page:recipes:project tracker:flask:private attachments

Host project tracker with Flask: private attachments

Summary

Deploy a project tracker built with Flask on Ample using the private document library pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables. Verified on Flask: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Not separately tested: your identity integration and role assignments; treat the project tracker-specific behavior as your application code.

Representative Queries

Resource Requirements

Infrastructure Requirements

  1. Compute:

    • Status: verified
    • Summary: Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.
  2. Postgres:

    • Status: verified
    • Summary: Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.
  3. S3-compatible object storage:

    • Status: verified
    • Summary: Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.

Framework

Flask

Workload

Project tracker

Release Status

Published

Support Status

Verified

Execution Status

Ready

Prerequisites

Workflow Steps

  1. Build and start: pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template. The server must bind 0.0.0.0 on PORT.

  2. Implement the pattern on PostgreSQL: The fixture's module implements private document library: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.

  3. Wire object storage: Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket.

  4. Deploy: Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.

    • Command: ample deploy . --name --public --start "python3 app.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  5. Verify: Fetch the live URL and the pattern self-test route(s) (/p/private-document-library) from the example; then run your own checks. On failure read ample logs --kind build then --kind runtime.

    • Command: ample logs --kind build

Success Checks

  1. App responds on its public URL:

    • Kind: http_get
    • Path: /
    • Expect: ample canary flask patterns
  2. Private-document-library self-test:

    • Kind: http_get
    • Path: /p/private-document-library
    • Expect: private=ok (with ?role=owner; 401 without, 403 for viewer)

Limitations

Cost Estimate

Components

  1. App server:

    • Size: s-1vcpu-1gb
    • Quantity: 1.0
    • Monthly Amount: 5.0
  2. Managed PostgreSQL database:

    • Size: s-1vcpu-1gb
    • Quantity: 1.0
    • Monthly Amount: 5.0

Note

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

Evidence Summary

  1. Kind: canary_run

    • Summary: Flask pattern fixture deployed on Ample (pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template); checks passed for private-document-library and configuration-secrets. Pattern proof: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).
    • Observed At: 2026-09-21T01:14:18Z
    • Implementation Revision: 50dbac567d2c5cc8e55e6c748a646be0025d9cfb-dirty (CLI 0.1.21)
    • Expires At: 2027-03-20T01:14:18Z
  2. Kind: canary_run

    • Summary: The same Flask app deployed with a --release-command migration; the marker it created was readable after activation.
    • Observed At: 2026-09-20T01:54:51Z
    • Implementation Revision: 199ff1dfd52683832ae75d3f98b53a7a4bff7f96-dirty (CLI e3181f5)
    • Expires At: 2027-03-19T01:54:51Z

Last Verified At

2026-09-21T01:14:18Z

Next Actions

  1. Browse the catalog index:

    • Action ID: browse-catalog
    • Method: GET
    • Relative Path: /v1/catalog
  2. Search published recipes by intent, stack and constraints:

    • Action ID: search-recipes
    • Method: POST
    • Relative Path: /v1/catalog/search
    • Body: {"limit":5,"query":"Host project tracker with Flask: private attachments"}
  3. Prepare a side-effect-free deployment plan for an authorized project:

    • Action ID: plan:page:recipes:project-tracker:flask:private-attachments
    • Method: POST
    • Relative Path: /v1/catalog/plan
    • Body: {"inputs":{},"projectId":"","recipeId":"page:recipes:project-tracker:flask:private-attachments","recipeRevision":"r1"}
  4. Read the existing agent authentication setup:

    • Action ID: auth-setup
    • Method: GET
    • Relative Path: /mcp/setup
  5. Browse Project tracker:

    • Action ID: browse:workload:project-tracker
    • Method: GET
    • Relative Path: /v1/catalog/nodes/workload%3Aproject-tracker
  6. Browse Flask:

    • Action ID: browse:stack:framework-flask
    • Method: GET
    • Relative Path: /v1/catalog/nodes/stack%3Aframework-flask
  7. Browse Private document library:

    • Action ID: browse:pattern:private-document-library
    • Method: GET
    • Relative Path: /v1/catalog/nodes/pattern%3Aprivate-document-library
  8. Browse Deploy web app:

    • Action ID: browse:intent:deploy-web-app
    • Method: GET
    • Relative Path: /v1/catalog/nodes/intent%3Adeploy-web-app