laravel.md
Membership associations: asset library using Laravel
Summary
A asset library blueprint for membership associations built with Laravel on Ample. Domain schema: course_groups (chapter_or_program, start_at, end_at): chapters and programs as groups; memberships (course_group_id, member_email, tier, role, renewed_at): members and roles; sessions (course_group_id, starts_at, title, venue): meetings and events; materials (course_group_id, title, object_key, visibility): member resources; uploads (id, owner_reference, object_key, content_type, size, uploaded_at): validated uploads linked to their owner. Public information: about, chapters and benefits, public events, join information. Kept out of scope until handling is reviewed: member directory details, dues and payment records. Member directories are personal data; only public events and member-authorized resources are modeled. Technical basis verified on Laravel: content-type and size validation that rejects disallowed files, an object written to a private bucket and a row linking the record to the object key (reject=ok upload=ok linked=ok).
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- A Laravel project (composer install --no-dev from composer.lock, then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables - A review of which membership associations data classes may be handled at all; this blueprint models public information only
Exact tested configuration
- template:
php-8.5 - runtime:
php - size:
s-1vcpu-1gb - install:
composer install --no-dev --prefer-dist --no-interaction --no-progress --optimize-autoloader - start:
frankenphp php-server --listen :$PORT --root public
Steps
Model the membership associations domain. Create the tables course_groups, memberships, sessions, materials, uploads. Chapters and programs as groups lives in course_groups; keep the sensitive classes (member directory details, dues and payment records) out of this schema.
Workflow step 1. Model assets linked to their owning group or workspace.
Workflow step 2. Validate uploads and store them in the private bucket; link each object to its row.
Workflow step 3. Authorize downloads by membership.
Workflow step 4. Deploy and verify rejection of disallowed files and a linked upload.
Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...Verify. Run the pattern self-test(s) from the example (/p/browser-file-uploads) and your own acceptance checks for the membership associations workflow.
ample logs <deployment_id> --kind build
Tested examples
- Laravel pattern fixture (tests/deploy-canaries/laravel-patterns): Verified browser file uploads basis for this blueprint.
Success checks
- App responds on its public URL (
/on the live URL, expect ample canary laravel patterns) - Browser-file-uploads self-test from the example (
/p/browser-file-uploadson the live URL, expect see the pattern fixture checks)
Limitations
- The technical basis (browser file uploads on Laravel) was verified with the pattern fixture; the membership associations schema and workflow are an original design for this blueprint and were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Member directories are personal data; only public events and member-authorized resources are modeled.
- Public content and synthetic examples only until actual data-handling requirements have been reviewed.
- Verified on the php-8.5 template at s-1vcpu-1gb; region, request-duration limits and other sizes are unknown or unverified.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified.
- PutObject and GetObject with path-style addressing are verified; other S3 operations and CDN cache rules are not.