page:guides:spring boot:private file access
Enforce Private-file Authorization for Spring Boot
Summary
Private file access for a Spring Boot app on Ample. Verified on Spring Boot: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: ./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT.
Prerequisites
- A Spring Boot project (
./mvnw -q -DskipTests packageor the Gradle wrapper) producing one application jar, thenjava -jaron the jvm-21 template (Temurin JDK 21) withserver.portread fromPORT) - A PostgreSQL driver reading
DATABASE_URLat runtime - A bucket from
ample bucket createwith credentials passed as encryptedS3_*environment variables - An Ample account token with
servers:write,databases:read,buckets:read
Steps
1. Build and Start
./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT; the server must bind 0.0.0.0 on PORT.
2. Create the Bucket and Pass its Credentials
Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.
ample deploy . --name <app_name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
3. Authorize Before Touching Storage
Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.
4. Verify
Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.
ample logs --kind build
Examples
- Spring Boot Pattern Fixture: Verified private file access on Spring Boot.
Success Checks
- App responds on its public URL.
- Private-document-library check from the example.
Limitations
- Verified on the jvm-21 template at s-1vcpu-2gb; other sizes and Spring Boot major versions are not verified.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
Cost Estimate
- Monthly Amount: $10.00 USD
- Components:
- App server: s-1vcpu-1gb
- Managed PostgreSQL database: s-1vcpu-1gb
Next Actions
- Browse the catalog index.
- Search published recipes by intent, stack, and constraints.
- Prepare a side-effect-free deployment plan for an authorized project.
- Read the existing agent authentication setup.