Enforce private-file authorization for Flask | Ample

INFRASTRUCTURE

What it needs

PREREQUISITES

Before you start

TESTED CONFIGURATION

Exactly what was tested

STEP BY STEP

How to do it

  1. 1

Build and start

pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template; the server must bind 0.0.0.0 on PORT.

  1. 2

Create the bucket and pass its credentials

Create it once with ample bucket create, then pass endpoint, region, bucket and keys with --env; use path-style addressing.

ample deploy . --name <app-name> --public --start "python3 app.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. 3

Authorize before touching storage

Return 401 for unauthenticated requests and 403 for the wrong role; keep the bucket unpublished and stream objects through the app.

  1. 4

Verify

Fetch the live URL and /p/private-document-library on the example; on failure read the build and runtime logs.

ample logs <deployment_id> --kind build

EXAMPLES

Tested examples

SUCCESS CHECKS

How to know it worked

LIMITATIONS

Know the limits

COST

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps auto-pause when idle. Buckets are allocation-priced per quota and not included.

EVIDENCE

Verification evidence

EXECUTION

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f. Binding state at export: current. Required scopes: servers:write, databases:read, buckets:read.

NEXT ACTIONS

Typed next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.