The Open Source DMZ: Inside plutoniummod/docs

How a legacy game modding framework uses bleeding-edge Next.js to crowdsource engine secrets without exposing its core architecture.

6 min read • View on GitHub • More from plutoniummod

A massive steel vault door attached to a bright, glass-walled public library, symbolizing the closed core and open documentation.
The Plutonium project maintains a strict boundary between its proprietary game client and its open-source documentation.
Key Takeaways

The Trust Boundary

The Plutonium game client is fiercely closed-source. The Call of Duty modding community has a long history of stealing code to sell malware and paid cheats. This creates a fundamental tension: a modding framework cannot survive without exhaustive documentation of its reverse-engineered game script functions, but opening the core engine invites exploitation.

The sad state of the CoD "Community" which copy pastes your code and tries to sell it off as their own. Sometimes figuratively, sometimes literally. We had an experiment going some time ago where a module largely written by a single dev was released as open source, they literally slapped a gui on top and started selling it...

Xerxes, Plutonium Staff · Plutonium Forums

The solution is a demilitarized zone. The plutoniummod/docs repository serves as a strictly typed, highly structured open-source web environment where the community can safely collaborate on game engine secrets without ever touching the C++ core.

Structuring the Unknown

Documenting thousands of game script "builtins" is a massive undertaking. To tame the chaos of community contributions, the repository relies on Fumadocs and source.config.ts to enforce strict Zod frontmatter validation on pull requests. This ensures that crowdsourced knowledge cannot break the build pipeline.

The Content Validation Pipeline ensures untrusted community Markdown becomes a safe, localized, and searchable static site.

The system even handles UI elements dynamically. Contributors specify an icon string in a meta.json file, and the application maps it to a React component automatically.

icon(icon) {
  if (icon && icon in icons) {
    return createElement(icons[icon as keyof typeof icons]);
  }
}

Living on the Edge of the Web

For a gaming community project, the tech stack is remarkably modern. The repository aggressively adopts Next.js 15, React 19, and Tailwind 4.0. This architecture is designed for static site generation via Cloudflare Pages, eliminating the need for a Node.js runtime in production.

Two hands pass a blueprint through a narrow slot in a thick glass pane. One hand wears a heavy metal gauntlet, the other is unprotected.
The repository acts as a secure transaction window, allowing the community to pass knowledge to the core maintainers safely.

The shift to Tailwind 4.0 is particularly notable. It abandons the traditional JavaScript configuration file in favor of a CSS-first architectural model.

@import 'tailwindcss';

@theme {
  --color-primary: var(--color-blue-500);
}

The Fumadocs Middle Ground

When evaluating documentation generators, the Plutonium team faced a spectrum of choices. They rejected heavy, batteries-included monolithic frameworks and hyper-minimalist tools in favor of a modular approach.

FrameworkArchitectureProsCons
DocusaurusThe MonolithBatteries included, rich ecosystemHeavy React runtime, opinionated layout
docmdThe MinimalistZero JS bloat, instant setupLacks advanced i18n and UI components
Fumadocs + Next.jsThe Modular EngineLeverages React 19 ecosystem, highly customizableRequires more initial wiring

By choosing Fumadocs, the team secured advanced features like Orama client-side search and dynamic segment internationalization while maintaining full control over the Next.js routing layer. It is a calculated compromise that provides the exact right amount of structure for a crowdsourced knowledge base.