page:blueprints:b2b saas:client portal:laravel
B2B SaaS: Client Portal using Laravel
Summary
A client portal blueprint for B2B SaaS built with Laravel on Ample. Domain schema:
- customer_workspaces (name, plan, seat_count, created_at): customer tenants;
- workspace_members (workspace_id, email, role): members and roles per workspace;
- doc_versions (product_version, title, object_key, published_at): versioned product documentation;
- customer_assets (workspace_id, title, object_key, visibility): assets scoped to one customer;
- document_access (document_id, principal_reference, role, granted_at): who may read which document.
Public information: product documentation by version, pricing and plan comparison, status and changelog.
Kept out of scope until handling is reviewed: customer data inside workspaces, usage and billing records, support attachments. Customer workspace data is tenant-scoped; isolation is application-enforced and no security certification is claimed.
Technical basis verified on Laravel: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).
Representative Queries
- B2B SaaS: client portal using Laravel
- Where can I host B2B SaaS: Client portal built with Laravel?
- I need a genuinely specialized client portal workflow covering customer workspaces, versioned product docs and customer-specific assets.
Resource Requirements
- primitive:compute
- primitive:postgres
- primitive:s3-compatible-object-storage
Infrastructure Requirements
- Compute: Verified apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
- Postgres: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
- S3-compatible object storage: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.
Workload
Client portal
Workflow Steps
- Model the B2B SaaS domain: Create the tables customer_workspaces, workspace_members, doc_versions, customer_assets, document_access. Customer tenants live in customer_workspaces; keep the sensitive classes out of this schema.
- Model client entities and engagement periods; every document belongs to one engagement.
- Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client).
- Store documents in the private bucket and stream them through the app.
- Deploy: Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
- Command:
ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
- Command:
- Verify: Run the pattern self-test(s) and your own acceptance checks for the B2B SaaS workflow.
- Command:
ample logs --kind build
- Command:
Technical Input Schema
- env: Encrypted environment variables (max 50 items, pattern:
^[A-Z][A-Z0-9_]*=.*$) - name: App name (max length 63, min length 1, pattern:
^[a-z0-9-]+$) - path: Project directory or ample.toml service (max length 512, min length 1)
- release_command: Migration command run before activation (max length 512)
Examples
- Laravel pattern fixture: Verified private document library basis for this blueprint.
- Source Ref: tests/deploy-canaries/laravel-patterns
Success Checks
- App responds on its public URL (expect: ample canary laravel patterns).
- Private-document-library self-test from the example (expect: see the pattern fixture checks).
Limitations
- The technical basis was verified with the pattern fixture; the B2B SaaS schema and workflow were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Customer workspace data is tenant-scoped; isolation is application-enforced and no security certification is claimed.
- Verified on the php-8.5 template at s-1vcpu-1gb; region, request-duration limits and other sizes are unknown or unverified.
Cost Estimate
- Currency: USD
- Monthly Amount: $10.00
- Basis: Size prices from pricing.toml (loaded by the API) at build revision.
- Components:
- App Server: s-1vcpu-1gb, quantity: 1.0, monthly amount: $5.00
- Managed PostgreSQL Database: s-1vcpu-1gb, quantity: 1.0, monthly amount: $5.00
- Note: Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.