Ilham Maulana
mxxham
Software engineer building warehouse, inventory and logistics systems.
How a specific unit of stock gets picked, from which bin, for which shipment.
Most of what I build sits in the gap between a spreadsheet and a warehouse floor: allocation rules, stock accuracy, and the audit trail that proves the stock is where the system says it is.
The recurring problem is FEFO. A lubricant warehouse stores several thousand bins of a few hundred SKUs, and nearly every unit has a batch and an expiry date. Picking the wrong unit is not a cosmetic bug — it is product that gets written off. So the allocation has to be deterministic, tie-broken consistently, and safe to re-plan when reality on the floor disagrees with the plan.
That constraint is what shapes most of my work: prefer an auditable, boring, verifiable design over a clever one.
Built for PT Cipta Krida Bahari · WSM SUB 2, Surabaya, operating a Shell lubricant warehouse.
One application, one database, one stock ledger — 2,570 bins · 106 SKUs · 1,790 stock rows in a single reconciled ledger.
| 🏷️ Bin labelling | 📱 Scanning | 🧊 3D stock | 🧠 FEFO allocation | 🌊 Waves |
|---|---|---|---|---|
| Location labels in 5 strip sizes (80×85 mm), QR + Code 128, generated as vectors | Camera or USB scanner, auto-focus and Enter to advance | All 2,570 bins in one draw call, rendered on demand | Reservation, deterministic tie-break, and a safe re-plan when the floor disagrees | Idempotent posting into an append-only movements ledger |
Alongside the core allocation loop it also covers the parts that decide whether a warehouse can be trusted: rack audits, blind pick audits, and shipment acceptance with stock correction — the loop that closes when a physical count contradicts the plan.
Stack: Next.js 15 · TypeScript 5 · Supabase (Postgres) · Tailwind · Radix UI · three.js + React Three Fiber · bwip-js · html5-qrcode · exceljs / xlsx · jspdf
| Project | What it is |
|---|---|
k-one-v2 |
The same warehouse problem rebuilt on NestJS + TypeScript + PostgreSQL 16 + Redis 7, with a BullMQ worker, React + Vite frontend, and Jest/Supertest + Vitest coverage. Ported from the PHP original, then extended with department-based roles, stock hold/quarantine, and wave planning. |
visionguard-ai |
Warehouse pest detection — a real-time dashboard over CCTV and webcam streams, running YOLOv8-nano behind a FastAPI service with WebSockets, PostgreSQL, React 18 and Recharts. |
finance-tracker |
FinTrack — full-stack personal finance app (Next.js 15, PostgreSQL, JWT auth) with transactions, budgets and charts. live demo |
k-one · allocator_app |
The earlier PHP / MySQL generations of the warehouse system — the version k-one-v2 was ported from. |
E2EE_Apps |
SecureChat — an Android messenger that implements the Signal Protocol's cryptography directly: X3DH key agreement on Curve P-256 and a Double Ratchet session cipher (AES-256-GCM, HKDF-SHA256, skipped-key handling for out-of-order delivery). The server only ever stores ciphertext. Modular Jetpack Compose + Hilt + Room on Supabase, with unit tests covering key agreement, forward secrecy and out-of-order decryption. |
Assignment-Software-Engineer |
obsidian-store — a motion-first storefront for a fictional streetwear label. React 19 + Vite 6 in plain CSS, with no UI or animation dependencies: lerped mouse parallax, 3D card tilt, IntersectionObserver reveals and a custom cursor, all hand-rolled in four hooks. |
- The ledger is the source of truth. If it isn't in
movements, it didn't happen. - Idempotent or it doesn't ship. Re-running a posting must be safe, because it will be re-run.
- Make the plan safe to abandon. Re-planning has to be a supported operation, not an emergency.
- Verify against the physical world. Blind audits exist because a system's confidence is not evidence.
Built with Next.js, TypeScript, Supabase and Postgres — mxxham