laravel.md
Management consultancies: client portal using Laravel
Summary
A client portal blueprint for management consultancies built with Laravel on Ample. Domain schema: client_entities (name, industry, primary_contact_role): client organizations; engagements (client_entity_id, scope_title, phase, period_start, period_end): engagement periods and phases; workstreams (engagement_id, name, owner, status, due_at): tracked workstreams; deliverables (engagement_id, title, version, object_key, released_at): versioned deliverables shared with the client; document_access (document_id, principal_reference, role, granted_at): who may read which document. Public information: service offerings and case studies (anonymized), consultant profiles, engagement model. Kept out of scope until handling is reviewed: client strategy documents, financial models, interview notes. Client strategy material is confidential; authorization is modeled per engagement.
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary.)
Prerequisites
- A Laravel project (composer install --no-dev from composer.lock, then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables
Exact tested configuration
- template:
php-8.5 - runtime:
php - size:
s-1vcpu-1gb - install:
composer install --no-dev --prefer-dist --no-interaction --no-progress --optimize-autoloader - start:
frankenphp php-server --listen :$PORT --root public
Steps
- Model the management consultancies domain. Create the tables client_entities, engagements, workstreams, deliverables, document_access.
- Workflow step 1. Model client entities and engagement periods; every document belongs to one engagement.
- Workflow step 2. Authorize by client entity and role before any storage access.
- Workflow step 3. Store documents in the private bucket and stream them through the app.
- Workflow step 4. Deploy and verify the negative authorization tests and an authorized download.
- Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... - Verify. Run the pattern self-test(s) from the example and your own acceptance checks for the management consultancies workflow.
ample logs <deployment_id> --kind build
Tested examples
- Laravel pattern fixture (tests/deploy-canaries/laravel-patterns): Verified private document library basis for this blueprint.
Success checks
- App responds on its public URL.
Limitations
- The technical basis was verified with the pattern fixture; the management consultancies schema and workflow are an original design for this blueprint and were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Client strategy material is confidential.
- Public content and synthetic examples only until actual data-handling requirements have been reviewed.
Cost estimate
Estimated 10.00 USD per month.
- App server x1
s-1vcpu-1gb: 5.00 USD - Managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Verification evidence
- Canary_run on 2026-09-20T20:36:21Z at revision
118ad1c6d7d23d4c2ce069254bab9ec9d37cd57b-dirty (CLI 118ad1c): Laravel pattern fixture deployed on Ample.
Execution binding
MCP tool ample_deploy (registry mcp:ample_deploy).
Input schema
- env: Encrypted environment variables
- name: App name
- path: Project directory or ample.toml service
- release_command: Migration command run before activation.