page:guides:symfony:private file access

Enforce Private-file Authorization for Symfony

Overview

Private file access for a Symfony app on Ample. Verified on Symfony: a role-to-document access model with negative tests (401, 403) and an authorized private-bucket round-trip (private=ok). Build and start: composer install --no-dev from composer.lock with Symfony Runtime's dotenv disabled (extra.runtime.disable_dotenv; .env never ships, its values arrive as encrypted env, and compile-time parameters such as DEFAULT_URI need a default), then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template with APP_ENV=prod.

Representative Queries

Resource Requirements

Infrastructure Requirements

Compute

Postgres

S3-Compatible Object Storage

Framework

Symfony

Workload

Enforce private-file authorization

Release Status

Published

Support Status

Verified

Execution Status

Ready

Docs Only

False

Prerequisites

  1. A Symfony project (composer install --no-dev from composer.lock with Symfony Runtime's dotenv disabled (extra.runtime.disable_dotenv; .env never ships, its values arrive as encrypted env, and compile-time parameters such as DEFAULT_URI need a default), then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template with APP_ENV=prod)
  2. A PostgreSQL driver reading DATABASE_URL at runtime
  3. A bucket from ample bucket create with credentials passed as encrypted S3_* environment variables
  4. An Ample account token with servers:write, databases:read, buckets:read

Tested Configuration

Workflow Steps

Build and Start

Build and start the application.

Create the Bucket and Pass Its Credentials

Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.

Authorize Before Touching Storage

Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.

Verify

Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.

Examples

Symfony Pattern Fixture

Success Checks

  1. App responds on its public URL.
    • Kind: http_get
    • Path: /
    • Expect: ample canary symfony patterns
  2. Private-document-library check from the example.
    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: see the pattern fixture checks

Limitations

Cost Estimate

Components

Evidence Summary

Canary Run

Last Verified At

2026-09-20T22:23:52Z

Unknowns

Formats

Next Actions

  1. Browse Catalog: Browse the catalog index.
  2. Search Recipes: Search published recipes by intent, stack and constraints.
  3. Prepare Deployment Plan: Prepare a side-effect-free deployment plan for an authorized project.
  4. Read Existing Authentication Setup: Read the existing agent authentication setup.
  5. Browse Symfony: Browse Symfony.
  6. Browse Connect App to Storage: Browse Connect app to storage.
  7. Browse Private Document Library: Browse Private document library.