page:guides:fastapi:object client

Configure S3-compatible access for FastAPI

Summary

Configure S3-compatible access for a FastAPI app on Ample. Create a bucket with ample bucket create, pass its endpoint, region, bucket name and keys as encrypted environment variables, and use boto3 with Config(s3={'addressing_style': 'path'}). The app writes and reads objects through the S3-compatible endpoint; the bucket stays private.

Prerequisites

Workflow Steps

  1. Create the bucket
    Create it once and keep the issued credentials out of the repository.

    ample bucket create --name <bucket-name>
    
  2. Configure the client with path-style addressing
    Use boto3 with Config(s3={'addressing_style': 'path'}); virtual-host addressing is not verified.

  3. Deploy with the credentials as encrypted env
    Pass the five S3_* variables with --env; they are stored encrypted and reused on redeploys.

    ample deploy . --name <app-name> --public --start "python3 run.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
    
  4. Test through the app
    Expose a route (/storage) that writes then reads an object and reports s3=ok.

  5. Verify
    Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.

    ample logs <app-name> --kind build
    

Success Checks

Limitations

Cost Estimate

Evidence Summary

Formats