page:guides:sinatra:private file access

Enforce private-file authorization for Sinatra

Summary

Private file access for a Sinatra app on Ample. Verified on Sinatra: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: bundle install into vendor/bundle from Gemfile.lock (development and test groups skipped), then Puma via rackup (config.ru) reading PORT on the ruby-3.4 template.

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute
    • Status: verified
    • Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres
    • Status: verified
    • Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage
    • Status: verified
    • Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Prerequisites

Tested Configuration

Workflow Steps

  1. Build and start
    bundle install into vendor/bundle from Gemfile.lock (development and test groups skipped), then Puma via rackup (config.ru) reading PORT on the ruby-3.4 template; the server must bind 0.0.0.0 on PORT.
  2. Create the bucket and pass its credentials
    Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.
    Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  3. Authorize before touching storage
    Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.
  4. Verify
    Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.
    Command: ample logs --kind build

Examples

Success Checks

  1. App responds on its public URL
    • Kind: http_get
    • Path: /
    • Expect: ample canary sinatra patterns
  2. Private-document-library check from the example
    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: see the pattern fixture checks

Limitations

Cost Estimate

Evidence Summary

Last Verified At

2026-09-20T23:45:31Z

Unknowns

Formats

Next Actions

  1. Browse the catalog index
    Method: GET
    Relative Path: /v1/catalog
    Requires Authentication: false
  2. Search published recipes by intent, stack and constraints
    Method: POST
    Relative Path: /v1/catalog/search
    Body: {"limit":5,"query":"Enforce private-file authorization for Sinatra"}
    Requires Authentication: false
  3. Prepare a side-effect-free deployment plan for an authorized project
    Method: POST
    Relative Path: /v1/catalog/plan
    Body: {"inputs":{},"projectId":"","recipeId":"page:guides:sinatra:private-file-access","recipeRevision":"r1"}
    Requires Authentication: true
  4. Read the existing agent authentication setup
    Method: GET
    Relative Path: /mcp/setup
    Requires Authentication: false
  5. Browse Sinatra
    Method: GET
    Relative Path: /v1/catalog/nodes/stack%3Aframework-sinatra
    Requires Authentication: false
  6. Browse Connect app to storage
    Method: GET
    Relative Path: /v1/catalog/nodes/intent%3Aconnect-app-to-storage
    Requires Authentication: false
  7. Browse Private document library
    Method: GET
    Relative Path: /v1/catalog/nodes/pattern%3Aprivate-document-library
    Requires Authentication: false