Home

How It’s Built

Web App

Surrealdente, LLC is a one-person software company in Kansas. It builds and operates RPGLMS, a learning platform that turns a course into a tabletop-style campaign.

This page is the technical record: what runs in production, and why it is built that way. It was written by the founder, who built all of it, and checked against the source on 2026-09-23. The product story is on About.

The stack

  • Client: one Flutter codebase for the web, iOS and Android, with Rive for the animated characters and creatures.
  • Server: Serverpod 4 (Dart), in a slim Debian container on Cloud Run.
  • Database: PostgreSQL 17 on Cloud SQL.
  • AI: Gemini on Vertex AI.

Google Cloud in production

Two projects, staging and production, both in us-central1. The same Terraform defines both, so staging is a real rehearsal for production.

Cloud Run
Two services: the Serverpod API, and a separate internal-only AI worker that runs long course generations (30-minute timeout) so they never tie up the API.
Cloud Run Jobs
Database migrations, run as a job on every deploy.
Cloud Tasks
The queue that hands AI generations from the API to the worker, authenticated with OIDC tokens rather than a shared secret.
Cloud Functions (2nd gen)
The webhook receiver for subscription events (via RevenueCat).
Cloud SQL for PostgreSQL 17
The database, reached over private service access, with daily backups kept for 30 days.
Cloud Storage
Private user uploads served through signed URLs, plus the static buckets for the web app and the websites.
Cloud Load Balancing + Cloud CDN
One global HTTPS load balancer with a managed certificate; the web app and sites are served through the CDN.
VPC + Cloud NAT
Cloud Run reaches the database over Direct VPC egress; outbound traffic leaves through Cloud NAT.
Secret Manager
Runtime secrets, with access granted per service account.
Artifact Registry
The container images Cloud Run deploys.
Cloud Logging, Monitoring, Trace, Error Reporting
Log-based metrics, eleven alert policies and a dashboard, all defined in Terraform.
Vertex AI
Gemini, for course generation and illustration (below).

Deploys and access

  • No service-account keys. GitHub Actions authenticates to Google Cloud through Workload Identity Federation, bound to the app’s repository and to specific workflows and branches. Key creation is switched off by organization policy on both projects, so a key can't be made by mistake.
  • Infrastructure as code. Networking, services, the database, queues, buckets, IAM and alerting are Terraform. Secret values are the one thing set by hand, so they never pass through a repository.

The AI authoring pipeline

The AI Wizard turns a teacher’s description of a course, and any sources they attach, into a structured course: campaigns, paths, lessons, quizzes and illustrations. The teacher can revise every piece afterward.

  • Models: gemini-3.8-flash for text,gemini-3.1-flash-image and gemini-3-pro-imagefor illustration, all on Vertex AI (as of 2026-09-23).
  • Segmented generation. A course is generated in segments that run in parallel, not as one long request. Each segment gets its own thinking depth, so simple parts cost less and come back sooner.
  • A five-step parse. Model output is extracted, decoded (including recovering a response cut off at the token limit), cleaned, checked for coherence, transformed, and only then parsed into typed database models.
  • Off the request path. Long generations go through Cloud Tasks to the AI worker, so the API stays responsive while a course is being written.
  • Cost and failure limits. A token-bucket rate limiter and a circuit breaker sit in front of Vertex AI. Every call has a hard timeout and a per-segment output cap, and a loop detector stops a runaway response. Every call is metered against the account’s monthly token grant.
  • Retention. The content of AI request logs is deleted after 90 days.

Students and their data

  • Answer keys stay on the server. Before a quiz reaches a student, the correct answers are removed and replaced with SHA-256 hashes, so the key can’t be read from the browser’s network tab. The server then grades every answer again itself, and only its result counts.
  • 13 and over. Sign-up opens with a neutral date-of-birth question. An answer under 13 ends sign-up without creating an account.
  • Deletion is real. Deleting an account from inside the app removes the sign-in and ends every session, anonymizes the player record and deletes the avatar, all in one database transaction. How to delete an account.
DocsAboutPedagogyHow It’s BuiltPricingGalleryTerms of ServicePrivacy PolicyDelete AccountFAQSupport

Surrealdente, LLC is a one-person software company in Kansas. It builds and operates RPGLMS, a learning platform that turns a course into a tabletop-style campaign.

© 2026 Surrealdente, LLC. All rights reserved.