page:guides:hono:private file access

Enforce private-file authorization for Hono

Summary

Private file access for a Hono app on Ample. Verified on Hono: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: npm install and npm run start with @hono/node-server on the node-22 template.

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute
    Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres
    Managed PostgreSQL 16 runs in its own microVM and auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage
    Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Prerequisites

Workflow Steps

  1. Build and start
    npm install and npm run start with @hono/node-server on the node-22 template; the server must bind 0.0.0.0 on PORT.
  2. Create the bucket and pass its credentials
    Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.
    ample deploy . --name  --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
    
  3. Authorize before touching storage
    Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.
  4. Verify
    Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.
    ample logs  --kind build
    

Examples

Success Checks

  1. App responds on its public URL
    • Kind: http_get
    • Path: /
    • Expect: ample canary hono patterns
  2. Private-document-library check from the example
    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: see the pattern fixture checks

Limitations

Cost Estimate

Evidence Summary

Last Verified At

2026-09-21T01:14:18Z

Formats

Next Actions

  1. Browse the catalog index
    • Action ID: browse-catalog
    • Operation ID: catalog_index
    • Method: GET
    • Relative Path: /v1/catalog
    • Requires Authentication: false
  2. Search published recipes by intent, stack and constraints
    • Action ID: search-recipes
    • Operation ID: search_recipes
    • Method: POST
    • Relative Path: /v1/catalog/search
    • Body: {"limit":5,"query":"Enforce private-file authorization for Hono"}
    • Requires Authentication: false
    • Requires Approval: false
  3. Prepare a side-effect-free deployment plan for an authorized project
    • Action ID: plan:page:guides:hono:private-file-access
    • Operation ID: plan_deployment
    • Method: POST
    • Relative Path: /v1/catalog/plan
    • Body: {"inputs":{},"projectId":"","recipeId":"page:guides:hono:private-file-access","recipeRevision":"r1"}
    • Requires Authentication: true
    • Requires Approval: false
  4. Read the existing agent authentication setup
    • Action ID: auth-setup
    • Operation ID: existing_auth_setup
    • Method: GET
    • Relative Path: /mcp/setup
    • Requires Authentication: false
    • Requires Approval: false
  5. Browse Hono
    • Action ID: browse:stack:framework-hono
    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/stack%3Aframework-hono
    • Requires Authentication: false
    • Requires Approval: false
  6. Browse Connect app to storage
    • Action ID: browse:intent:connect-app-to-storage
    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/intent%3Aconnect-app-to-storage
    • Requires Authentication: false
    • Requires Approval: false
  7. Browse Private document library
    • Action ID: browse:pattern:private-document-library
    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/pattern%3Aprivate-document-library
    • Requires Authentication: false
    • Requires Approval: false