The first day: Z Route Academy went from an Astro starter template to a launched site in ten build phases.

Foundation (Phases 01-06)

  • Information architecture, navigation, layouts, and site metadata for the whole public knowledge base.
  • A field-guide design system: verification-status badges, card and callout components, and a distinct dark theme for the private alliance area.
  • The core content collections — guides, heroes, events, glossary — with schema validation. Every entry started as an honest NEEDS_VERIFICATION stub rather than invented content, per this site’s accuracy rule.
  • A build-time search index with vanilla-JS scored client-side search — no hosted search service.
  • Discord OAuth login (PKCE + CSRF state) with D1-backed sessions, authorization checks, and the private NexS Command Center behind auth-gated routes. The site switched to hybrid rendering so the private area runs per-request while the public knowledge base stays static.

Interactive tools, and the TOZ → NexS rename

The HQ/Base Upgrade Planner, Resource Calculator, Shard Calculator, and Command Calculator arrived as Phase 07 — each one honestly reporting “no data yet” rather than guessing where real numbers weren’t available yet.

The alliance itself was renamed [TOZ] TerminateOnSite → [NexS] NeXuS the same day, done cleanly since nothing was in production yet: routes moved from /toz/* to /nexs/*, and every matching code identifier (TozPageLayout, isTozFamily, TOZ_FAMILY_ALLIANCES, and so on) was renamed to match.

A tactical redesign

The site’s visual language shifted from a light “field guide” look to a dark, tactical, post-apocalyptic-survival aesthetic — new color tokens, a self-hosted display font for headings, and an intensified theme for the NexS Command Center. The homepage hero picked up HUD-style corner brackets and a large low-opacity typographic “Z,” built entirely in CSS with no image assets.

A real correction workflow

Rather than an open-edit wiki, Phase 08 added a curated correction queue: a public /contribute/ form (linked from every article’s “Suggest a Correction” button, pre-filled with the page you were reading), a hidden honeypot and rate limiting for abuse protection, and a private review screen gated to R4+ alliance officers. Accepting a submission never touches content files automatically — a person still has to make the edit.

SEO, security, accessibility, analytics

Phase 09 covered a lot of ground in one pass: JSON-LD structured data, a dynamic robots.txt that can’t drift out of sync with the sitemap, noindex on every private route as a third independent layer of protection, a missing font preload fixed, tuned cache headers, an ARIA anti-pattern fixed in the mobile nav, all 14 database queries audited as fully parameterized, added Strict-Transport-Security and Permissions-Policy headers, and cookie-free, PII-free analytics via Cloudflare’s own Analytics Engine. The production domain (zroute.dev) was registered and wired up the same day.

Launch audit

Phase 10 closed out the day with a final audit: custom 404/500 pages, a mobile logout-button fix, and a re-verification of the public/private content separation, search accuracy, database migration state, and security headers. No launch blockers were found.

An R5-gated admin page for managing member alliance/rank/cabinet assignments shipped the same day, closing out launch day’s work.