worker state.md
Host ai workflow runner with ASP.NET Core: worker execution and job state
Summary
Deploy a ai workflow runner built with ASP.NET Core as a public web service plus a dedicated worker process on Ample. ample plan --write discovers both services and their shared database and writes ample.toml; ample up reconciles the topology: a managed PostgreSQL 16 database, a public web microVM and a private worker microVM (kind worker, no public URL), both reading DATABASE_URL. Verified on ASP.NET Core: a separately deployed worker service (kind worker, no public URL) sharing a declared managed PostgreSQL database with the web service, consuming a jobs table with row locks and marking jobs done once (worker=done attempts=1). Not separately tested: your job payloads, retry policy and scheduling; treat the ai workflow runner-specific behavior as your application code.
Infrastructure requirements
- Verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
Prerequisites
- A repository with the web app and the worker as separate service directories, each building and starting with the documented commands (dotnet publish -c Release -o out in the builder, then dotnet
.dll on the dotnet-10 template with ASPNETCORE_URLS bound to PORT; the worker starts with dotnet of its own console project (plain Npgsql) and binds no port) - Both services read DATABASE_URL at runtime and share one jobs table; the worker claims rows with SELECT ... FOR UPDATE SKIP LOCKED and marks them done once
- An Ample account token with servers:write and databases:write (ample up creates the database)
Exact tested configuration
- template:
dotnet-10 - runtime:
dotnet - size:
s-1vcpu-1gb - build:
dotnet publish -c Release -o out - start:
ASPNETCORE_URLS=http://0.0.0.0:$PORT dotnet out/$(basename $(ls out/*.runtimeconfig.json | head -n 1) .runtimeconfig.json).dll
Steps
- Plan the topology. Run the planner once. It discovers the web and worker services, infers kind = "worker" for the process without a port, declares the database each service needs, and writes ample.toml. Exit 2 means it left questions in the manifest; answer them with --answer or by editing the file.
ample plan --write .
- Share one database. Keep a single [databases.main] with engine = "postgres", drop any per-service database the planner added, and set DATABASE_URL = { database = "main" } under both [services.web.env] and [services.worker.env].
ample plan --offline .
- Apply. Reconcile the whole manifest in dependency order: the database first, then both services. It is idempotent and never destructive; exit 0 means everything applied, 2 needs input, 1 a failed resource (independent siblings still proceed and re-running resumes).
ample up .
- Verify. Fetch the web service URL and its worker status route (/p/worker-queue/status in the example) and confirm the worker processed the enqueued job; on failure read the worker service's runtime logs.
ample logs <deployment_id> --kind runtime
Tested examples
- ASP.NET Core web + worker fixture: A ASP.NET Core web app (apps/web) and a worker process (apps/worker) sharing one managed PostgreSQL database; the queue module is under tests/deploy-canaries/_pattern-modules.
Success checks
- web service responds on its public URL (
/on the live URL, expect ample canary asp net core patterns) - worker consumed the enqueued job (
/p/worker-queue/statuson the live URL, expect worker=done attempts=1 result=processed-by-worker)
Limitations
- Verified on the dotnet-10 template at s-1vcpu-1gb for both services with the example fixture; other sizes, templates and ASP.NET Core major versions are not verified.
- The ai workflow runner itself (your job payloads, retry policy and scheduling) is application code and was not separately tested; the worker-queue check is what was verified.
- The worker is a single long-running process supervised in its own microVM; there is no scheduler, cron or horizontal worker scaling in this recipe, and the check ran immediately after deploy so idle behavior of the worker VM is not verified.
- The worker service is private: it has no public URL and is reached only through the shared database; both services are placed with their database.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified; apps and their databases are placed together.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
Cost estimate
Estimated 15.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- web server x1
s-1vcpu-1gb: 5.00 USD - worker server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes for the web service, the worker service and the database; apps auto-pause when idle.
Verification evidence
- canary_run on 2026-09-20T23:09:18Z at revision
deb0e34-dirty (CLI 0.1.21): ASP.NET Core web service plus a separate ASP.NET Core worker process deployed on Ample withample plan --writethenample up(dotnet publish -c Release -o out in the builder, then dotnet.dll on the dotnet-10 template with ASPNETCORE_URLS bound to PORT); the web service enqueued a job that the private worker service consumed from the shared managed PostgreSQL database. Pattern proof: a separately deployed worker service (kind worker, no public URL) sharing a declared managed PostgreSQL database with the web service, consuming a jobs table with row locks and marking jobs done once (worker=done attempts=1). (expires 2027-03-19T23:09:18Z)
Last verified: 2026-09-20T23:09:18Z
Execution binding
MCP tool ample_up, schema hash db7ca0facfe2cd28 observed 2026-09-21T03:19:59.525781+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:write.