15 Years, One Codebase: A Forensic Map of Spotlight Home Tours and Social Compass
Part 1 of an eight-part series on my tenure as lead developer at Spotlight Media Group (also known as Spotlight Home Tours). If you read the Prestige Men's Health series, this is the same idea applied to a much older system. How the research was done is covered in How These Posts Were Written — and How You Can Verify Them, with one important difference that I explain below.
I spent about fifteen years as lead developer for a Salt Lake City company that started out selling photo, video, and virtual-tour packages to real estate agents and ended up shipping a social media management product, Social Compass, to businesses in any industry. The platform that ran all of it was one codebase that never got a clean rewrite. It just kept growing.
This post is the map. The later posts go deep on individual systems: photo processing and S3, video, long-running jobs, MLS data, the Social Compass scheduler, and the social network APIs. This one answers three questions first: what the business was, what the codebase looks like after fifteen years, and how I can tell any of that from the artifact alone.
Why this series reads differently from the Prestige one
The Prestige series was built on a real commit history: every dated claim traced back to a commit message, author, and timestamp. I can't do that here, and I'd rather say so up front.
The Spotlight repository has 49 commits. All of them are from 2026-09-28 to 2026-10-08. They record the migration of the production site into git, and then the work of getting it to run again in a clean environment. The earliest commits are bulk imports ("Migrate production website … 53883 files"), and the rest are fixes. The fifteen years before that lived on a production server, in an SVN-then-git workflow (the repo's own old README says "Git repo setup on 9/2/2014"), and in hosting providers that have since changed.
So this series is forensic reconstruction from the artifact, not commit-level history. The evidence I'm using instead:
Authorship headers. Roughly 160 of the ~290 top-level
class.*.phpfiles in the shared library carry my name in an@authortag. Other files name other developers (more on that below).Dated comments and file names. Examples: a 2011 creation date on the photo-zip script, a 2015 date on the S3 zip-queue class, and backups suffixed
_20_Sept_2016.Layered SDKs and parallel class versions.
awss3next toawss3v3, three generations of LinkedIn integration side by side,retsmd/PHRETS next to a later RESO client. The code carries its own geological strata.Data volumes. The bundled database exports show the platform's scale directly.
Public web properties. The company's own site says "Over the past decade Spotlight Home Tours has been the trusted name for photography, video production and marketing solutions," and that the Social Compass platform was rolled out beginning in 2018.
Where I put an era on a date, I'll say whether it's from a header, a file name, or my own recollection checked against the code. If the evidence is thin, the post will say so.
One more thing worth saying plainly, because it shapes how to read everything that follows: every line of this platform before 2026 was written by hand, before AI coding tools existed. That is why it looks the way it does: fifteen years of pragmatic decisions, several developers, no test suite. AI shows up only in the 2026 move to Ubuntu. Where later posts have a section on how I'd approach a problem with AI today, it's a forward-looking view of the same code, not a description of how it was built.
Two other ground rules, same as before:
Code shown in these posts is illustrative. The repository is private. I'll describe patterns and show short reconstructions of their shape, labeled as such, and I won't paste proprietary source.
No credentials, customer names, or financials. The code contains things that never should have been committed (that's a legitimate post-mortem topic in its own right, but I won't describe specifics here).
The business, in one paragraph
Spotlight sold a tour: a bundle of still photos, panoramas, video, floor plans, and a branded web presentation for a single property listing. Photographers shot the property, uploads came in through the web, the platform processed the media, and the agent got a shareable tour page, downloadable photo sets at several resolutions, a video player, and marketing extras like brochures and syndication to listing sites. Brokerages and teams bought in bulk; agents paid per tour or by membership. Later, the same platform grew a self-serve marketing layer (Social Hub, then Social Compass, then a "Concierge" tier of done-for-you marketing) and an affiliate/partner program with training content.
Everything hard in this system follows from that: lots of large media files, from many untrusted uploaders, processed asynchronously, stored cheaply, and served fast, tied to a catalog of orders, payments, and MLS listing data.
The shape of the codebase today
A read-only audit I wrote while standing the environment back up gave me real numbers rather than impressions:
About 7.6 million lines of PHP in roughly 30,800 files, of which 79% is vendored third-party code: four WordPress installs, the AWS SDK, Zend, SimpleSAMLphp, QuickBooks, Authorize.net, SwiftMailer, and others.
