page:blueprints:nonprofits:member portal:django

Nonprofits: Member Portal Using Django

A member portal blueprint for nonprofits built with Django on Ample.

Summary

Domain schema:

Public information: mission and programs, events, donation entry point. Kept out of scope until handling is reviewed: beneficiary identity and case notes, donor records. Beneficiary and donor data are sensitive; donations are handled by your payment provider and are not modeled here.

Technical basis verified on Django: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute

    • Status: verified
    • Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres

    • Status: verified
    • Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage

    • Status: verified
    • Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Prerequisites

Workflow Steps

  1. Model the nonprofits domain
    Create the tables course_groups, memberships, sessions, materials, document_access. Programs and cohorts live in course_groups; keep the sensitive classes (beneficiary identity and case notes, donor records) out of this schema.

  2. Workflow step 1
    Model groups, memberships, and roles.

  3. Workflow step 2
    Authorize access to materials by membership and role (401, 403 negative tests).

  4. Workflow step 3
    Store materials in the private bucket and stream them through the app.

  5. Workflow step 4
    Deploy and verify the negative tests and an authorized download.

  6. Deploy
    Run the synchronous deploy once and read the result. Re-running with no change is a no-op.

    Command: ample deploy . --name --public --start "python3 run.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...

  7. Verify
    Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the nonprofits workflow.

    Command: ample logs --kind build

Limitations

Cost Estimate