration and a secrets checklist. Teams receive distinct databases and secrets; prefixes separate the storage resources that remain shared.

Authorization stays with the application even when an external service participates in a workflow. Discord roles and Workspace integrations support operations, but do not replace the portal's permission model.

The public demo has a separate purpose and execution model: fictional records in browser-local SQLite, without a production tenant connection. This allows a visitor to explore workflows while preserving the distinction between demonstration and live operations.


KEYBOARD_SHORTCUTS

GO_TO

  • g h TERMINAL
  • g p PROJECT_INDEX
  • g e EXPERIMENTS
  • g s SKILL_MATRIX
  • g a ABOUT_ME
  • g r EXPERIENCE

GLOBAL

  • ⌘K COMMAND_PALETTE
  • / COMMAND_PALETTE
  • ` TERMINAL_MODE
  • ? SHORTCUT_PANEL
  • ESC CLOSE_OVERLAY

Chords expire after 1 second. Keys are ignored while typing.