About 1.58 million lines of first-party legacy PHP in ~7,150 files.
About 45,000 lines of Laravel 8 across two newer applications.
Around 600 ColdFusion (CFML) files, which is why the stack still needs a Lucee runtime, and why three PHP versions have to coexist (the legacy tree uses removed functions like
ereg,each, andmcrypt_*; the Laravel portal's lockfile needs PHP 8; Moodle wants 7.4).A Node 12 MLS/RESO sync service and a Moodle 3.11 LMS for affiliate training.
A production database holding, in the exports I worked with, roughly 126,000 tours, 135,000 orders, and 45,000 users.
The headline is that "the legacy codebase" is not 7.6 million lines. It is about 1.5 million, surrounded by a lot of other people's code. That distinction matters for any modernization plan, and it matters for how I talk about what I built versus what I inherited or integrated.
The architectural evolution, era by era
These are approximate eras, reconstructed from the code. Boundaries are fuzzy because most systems were never fully replaced.
Era 1 — The Windows/IIS monolith (earliest code I can date: 2011)
The foundation was ColdFusion plus procedural PHP, running on Windows under IIS. The evidence is hard to miss once you look:
A background-task helper that launched PHP scripts by shelling out through Windows COM (
WScript.Shell), with hardcodedD:\websites\...paths andphp.exelocations.Per-agent subdomains provisioned by calling IIS's
appcmdto create a site binding and a physical directory per agent.Video processing that wrote
ffmpegcommands into a generated.batfile, then executed it.Host detection by literal hostname (
is318(),is342()) to tell two production servers apart.
Early video delivery was RTMP with SMIL manifests for bitrate selection, which is Flash-era adaptive streaming. The 2011 header on the photo-zip script (written by another developer on the team, not me) tells me tours were already being processed this way by then.
Lesson I carry from this era: when there is no job queue, your database and your filesystem become the queue. That's survivable, but it shapes everything you do about reliability afterward (post 4).
Era 2 — Offloading to AWS (roughly 2014–2017)
Media got too big for the web server's disks. The code shows a clear migration to AWS:
An S3 bucket for tour media, with uploads defaulting to long-lived cache headers.
Glacier for tour archives.
A queue-table-driven zip-file builder for downloadable photo sets at multiple widths (a 2015 header names the developer who wrote it). It later got its own dedicated EC2 server, because it was consuming too much of the main server's resources.
CloudFront for streaming.
HLS video, from about 2016, produced by a fully custom ffmpeg setup on the Windows host (managed AWS transcoding came much later; see Era 4).
This is also the era where the integration surface exploded: a dozen-plus MLS-board adapter classes, PHRETS and then RESO clients, listing syndication, several payment gateways over time (Authorize.net, Payeezy/First Data, Stripe, Square), and CRM/marketing integrations such as Infusionsoft, LionDesk, and QuickBooks.
Era 3 — Social Hub becomes Social Compass (2018 onward)
"Social Hub" began as a way to auto-post a finished tour to an agent's social accounts. The public company page dates the Social Compass rollout to 2018, and the code shows the product widening:
A scheduling queue with a calendar, per-network settings, and approval ("proof") emails.
A content library with categories, so a member could post curated content, not just their own listings.
A branded redirect page so clicks land on the member's brand, not a third party's.
Compass Create, a DIY graphic design tool.
A Cordova/Framework7 iOS app that wrapped the same backend (the compiled app bundle is in the repo).
Support for Facebook, Twitter, LinkedIn (three separate generations of integration code), Pinterest, Google+, Blogger, YouTube, and Instagram, each with different authentication, posting, and failure behavior.
This is the part of the story most relevant if you build on top of third-party platform APIs, and it gets two full posts (6 and 7).
Era 4 — Laravel beside the monolith (2021–2022)
Rather than rewrite the monolith, new work went into a Laravel 8 affiliate portal (with Livewire), a Laravel training-admin app, a Moodle LMS for affiliate training, a third-party site builder, and a Node-based MLS sync service. Around 2022, video processing also moved off the custom ffmpeg setup and onto AWS-managed transcoding, with a distinct S3 prefix for the 2022 output that the playback code has to check alongside the older one.
