django.md

B2B SaaS: asset library using Django

Summary

A asset library blueprint for b2b saas built with Django on Ample. Domain schema: customer_workspaces (name, plan, seat_count, created_at): customer tenants; workspace_members (workspace_id, email, role): members and roles per workspace; doc_versions (product_version, title, object_key, published_at): versioned product documentation; customer_assets (workspace_id, title, object_key, visibility): assets scoped to one customer; uploads (id, owner_reference, object_key, content_type, size, uploaded_at): validated uploads linked to their owner. Public information: product documentation by version, pricing and plan comparison, status and changelog. Kept out of scope until handling is reviewed: customer data inside workspaces, usage and billing records, support attachments. Customer workspace data is tenant-scoped; isolation is application-enforced and no security certification is claimed. Technical basis verified on Django: content-type and size validation that rejects disallowed files, an object written to a private bucket and a row linking the record to the object key (reject=ok upload=ok linked=ok).

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Model the b2b saas domain. Create the tables customer_workspaces, workspace_members, doc_versions, customer_assets, uploads. Customer tenants lives in customer_workspaces; keep the sensitive classes (customer data inside workspaces, usage and billing records, support attachments) out of this schema.
  2. Workflow step 1. Model assets linked to their owning group or workspace
  3. Workflow step 2. Validate uploads and store them in the private bucket; link each object to its row
  4. Workflow step 3. Authorize downloads by membership
  5. Workflow step 4. Deploy and verify rejection of disallowed files and a linked upload
  6. Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
   ample deploy . --name <app-name> --public --start "python3 run.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. Verify. Run the pattern self-test(s) from the example (/p/browser-file-uploads) and your own acceptance checks for the b2b saas workflow.
   ample logs <deployment_id> --kind build

Tested examples

Success checks

Limitations

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

Verification evidence

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:read, buckets:read.