page:recipes:reporting dashboard:flask:attachments
Host reporting dashboard with Flask: file attachments
Summary: Deploy a reporting dashboard built with Flask on Ample using the browser file uploads pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables. Verified on Flask: content-type and size validation that rejects disallowed files, an object written to a private bucket and a row linking the record to the object key (reject=ok upload=ok linked=ok). Not separately tested: your upload UI, allowed types, size limits and virus scanning; treat the reporting dashboard-specific behavior as your application code.
Framework: Flask
Workload: Reporting dashboard
Release Status: published
Support Status: verified
Execution Status: ready
Prerequisites:
- A Flask project that builds and starts with the documented commands (pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template)
- A PostgreSQL driver reading DATABASE_URL at runtime (auto-provisioned when omitted, or supplied with --env)
- A bucket from
ample bucket createwith its credentials passed as encrypted S3_* environment variables - An Ample account token with servers:write, databases:read, buckets:read
Workflow Steps
- Build and start: pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template. The server must bind 0.0.0.0 on PORT.
- Implement the pattern on PostgreSQL: The fixture's module implements browser file uploads: content-type and size validation that rejects disallowed files, an object written to a private bucket and a row linking the record to the object key (reject=ok upload=ok linked=ok). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.
- Wire object storage: Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket.
- Deploy: Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
- Verify: Fetch the live URL and the pattern self-test route(s) (/p/browser-file-uploads) from the example; then run your own checks. On failure read
ample logs --kind buildthen--kind runtime.
Input Schema
{
"type": "object",
"properties": {
"env": {
"description": "Encrypted environment variables (bucket credentials, secrets)",
"type": "array",
"items": {
"pattern": "^[A-Z][A-Z0-9_]*=.*$",
"type": "string"
},
"maxItems": 50
},
"name": {
"description": "App name",
"type": "string",
"minLength": 1,
"maxLength": 63,
"pattern": "^[a-z0-9-]+$"
},
"path": {
"description": "Project directory or ample.toml service",
"type": "string",
"minLength": 1,
"maxLength": 512
},
"release_command": {
"description": "Migration command run before activation",
"type": "string",
"maxLength": 512
},
"start": {
"description": "Start command (Python apps pass one explicitly)",
"type": "string",
"maxLength": 512
}
},
"required": ["env", "name", "path", "start"],
"additionalProperties": false
}
Cost Estimate
- Currency: USD
- Monthly Amount: 10.0
- Components:
- App Server: s-1vcpu-1gb
- Managed PostgreSQL Database: s-1vcpu-1gb
Note: Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Limitations
- Verified on the python-3.12 template at s-1vcpu-1gb with the example fixture; other sizes, templates and Flask major versions are not verified.
- The reporting dashboard itself (your upload UI, allowed types, size limits and virus scanning) is application code and was not separately tested; the pattern checks are what was verified.
- Apps auto-pause when idle and wake on the next request; always-on is an operator setting, not a plan feature.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified; apps and their databases are placed together.
Evidence Summary
- Kind: canary_run Summary: Flask pattern fixture deployed on Ample; checks passed for browser-file-uploads and configuration-secrets. Observed At: 2026-09-21T01:14:18Z Expires At: 2027-03-20T01:14:18Z
Examples
- Title: Flask pattern fixture Description: Multi-pattern Flask app whose browser file uploads module was checked live.