page:recipes:client portal:spring boot:public profiles

Host client portal with Spring Boot: public profile assets

Summary

Deploy a client portal built with Spring Boot on Ample using the public image delivery pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables, and a published bucket serves public assets from the CDN host. Verified on Spring Boot: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Not separately tested: your image processing and profile-media rules; treat the client portal-specific behavior as your application code.

Representative Queries

Resource Requirements

Infrastructure Requirements

Compute

Postgres

S3-compatible object storage

CDN

Prerequisites

  1. A Spring Boot project that builds and starts with the documented commands (./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT).
  2. A PostgreSQL driver reading DATABASE_URL at runtime (auto-provisioned when omitted, or supplied with --env).
  3. A bucket from ample bucket create with its credentials passed as encrypted S3_* environment variables and a second, published bucket for public assets (CDN_*).
  4. An Ample account token with servers:write, databases:read, buckets:read.

Tested Configuration

Workflow Steps

  1. Build and start
    ./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT. The server must bind 0.0.0.0 on PORT.

  2. Implement the pattern on PostgreSQL
    The fixture's module implements public image delivery: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.

  3. Wire object storage
    Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.

  4. Deploy
    Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
    Replace placeholders with actual values: ample deploy . --name <name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...

  5. Verify
    Fetch the live URL and the pattern self-test route(s) (/p/public-media-library, /p/private-document-library) from the example; then run your own checks. On failure read ample logs --kind build then --kind runtime.
    Command: ample logs --kind build

Examples

Success Checks

  1. HTTP GET on /
    Expect: ample canary spring boot patterns

  2. Public-media-library self-test
    Expect: A CDN URL whose content is served publicly.

  3. Private-document-library self-test
    Expect: private=ok (with ?role=owner; 401 without, 403 for viewer).

Limitations

Cost Estimate

Evidence Summary

Last Verified At

2026-09-21T02:34:39Z

Next Actions

  1. Browse the catalog index

    • Operation ID: catalog_index
    • Method: GET
    • Relative Path: /v1/catalog
    • Requires Authentication: No
  2. Search published recipes by intent, stack and constraints

    • Operation ID: search_recipes
    • Method: POST
    • Relative Path: /v1/catalog/search
    • Parameters: Body: { "limit": 5, "query": "Host client portal with Spring Boot: public profile assets" }
    • Requires Authentication: No
  3. Prepare a side-effect-free deployment plan for an authorized project

    • Operation ID: plan_deployment
    • Method: POST
    • Relative Path: /v1/catalog/plan
    • Parameters: Body: { "inputs": {}, "projectId": "", "recipeId": "page:recipes:client-portal:spring-boot:public-profiles", "recipeRevision": "r1"}
    • Requires Authentication: Yes
  4. Read the existing agent authentication setup

    • Operation ID: existing_auth_setup
    • Method: GET
    • Relative Path: /mcp/setup
    • Requires Authentication: No
  5. Browse Client portal

    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/workload%3Aclient-portal
    • Requires Authentication: No
  6. Browse Spring Boot

    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/stack%3Aframework-spring-boot
    • Requires Authentication: No
  7. Browse Public image delivery

    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/pattern%3Apublic-image-delivery
    • Requires Authentication: No
  8. Browse Deploy web app

    • Operation ID: browse_node
    • Method: GET
    • Relative Path: /v1/catalog/nodes/intent%3Adeploy-web-app
    • Requires Authentication: No