django.md
Video production: client portal using Django
Summary
A client portal blueprint for video production built with Django on Ample. Domain schema: customer_workspaces (client_name, project_count): client organizations; projects (workspace_id, title, stage, delivery_due_at): productions in flight; cuts (project_id, version, object_key, review_status, reviewed_at): versioned cuts for review; customer_assets (workspace_id, project_id, object_key, visibility): final deliverables and raw footage access; document_access (document_id, principal_reference, role, granted_at): who may read which document. Public information: showreel and services, production process, contact. Kept out of scope until handling is reviewed: unreleased footage, talent releases and contracts, client brand material. Footage is large and confidential; the storage checks here use small objects, so verify large-file behavior separately. Technical basis verified on Django: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- A Django project (pip install into .ample/python from requirements.txt, then waitress serving project.wsgi from run.py reading PORT on the python-3.12 template)
- A PostgreSQL driver reading DATABASE_URL (auto-provisioned when omitted)
- Bucket credentials from
ample bucket createpassed as encrypted S3_* environment variables - A review of which video production data classes may be handled at all; this blueprint models public information only
Exact tested configuration
- template:
python-3.12 - runtime:
python - size:
s-1vcpu-1gb - install:
python3 -m pip install --target .ample/python -r requirements.txt - start:
PYTHONPATH=.ample/python:${PYTHONPATH:-} python3 run.py
Steps
Model the video production domain. Create the tables customer_workspaces, projects, cuts, customer_assets, document_access. Client organizations lives in customer_workspaces; keep the sensitive classes (unreleased footage, talent releases and contracts, client brand material) out of this schema.
Workflow step 1. Model client entities and engagement periods; every document belongs to one engagement
Workflow step 2. Authorize by client entity and role before any storage access (401 without identity, 403 for the wrong client)
Workflow step 3. Store documents in the private bucket and stream them through the app
Workflow step 4. Deploy and verify the negative authorization tests and an authorized download
Deploy. Run the synchronous deploy once and read the result. Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --start "python3 run.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...Verify. Run the pattern self-test(s) from the example (/p/private-document-library) and your own acceptance checks for the video production workflow.
ample logs <deployment_id> --kind build
Tested examples
- Django pattern fixture (tests/deploy-canaries/django-patterns): Verified private document library basis for this blueprint.
Success checks
- app responds on its public URL (
/on the live URL, expect ample canary django patterns) - private-document-library self-test from the example (
/p/private-document-libraryon the live URL, expect see the pattern fixture checks)
Limitations
- The technical basis (private document library on Django) was verified with the pattern fixture; the video production schema and workflow are an original design for this blueprint and were not executed as a separate application.
- No health, financial, privacy or other compliance claim is made. Footage is large and confidential; the storage checks here use small objects, so verify large-file behavior separately.
- Public content and synthetic examples only until actual data-handling requirements have been reviewed.
- Verified on the python-3.12 template at s-1vcpu-1gb; region, request-duration limits and other sizes are unknown or unverified.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified.
- PutObject and GetObject with path-style addressing are verified; other S3 operations and CDN cache rules are not.
Cost estimate
Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Verification evidence
- canary_run on 2026-09-20T03:31:44Z at revision
03b6402b1b3e19178985f08ea4033804521d85d4-dirty (CLI b75e104): Django pattern fixture deployed on Ample (pip install into .ample/python from requirements.txt, then waitress serving project.wsgi from run.py reading PORT on the python-3.12 template); the private document library checks passed: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). The blueprint's Video production schema and workflow below build on that verified basis and were not separately executed. (expires 2027-03-19T03:31:44Z)
Execution binding
MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:read, buckets:read.