laravel.md
Travel operators: reporting dashboard using Laravel
Summary
A reporting dashboard blueprint for travel operators built with Laravel on Ample. Domain schema: listings (reference, destination, departure_dates, price_from, publishing_status, agency_id): trips as listings with publishing status; agencies (name, license_number, region): operators or branches; suppliers (name, type, agency_id, status): hotels and transport suppliers; reports (agency_id, period, object_key, generated_at): branch sales reports; exports (id, definition, object_key, row_count, generated_at, authorized_role): generated artifacts and who may download them. Public information: published trips and departure dates, destination guides, booking conditions. Kept out of scope until handling is reviewed: traveler passports and identity, payment details, supplier contracts. Passport and payment data are regulated; only published trips and branch reporting are modeled. Technical basis verified on Laravel: an export query rendered to a CSV artifact stored with metadata in a private bucket and returned only to an authorized caller (401 without token, export=ok rows=3).
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- A Laravel project (composer install --no-dev from composer.lock, then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables - A review of which travel operators data classes may be handled at all; this blueprint models public information only
Steps
Model the travel operators domain. Create the tables listings, agencies, suppliers, reports, exports. Trips as listings with publishing status lives in listings; keep the sensitive classes (traveler passports and identity, payment details, supplier contracts) out of this schema.
Workflow step 1. Model report definitions scoped to the agency
Workflow step 2. Generate report artifacts from queries and store them with metadata
Workflow step 3. Authorize downloads (401 without identity)
Workflow step 4. Deploy and verify an authorized export and the rejected anonymous request
Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...Verify. Run the pattern self-test(s) from the example (/p/generated-downloads) and your own acceptance checks for the travel operators workflow.
ample logs <deployment_id> --kind build
Limitations
- The technical basis (generated downloads on Laravel) was verified with the pattern fixture; the travel operators schema and workflow are an original design for this blueprint and were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Passport and payment data are regulated; only published trips and branch reporting are modeled.
- Public content and synthetic examples only until actual data-handling requirements have been reviewed.
Cost estimate
Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Verification evidence
- canary_run on 2026-09-20T20:36:21Z at revision
118ad1c6d7d23d4c2ce069254bab9ec9d37cd57b-dirty (CLI 118ad1c): Laravel pattern fixture deployed on Ample (composer install --no-dev from composer.lock, then FrankenPHP serving public/ (php-server with the index.php fallback) reading PORT on the php-8.5 template); the generated downloads checks passed: an export query rendered to a CSV artifact stored with metadata in a private bucket and returned only to an authorized caller (401 without token, export=ok rows=3). The blueprint's Travel operators schema and workflow below build on that verified basis and were not separately executed. (expires 2027-03-19T20:36:21Z)
Execution binding
MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:read, buckets:read.