page:guides:symfony:private file access
Enforce Private-file Authorization for Symfony
Overview
Private file access for a Symfony app on Ample. Verified on Symfony: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: composer install --no-dev from composer.lock with Symfony Runtime's dotenv disabled (extra.runtime.disable_dotenv; .env never ships, its values arrive as encrypted env, and compile-time parameters such as DEFAULT_URI need a default), then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template with APP_ENV=prod.
Representative Queries
- Enforce private-file authorization for Symfony
- Where can I host Enforce private-file authorization built with Symfony?
- I need application identity integration, per-file access rules and negative authorization tests.
Resource Requirements
- primitive:compute
- primitive:postgres
- primitive:s3-compatible-object-storage
Infrastructure Requirements
Compute
- Status: Verified
- Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
Postgres
- Status: Verified
- Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
S3-Compatible Object Storage
- Status: Verified
- Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.
Framework
Symfony
Workload
Enforce private-file authorization
Release Status
Published
Support Status
Verified
Execution Status
Ready
Docs Only
False
Prerequisites
- A Symfony project (composer install --no-dev from composer.lock with Symfony Runtime's dotenv disabled (extra.runtime.disable_dotenv; .env never ships, its values arrive as encrypted env, and compile-time parameters such as DEFAULT_URI need a default), then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template with APP_ENV=prod)
- A PostgreSQL driver reading DATABASE_URL at runtime
- A bucket from
ample bucket createwith credentials passed as encrypted S3_* environment variables - An Ample account token with servers:write, databases:read, buckets:read
Tested Configuration
- Template: php-8.5
- Runtime: php
- Size: s-1vcpu-1gb
- Install: composer install --no-dev --prefer-dist --no-interaction --no-progress --optimize-autoloader
- Start: frankenphp php-server --listen :$PORT --root public
Workflow Steps
Build and Start
Build and start the application.
Create the Bucket and Pass Its Credentials
Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.
- Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
Authorize Before Touching Storage
Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.
Verify
Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.
- Command: ample logs --kind build
Examples
Symfony Pattern Fixture
- Description: Verified private file access on Symfony.
- Source Reference: tests/deploy-canaries/symfony-patterns
Success Checks
- App responds on its public URL.
- Kind: http_get
- Path: /
- Expect: ample canary symfony patterns
- Private-document-library check from the example.
- Kind: http_get
- Path: /p/private-document-library
- Expect: see the pattern fixture checks
Limitations
- Verified on the php-8.5 template at s-1vcpu-1gb; other sizes and Symfony major versions are not verified.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified.
- PutObject and GetObject with path-style addressing are verified; other S3 operations are not.
Cost Estimate
- Currency: USD
- Monthly Amount: 10.0
- Basis: size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty
Components
- App Server: s-1vcpu-1gb - 1.0x - $5.0
- Managed PostgreSQL Database: s-1vcpu-1gb - 1.0x - $5.0
- Note: Always-on monthly price of the tested sizes; apps auto-pause when idle. Buckets are allocation-priced per quota and not included.
Evidence Summary
Canary Run
- Summary: Symfony pattern fixture deployed on Ample.
- Observed At: 2026-09-20T22:23:52Z
- Implementation Revision: 64a7bb8e37dd-dirty (CLI 64a7bb8e)
- Expires At: 2027-03-19T22:23:52Z
- Scope: checks ["/p/private-document-library"]
Last Verified At
2026-09-20T22:23:52Z
Unknowns
- Region availability is unknown until a verified region fact is recorded.
- Compliance attestations are unknown; none are claimed.
Formats
Next Actions
- Browse Catalog: Browse the catalog index.
- Search Recipes: Search published recipes by intent, stack and constraints.
- Prepare Deployment Plan: Prepare a side-effect-free deployment plan for an authorized project.
- Read Existing Authentication Setup: Read the existing agent authentication setup.
- Browse Symfony: Browse Symfony.
- Browse Connect App to Storage: Browse Connect app to storage.
- Browse Private Document Library: Browse Private document library.