page:recipes:help desk:flask:private attachments

Host Help Desk with Flask: Private Attachments

Deploy a help desk built with Flask on Ample using the private document library pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables. Verified on Flask: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Not separately tested: your identity integration and role assignments; treat the help desk-specific behavior as your application code.

Support Status

Infrastructure Requirements

Prerequisites

  1. A Flask project that builds and starts with the documented commands (pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template).
  2. A PostgreSQL driver reading DATABASE_URL at runtime (auto-provisioned when omitted, or supplied with --env).
  3. A bucket from ample bucket create with its credentials passed as encrypted S3_* environment variables.
  4. An Ample account token with servers:write, databases:read, buckets:read.

Workflow Steps

1. Build and Start

2. Implement the Pattern on PostgreSQL

3. Wire Object Storage

4. Deploy

5. Verify

Success Checks

  1. App responds on its public URL: http_get / expect ample canary flask patterns
  2. Private-document-library self-test: http_get /p/private-document-library expect private=ok (with ?role=owner; 401 without, 403 for viewer)

Limitations

Cost Estimate