page:guides:django:private file access

Enforce private-file authorization for Django

Summary
Private file access for a Django app on Ample. Verified on Django: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: pip install into .ample/python from requirements.txt, then waitress serving project.wsgi from run.py reading PORT on the python-3.12 template.


Representative Queries


Resource Requirements


Workflow Steps

  1. Build and start
    pip install into .ample/python from requirements.txt, then waitress serving project.wsgi from run.py reading PORT on the python-3.12 template; the server must bind 0.0.0.0 on PORT.

  2. Create the bucket and pass its credentials
    Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.

    ample deploy . --name <name> --public --start "python3 run.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...  
    
  3. Authorize before touching storage
    Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.

  4. Verify
    Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.

    ample logs <log-options> --kind build  
    

Prerequisites


Cost Estimate


Limitations


Examples


Success Checks

  1. App responds on its public URL

    • Kind: http_get
    • Path: /
    • Expect: ample canary django patterns
  2. Private-document-library check from the example

    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: see the pattern fixture checks

Next Actions


Formats