page:recipes:vendor portal:flask:public profiles

Host vendor portal with Flask: public profile assets

Summary

Deploy a vendor portal built with Flask on Ample using the public image delivery pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables, and a published bucket serves public assets from the CDN host. Verified on Flask: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Not separately tested: your image processing and profile-media rules; treat the vendor portal-specific behavior as your application code.

Representative Queries

Resource Requirements

Infrastructure Requirements

Compute

Postgres

S3-compatible object storage

CDN

Prerequisites

Workflow Steps

1. Build and start

pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template. The server must bind 0.0.0.0 on PORT.

2. Implement the pattern on PostgreSQL

The fixture's module implements public image delivery: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.

3. Wire object storage

Create the bucket(s), then pass endpoint, region, bucket, and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.

4. Deploy

Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op. Command: ample deploy . --name --public --start "python3 app.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...

5. Verify

Fetch the live URL and the pattern self-test route(s) (/p/public-media-library, /p/private-document-library) from the example; then run your own checks. On failure read ample logs --kind build then --kind runtime. Command: ample logs --kind build

Limitations

Cost Estimate

Components

Note: Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.