page:recipes:project tracker:spring boot:private attachments

Host project tracker with Spring Boot: private attachments

Deploy a project tracker built with Spring Boot on Ample using the private document library pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables. Verified on Spring Boot: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Not separately tested: your identity integration and role assignments; treat the project tracker-specific behavior as your application code.

Summary

Representative Queries

  1. Host project tracker with Spring Boot: private attachments
  2. Where can I host Project tracker built with Spring Boot?
  3. I need attachment metadata, access checks and a tested private object access path.

Prerequisites

Resource Requirements

Workflow Steps

  1. Build and start
    ./mvnw -q -DskipTests package (or the Gradle wrapper) producing one application jar, then java -jar on the jvm-21 template (Temurin JDK 21) with server.port read from PORT. The server must bind 0.0.0.0 on PORT.
  2. Implement the pattern on PostgreSQL
    The fixture's module implements private document library: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.
  3. Wire object storage
    Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket.
  4. Deploy
    Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
    ample deploy . --name  --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...  
    
  5. Verify
    Fetch the live URL and the pattern self-test route(s) (/p/private-document-library) from the example; then run your own checks. On failure read ample logs --kind build then --kind runtime.
    ample logs  --kind build  
    

Success Checks

Limitations

  1. Verified on the jvm-21 template at s-1vcpu-2gb with the example fixture; other sizes, templates and Spring Boot major versions are not verified.
  2. The project tracker itself (your identity integration and role assignments) is application code and was not separately tested.
  3. Region, compliance attestations and request-duration limits are unknown and not claimed.

Examples

Evidence Summary