The result is a "strangler fig" with no clear strangling date: new services stand next to old ones and share a database.
Era 5 — 2026: moving a Windows platform to Ubuntu, with AI assistance
I stopped working on the platform day to day in 2022. In 2026 I took a small, fixed-scope engagement with one goal: move the site off its legacy Windows/IIS host and get it working one-to-one on Ubuntu, so the owners can run it on their own machines and evolve it with AI coding tools ahead of a move to a smaller cloud server.
The production server was migrated into git by a scripted, audited copy (an include/exclude manifest per run, 83 migration logs, exclusion of S3-bound media), and then the real work started: could it run anywhere else?
That meant a Docker image with three PHP versions plus Lucee and MariaDB, a bundle of nearly 500 database table exports so local data matches production shape, and a large number of "this page 500s on a clean machine" fixes (case-sensitive table names after a Windows-to-Linux move, hardcoded production domains, display_errors leaking raw warnings into rendered pages, missing assets excluded by an over-eager .gitignore).
41 of the 49 commits in the repo are co-authored with Cursor. That's the last post in this series, and it's the one place where AI-assisted development enters the story: a 15-year-old, partly untested platform brought back to a runnable, documented state in about ten days.
Who built what
A 15-year platform is never one person's work, and these posts shouldn't read like it was. From the headers in the first-party library:
Many of the shared classes, including the S3, Glacier, Transcoder, MediaConvert, process-watcher, and Concierge code, carry my name.
Other developers' names appear on significant pieces: photo/zip processing scripts, the S3 zip-queue, and parts of the admin and CRM layers.
Anything under
vendor/,google-api*,facebook*,phrets, and so on is third-party.
When a post says "I built X," it will be because the header says so and I wrote it. When it says "we," it means the team.
What's coming in this series
The Tour Factory. Photo processing, zip delivery, and an S3 migration done while the site stayed up.
From RTMP and Batch Files to HLS. Rebuilding a video pipeline three times, from a Windows box to managed transcoding.
Keeping Long-Running Work Alive on a Web Tier. Cron-by-HTTP, advisory locks, a query killer, and what "reliability" looked like without a worker fleet.
Thirteen MLS Boards, Three Transports. The listing-data layer that fed a media business.
Social Compass: Anatomy of a Multi-Tenant Social Scheduler. The decision loop, content selection, the branded redirect, and the iOS wrapper.
Seven Networks, Three Eras of Auth. Living with other people's APIs, and what each platform changed.
Resurrecting a 15-Year-Old Platform with Cursor. The migration, the audit, and what AI-assisted development was and wasn't good at here.
What I'd ask of you, reader
I'm not able to hand you a public repository to check these claims against, because it's a private company repo. What I can do:
Every post will cite file and class names and the kind of evidence (header, dated filename, row count, public web page).
The public web properties I reference are linkable: the company site, the Social Compass marketing pages, and the company's LinkedIn page.
If you're a hiring manager and want to go deeper, I'm glad to walk through any of this live, with the code open.
If something here looks wrong or overstated, tell me. A correction beats a quiet error.
Evidence appendix (for this post)
Claims in this post trace to these artifacts in the repository:
49 commits, 2026-09-28 to 2026-10-08; 41 co-authored with Cursor:
git logon the repo.Old README, "Git repo setup on 9/2/2014":
README.Codebase size, 79% vendored, ~600 CFML files, three PHP versions:
deploy/docker/Design_Reasoning.md,deploy/README.md.Row counts (tours, orders, users):
deploy/README.md"Importing real data".Windows/IIS evidence:
repository_inc/classes/class.backgroundtask.php(COMWScript.Shell),class.subdomain.php(appcmd),class.tourvideos.php(.batbatch file),inc.global.php(is318()/is342()).AWS layer:
class.awss3.php,class.awss3v3.php,class.awsglacier.php,class.awstranscoder*.php,class.awsmediaconvert.php,class.s3zipfiles.php.Social layer:
class.socialcompass.php,class.socialmarketing.php,class.socialnetworks.php,class.socialcontent.php,class.socialcreate.php,files/Social Compass.app.Public company pages: the Spotlight Media Group About page (2018 Social Compass rollout) and Social Compass page.
Comments
No comments yet — be the first to share your thoughts.
Leave a comment
Your comment will be reviewed before it appears publicly.