Membership associations: asset library using Next.js | Ample

INFRASTRUCTURE

What it needs

Before you start

Exactly what was tested

How to do it

  1. Model the membership associations domain
    Create the tables course_groups, memberships, sessions, materials, uploads. Chapters and programs as groups lives in course_groups; keep the sensitive classes (member directory details, dues and payment records) out of this schema.

  2. Workflow step 1
    Model assets linked to their owning group or workspace

  3. Workflow step 2
    Validate uploads and store them in the private bucket; link each object to its row

  4. Workflow step 3
    Authorize downloads by membership

  5. Workflow step 4
    Deploy and verify rejection of disallowed files and a linked upload

  6. Deploy
    Run the synchronous deploy once and read the result. Re-running with no change is a no-op.

   ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. Verify
    Run the pattern self-test(s) from the example (/p/browser-file-uploads) and your own acceptance checks for the membership associations workflow.
   ample logs <deployment_id> --kind build

Tested examples

How to know it worked

Know the limits

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

Verification evidence

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f. Binding state at export: current. Required scopes: servers:write, databases:read, buckets:read.

Typed next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.