page:recipes:admin dashboard:spring boot:public profiles
Host Admin Dashboard with Spring Boot: Public Profile Assets
Summary
Deploy an admin dashboard built with Spring Boot on Ample using the public image delivery pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables, and a published bucket serves public assets from the CDN host. Verified on Spring Boot: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Not separately tested: your image processing and profile-media rules; treat the admin dashboard-specific behavior as your application code.
Representative Queries
- Host admin dashboard with Spring Boot: public profile assets
- Where can I host Admin dashboard built with Spring Boot?
- I need separate public profile media from private data, with CDN cache rules.
Resource Requirements
- primitive:compute
- primitive:postgres
- primitive:s3-compatible-object-storage
- primitive:cdn
Infrastructure Requirements
Compute
Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.Postgres
Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.S3-Compatible Object Storage
Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.CDN
The CDN host serves objects from published buckets. It does not front app compute and is not a cache or key-value store.
Prerequisites
- A Spring Boot project that builds and starts with the documented commands (./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT).
- A PostgreSQL driver reading DATABASE_URL at runtime (auto-provisioned when omitted, or supplied with --env).
- A bucket from
ample bucket createwith its credentials passed as encrypted S3_* environment variables and a second, published bucket for public assets (CDN_*). - An Ample account token with servers:write, databases:read, buckets:read.
Workflow Steps
Build and Start
./mvnw -q -DskipTests package(or the Gradle wrapper) producing one application jar, thenjava -jaron the jvm-21 template (Temurin JDK 21) with server.port read from PORT. The server must bind 0.0.0.0 on PORT.Implement the Pattern on PostgreSQL
The fixture's module implements public image delivery: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.Wire Object Storage
Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.Deploy
Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...Verify
Fetch the live URL and the pattern self-test route(s) (/p/public-media-library, /p/private-document-library) from the example; then run your own checks. On failure readample logs --kind buildthen--kind runtime.ample logs --kind build
Examples
- Spring Boot Pattern Fixture
Multi-pattern Spring Boot app whose public image delivery module was checked live; the module is under tests/deploy-canaries/_pattern-modules.- Source Reference: tests/deploy-canaries/spring-boot-patterns
Success Checks
App responds on its public URL
- Kind:
http_get, Path:/, Expect:ample canary spring boot patterns
- Kind:
Public-media-library self-test
- Kind:
http_get, Path:/p/public-media-library, Expect:a CDN URL whose content is served publicly
- Kind:
Private-document-library self-test
- Kind:
http_get, Path:/p/private-document-library, Expect:private=ok (with ?role=owner; 401 without, 403 for viewer)
- Kind:
Limitations
- Verified on the jvm-21 template at s-1vcpu-2gb with the example fixture; other sizes, templates and Spring Boot major versions are not verified.
- The admin dashboard itself (your image processing and profile-media rules) is application code and was not separately tested; the pattern checks are what was verified.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
- Apps auto-pause when idle and wake on the next request; always-on is an operator setting, not a plan feature.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified; apps and their databases are placed together.
- PutObject and GetObject with path-style addressing are verified; multipart upload, listing, presigned URLs and lifecycle rules are not.
- The CDN serves published-bucket objects only; cache rules, purge and TTL control are not verified (the fixture sets Cache-Control on upload and versions keys).
Cost Estimate
- Currency: USD
- Monthly Amount: 10.0
- Authoritative: true
- Basis: size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty
- Components:
- App Server
- Size: s-1vcpu-1gb
- Quantity: 1.0
- Monthly Amount: 5.0
- Managed PostgreSQL Database
- Size: s-1vcpu-1gb
- Quantity: 1.0
- Monthly Amount: 5.0
- App Server
- Note: Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Evidence Summary
Canary Run
- Summary: Spring Boot pattern fixture deployed on Ample (./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT); checks passed for public-media-library, private-document-library and configuration-secrets. Pattern proof: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role).
- Observed At: 2026-09-21T02:34:39Z
- Implementation Revision: 1d28ae0-dirty (CLI 0.1.21)
- Expires At: 2027-03-20T02:34:39Z
Canary Run
- Summary: The same Spring Boot app deployed with a --release-command migration; the marker it created was readable after activation.
- Observed At: 2026-09-20T22:49:19Z
- Implementation Revision: af6f45adea26-dirty (CLI af6f45a)
- Expires At: 2027-03-19T22:49:19Z
Unknowns
- Region availability is unknown until a verified region fact is recorded.
- Compliance attestations are unknown; none are claimed.
Formats
- HTML: HTML Documentation
- Markdown: Markdown Documentation
- JSON: JSON API
Next Actions
Browse the Catalog Index
- Method: GET
- Relative Path: /v1/catalog
Search Published Recipes
- Method: POST
- Relative Path: /v1/catalog/search
- Parameters: {"body":{"limit":5,"query":"Host admin dashboard with Spring Boot: public profile assets"}}
Prepare a Deployment Plan
- Method: POST
- Relative Path: /v1/catalog/plan
- Parameters: {"body":{"inputs":{},"projectId":"","recipeId":"page:recipes:admin-dashboard:spring-boot:public-profiles","recipeRevision":"r1"}}
Read Existing Auth Setup
- Method: GET
- Relative Path: /mcp/setup
Browse Admin Dashboard
- Method: GET
- Relative Path: /v1/catalog/nodes/workload%3Aadmin-dashboard
Browse Spring Boot
- Method: GET
- Relative Path: /v1/catalog/nodes/stack%3Aframework-spring-boot
Browse Public Image Delivery
- Method: GET
- Relative Path: /v1/catalog/nodes/pattern%3Apublic-image-delivery
Browse Deploy Web App
- Method: GET
- Relative Path: /v1/catalog/nodes/intent%3Adeploy-web-app