page:guides:gin:private file access

Enforce Private-File Authorization for Gin

Summary

Private file access for a Gin app on Ample. Verified on Gin: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: CGO_ENABLED=0 go build -o app ./... then ./app on the ubuntu-24.04 template (go.sum committed for a reproducible build).

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute

    • Status: verified
    • Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres

    • Status: verified
    • Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage

    • Status: verified
    • Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Workflow Steps

  1. Build and start
    CGO_ENABLED=0 go build -o app ./... then ./app on the ubuntu-24.04 template (go.sum committed for a reproducible build); the server must bind 0.0.0.0 on PORT.

  2. Create the bucket and pass its credentials
    Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.
    Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...

  3. Authorize before touching storage
    Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.

  4. Verify
    Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.
    Command: ample logs --kind build

Examples

Success Checks

  1. app responds on its public URL

    • Kind: http_get
    • Path: /
    • Expect: ample canary gin patterns
  2. private-document-library check from the example

    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: see the pattern fixture checks

Limitations

Cost Estimate

Components

  1. App server

    • Size: s-1vcpu-1gb
    • Quantity: 1.0
    • Monthly Amount: 5.0
  2. Managed PostgreSQL database

    • Size: s-1vcpu-1gb
    • Quantity: 1.0
    • Monthly Amount: 5.0

Note: Always-on monthly price of the tested sizes; apps auto-pause when idle. Buckets are allocation-priced per quota and not included.

Next Actions

  1. Browse the catalog index
    Action ID: browse-catalog
    Method: GET
    Relative Path: /v1/catalog

  2. Search published recipes by intent, stack and constraints
    Action ID: search-recipes
    Method: POST
    Relative Path: /v1/catalog/search

  3. Prepare a side-effect-free deployment plan for an authorized project
    Action ID: plan:page:guides:gin:private-file-access
    Method: POST
    Relative Path: /v1/catalog/plan

  4. Read existing agent authentication setup
    Action ID: auth-setup
    Method: GET
    Relative Path: /mcp/setup

  5. Browse Gin
    Action ID: browse:stack:framework-gin
    Method: GET
    Relative Path: /v1/catalog/nodes/stack%3Aframework-gin

  6. Browse Connect app to storage
    Action ID: browse:intent:connect-app-to-storage
    Method: GET
    Relative Path: /v1/catalog/nodes/intent%3Aconnect-app-to-storage

  7. Browse Private document library
    Action ID: browse:pattern:private-document-library
    Method: GET
    Relative Path: /v1/catalog/nodes/pattern%3Aprivate-document-library