page:recipes:admin dashboard:rails:public profiles

Host admin dashboard with Rails: public profile assets

Deploy an admin dashboard built with Rails on Ample using the public image delivery pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables, and a published bucket serves public assets from the CDN host. Verified on Rails: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Not separately tested: your image processing and profile-media rules; treat the admin dashboard-specific behavior as your application code.

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute:
    • Status: verified
    • Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres:
    • Status: verified
    • Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage:
    • Status: verified
    • Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.
  4. CDN:
    • Status: verified
    • Summary: The CDN host serves objects from published buckets. It does not front app compute and is not a cache or key-value store.

Prerequisites

Workflow Steps

  1. Build and start:
    • Run: bundle install into vendor/bundle from Gemfile.lock (development and test groups skipped), then Puma via rails server reading PORT on the ruby-3.4 template with RAILS_ENV=production. The server must bind 0.0.0.0 on PORT.
  2. Implement the pattern on PostgreSQL:
    • The fixture's module implements public image delivery: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.
  3. Wire object storage:
    • Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.
  4. Deploy:
    • Run the synchronous deploy and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
    • Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...
  5. Verify:
    • Fetch the live URL and the pattern self-test route(s) (/p/public-media-library, /p/private-document-library) from the example; then run your own checks. On failure read ample logs --kind build then --kind runtime.
    • Command: ample logs --kind build

Success Checks

Limitations

Cost Estimate

Evidence Summary

  1. Canary Run:
    • Summary: Rails pattern fixture deployed on Ample; checks passed for public-media-library, private-document-library and configuration-secrets.
    • Observed At: 2026-09-20T21:55:28Z
    • Expires At: 2027-03-19T21:55:28Z
  2. Unknowns:
    • Region availability is unknown until a verified region fact is recorded.
    • Compliance attestations are unknown; none are claimed.

Formats

Next Actions

  1. Browse the catalog index
  2. Search published recipes by intent, stack and constraints
  3. Prepare a side-effect-free deployment plan for an authorized project
  4. Read the existing agent authentication setup
  5. Browse Admin dashboard
  6. Browse Rails
  7. Browse Public image delivery
  8. Browse Deploy web app