next js.md
Tutoring centers: member portal using Next.js
Summary
A member portal blueprint for tutoring centers built with Next.js on Ample. Domain schema:
- course_groups (subject, level, start_at, end_at, capacity): tutoring groups;
- memberships (course_group_id, student_reference, guardian_reference, role): students, guardians and tutors;
- sessions (course_group_id, starts_at, tutor, attendance_count): session events;
- materials (course_group_id, title, object_key, visibility): worksheets and answer keys;
- document_access (document_id, principal_reference, role, granted_at): who may read which document.
Public information: subjects and levels, schedule and locations, tutor qualifications. Kept out of scope until handling is reviewed: minor students and guardian identity, progress reports.
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- A Next.js project (next build then next start -H 0.0.0.0 -p $PORT on the node-22 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables - A review of which tutoring centers data classes may be handled at all; this blueprint models public information only
Steps
Model the tutoring centers domain. Create the tables course_groups, memberships, sessions, materials, document_access. Tutoring groups lives in course_groups; keep the sensitive classes (minor students and guardian identity, progress reports) out of this schema.
Workflow step 1. Model groups, memberships and roles
Workflow step 2. Authorize access to materials by membership and role (401, 403 negative tests)
Workflow step 3. Store materials in the private bucket and stream them through the app
Workflow step 4. Deploy and verify the negative tests and an authorized download
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...Verify. Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the tutoring centers workflow.
ample logs <deployment_id> --kind build
Tested examples
- Next.js pattern fixture (tests/deploy-canaries/next-js-patterns): Verified private document library basis for this blueprint.
Cost estimate
Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Verification evidence
- canary_run on 2026-09-21T02:34:39Z: Next.js pattern fixture deployed on Ample (next build then next start -H 0.0.0.0 -p $PORT on the node-22 template); the private document library checks passed: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). The blueprint's Tutoring centers schema and workflow below build on that verified basis and were not separately executed.
Last verified: 2026-09-21T02:34:39Z
Input schema
{
"additionalProperties": false,
"properties": {
"env": {
"description": "Encrypted environment variables",
"items": {
"pattern": "^[A-Z][A-Z0-9_]*=.*$",
"type": "string"
},
"maxItems": 50,
"type": "array"
},
"name": {
"description": "App name",
"maxLength": 63,
"minLength": 1,
"pattern": "^[a-z0-9-]+$",
"type": "string"
},
"path": {
"description": "Project directory or ample.toml service",
"maxLength": 512,
"minLength": 1,
"type": "string"
},
"release_command": {
"description": "Migration command run before activation",
"maxLength": 512,
"type": "string"
}
},
"required": [
"env",
"name",
"path"
],
"type": "object"
}