laravel.md
B2B SaaS: Asset Library Using Laravel
Summary
A asset library blueprint for B2B SaaS built with Laravel on Ample. Domain schema: customer_workspaces (name, plan, seat_count, created_at): customer tenants; workspace_members (workspace_id, email, role): members and roles per workspace; doc_versions (product_version, title, object_key, published_at): versioned product documentation; customer_assets (workspace_id, title, object_key, visibility): assets scoped to one customer; uploads (id, owner_reference, object_key, content_type, size, uploaded_at): validated uploads linked to their owner. Public information: product documentation by version, pricing and plan comparison, status, and changelog. Kept out of scope until handling is reviewed: customer data inside workspaces, usage and billing records, support attachments. Customer workspace data is tenant-scoped; isolation is application-enforced and no security certification is claimed. Technical basis verified on Laravel: content-type and size validation that rejects disallowed files, an object written to a private bucket and a row linking the record to the object key (reject=ok upload=ok linked=ok).
Infrastructure Requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- A Laravel project (composer install --no-dev from composer.lock, then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables - A review of which B2B SaaS data classes may be handled at all; this blueprint models public information only.
Exact Tested Configuration
- Template:
php-8.5 - Runtime:
php - Size:
s-1vcpu-1gb - Install:
composer install --no-dev --prefer-dist --no-interaction --no-progress --optimize-autoloader - Start:
frankenphp php-server --listen :$PORT --root public
Steps
Model the B2B SaaS domain. Create the tables customer_workspaces, workspace_members, doc_versions, customer_assets, uploads. Customer tenants live in customer_workspaces; keep the sensitive classes (customer data inside workspaces, usage and billing records, support attachments) out of this schema.
Workflow Step 1. Model assets linked to their owning group or workspace.
Workflow Step 2. Validate uploads and store them in the private bucket; link each object to its row.
Workflow Step 3. Authorize downloads by membership.
Workflow Step 4. Deploy and verify rejection of disallowed files and a linked upload.
Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...Verify. Run the pattern self-test(s) from the example (/p/browser-file-uploads) and your own acceptance checks for the B2B SaaS workflow.
ample logs <deployment_id> --kind build
Tested Examples
- Laravel Pattern Fixture (tests/deploy-canaries/laravel-patterns): Verified browser file uploads basis for this blueprint.
Success Checks
- App responds on its public URL (
/on the live URL, expect ample canary Laravel patterns). - Browser-file-uploads self-test from the example (
/p/browser-file-uploadson the live URL, expect see the pattern fixture checks).
Limitations
- The technical basis (browser file uploads on Laravel) was verified with the pattern fixture; the B2B SaaS schema and workflow are an original design for this blueprint and were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Customer workspace data is tenant-scoped; isolation is application-enforced and no security certification is claimed.
- Public content and synthetic examples only until actual data-handling requirements have been reviewed.
- Verified on the php-8.5 template at s-1vcpu-1gb; region, request-duration limits and other sizes are unknown or unverified.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified.
- PutObject and GetObject with path-style addressing are verified; other S3 operations and CDN cache rules are not.
Cost Estimate
Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- App server x1
s-1vcpu-1gb: 5.00 USD - Managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Verification Evidence
- canary_run on 2026-09-20T20:36:21Z at revision
118ad1c6d7d23d4c2ce069254bab9ec9d37cd57b-dirty (CLI 118ad1c): Laravel pattern fixture deployed on Ample (composer install --no-dev from composer.lock, then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template); the browser file uploads checks passed: content-type and size validation that rejects disallowed files, an object written to a private bucket and a row linking the record to the object key (reject=ok upload=ok linked=ok). The blueprint's B2B SaaS schema and workflow below build on that verified basis and were not separately executed. (expires 2027-03-19T20:36:21Z)
Last verified: 2026-09-20T20:36:21Z
Execution Binding
MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:read, buckets:read.