Ask Zico: Production Architecture And Request Flow
A system map of Ask Zico: the PHP trust boundary, Cloudflare Worker, evidence stores, model providers, operational state, and end-to-end request lifecycle.
A system map of Ask Zico: the PHP trust boundary, Cloudflare Worker, evidence stores, model providers, operational state, and end-to-end request lifecycle.
The project-specific evidence behind Ask Zico's controlled retrieval, stable identity, internal semantic routing, and application-owned ranking.
How Ask Zico preserves readable Arabic, normalized search text, deterministic per-build IDs, metadata, and coordinated retrieval artifacts.
The launched Ask Zico retrieval pipeline: Arabic normalization, semantic routing, Vectorize, lexical shards, filters, rank fusion, and KV hydration.
How Ask Zico compacts evidence, routes provider capacity, validates citation IDs, refreshes follow-up evidence, and deliberately falls back.
A layered evaluation method for Arabic retrieval, answer correctness, citation precision, refusals, regressions, and production feedback.
How the launched Ask Zico interface uses Arabic-first copy, visible sources, deliberate fallback, quota states, feedback, and mobile reading behavior to calibrate trust.
How Ask Zico uses structured D1 events, retrieval metadata, provider attempts, quota outcomes, CPU phases, and message-linked feedback without publishing private traffic.
A dated, privacy-safe cost model for Ask Zico covering exact quota reservation, provider routing, compact context, fallback, counters, and alerts.
How a Coptic education project grew into a large publishing platform, and the engineering constraints that shaped it.
A grounded tour of the production request path, local Docker topology, and Vite asset build used by the PHP platform.
How thin entrypoints, generate-* assemblers, data loaders, and reusable PHP fragments compose complete content pages.
How server-rendered pages, configured cache policies, versioned Vite assets, and R2 media delivery are designed to reduce critical-path work.
A candid review of the platform's layered controls, including HTTPS, headers, CSP, sessions, CSRF, database access, and known legacy gaps.