WORK / SYS-03: FLEXZONE
PRODUCTION DEPLOYMENT OPERATIONS & ACCESS CONTROL 2024 — 2026

Flexzone

End-to-end fitness center operations platform managing multi-branch memberships, automated Xendit payment billing, and an asynchronous QR scanning kiosk bridge linking mobile phone scanners to front-desk attendance hardware.

ROLE
Full-Stack Systems Architect & Developer
STACK (V1 PRODUCTION)
PHP 8.x Monolith · MySQL · Xendit
HARDWARE BRIDGE
Cross-Device QR Attendance Kiosk
CLIENT CONTEXT
Commercial Fitness Centers
01 / ARCHITECTURAL EVOLUTION

V1 Monolithic Production vs. V2 Redesign Concept

SOURCE CODE VERIFIED GROUND TRUTH

The verified, battle-tested production system deployed in commercial facilities is Flexzone V1.0: a high-efficiency PHP 8.x and MySQL monolith with custom session isolation, Xendit webhook billing, and the file-mutexed mobile scanner bridge.

*Note on Architectural Trajectory:* A proposed V2 multi-tier rewrite incorporating Laravel microservices, React frontends, and Java desktop runtimes represents a forward-looking architectural redesign concept, while V1 remains the operational production baseline.

02 / PHYSICAL FACILITY BOTTLENECKS

The Front-Desk Bottleneck & Access Contention

Gyms and commercial fitness centers face intense front-desk congestion during morning and evening rush hours. Members queue to check in manually, staff spend valuable time cross-referencing paper logs or expired membership cards, and unverified visitors slip through unnoticed.

Commercial turnstiles with integrated proprietary optical hardware cost thousands of dollars per lane—an impractical capital expenditure for independent gyms and growing branch franchises.

03 / ENGINEERING DEEP-DIVE

The Asynchronous QR Kiosk Hardware Bridge

To deliver sub-second, contactless check-ins at zero incremental hardware cost, I engineered a cross-device scanner bridge. Any staff smartphone or mounted budget tablet acts as an optical scanning sensor, while the front-desk workstation acts as the authoritative verification terminal:

HARDWARE I/O TOPOLOGY // ZERO-COST KIOSK BRIDGE

Cross-Device Optical Scanner & Atomic Mutex Queue

Mobile HTML5 Camera Sensor → flock(LOCK_EX) Serialized Queue → Sub-200ms Front-Desk Terminal Polling → MySQL InnoDB Verification

01 / OPTICAL INGRESS
MOBILE SENSOR
HTML5-QRCode
Mounted smartphone / budget tablet camera feed
PAYLOAD INGRESS
HTTP POST
Token & microsecond client timestamp stream
02 / ATOMIC MUTEX ● ATOMIC
FILE LOCK STREAM
flock(LOCK_EX)
Non-blocking serialization prevents concurrent write corruption
PERSISTENT BUFFER
pending_scans.json
In-memory / SSD atomic rewrite with ftruncate()
03 / FRONT-DESK LOOP
EVENT POLLER
Sub-200ms Cycle
Local desk terminal queries serialized queue
AUDIO / VISUAL
Chime & Profile Flash
Instant member photo & subscription badge rendering
04 / DB VERIFICATION
STATE ENGINE
MySQL InnoDB
Active / Expired validity check with branch scoping
AUDIT LOGGING
Attendance Table
Timestamped immutable check-in ledger
● SUB-SECOND VERIFY
CROSS-DEVICE SCANNER QUEUE BRIDGE (Atomic flock Mutex)
// Asynchronous mobile scanner bridge writer (api_submit_scan.php)
$token = trim($_POST['member_token'] ?? '');
$queueFile = __DIR__ . '/storage/pending_scans.json';

// Open file with exclusive lock to prevent read/write corruption
$fp = fopen($queueFile, 'c+');
if ($fp && flock($fp, LOCK_EX)) {
    $content = stream_get_contents($fp);
    $queue = !empty($content) ? json_decode($content, true) : [];

    // Push new scan entry with microsecond timestamp
    $queue[] = [
        'token'     => $token,
        'timestamp' => microtime(true),
        'device'    => $_SERVER['REMOTE_ADDR']
    ];

    // Truncate and rewrite atomically
    ftruncate($fp, 0);
    rewind($fp);
    fwrite($fp, json_encode($queue));
    fflush($fp);
    flock($fp, LOCK_UN);
}
if ($fp) fclose($fp);
FRONT-DESK VERIFICATION DISPATCH

The front-desk console polls the atomic scan queue in sub-200ms cycles. Upon detecting a new token, it queries the MySQL membership state engine, flashes the member profile and photo, emits an audible chime, and records the timestamped attendance log.

04 / LIFECYCLE GOVERNANCE

Deterministic Membership State Engine

Subscriptions transition through a deterministic finite state machine to prevent revenue leakage and expired access:

1. REGISTRATION & PLAN SELECTION
Prospective member registers; record enters PENDING_PAYMENT status.
2. XENDIT PAYMENT SETTLEMENT
User pays via digital wallet/card. Idempotent webhook receiver validates signature, transitions status to ACTIVE, and dispatches dynamic QR pass.
3. EXPIRY WARNING & AUTOMATED RENEWAL
Automated sweep flags accounts 7 days prior to expiration (EXPIRING), sending email payment links via PHPMailer.
4. ACCESS SUSPENSION
Unrenewed accounts transition to EXPIRED, immediately denying entry at the QR kiosk with visual on-screen alerts.
SPECIFICATION SUMMARY
Engine: PHP 8.x Monolith
Database: MySQL (15+ Tables)
Payment: Xendit API (^7.0)
Scanner: HTML5-QRCode Bridge
Tunneling: Cloudflare Tunnel
Version: 1.0 Production Ready
NEXT SYSTEM BRIEF

BayanLink

Multi-tenant civic operations platform in Turborepo with Next.js 15, NestJS, and Socket.IO.

VIEW BAYANLINK →