public profiles.md
Host client portal with Nuxt: public profile assets
Summary
Deploy a client portal built with Nuxt on Ample using the public image delivery pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, a managed PostgreSQL 16 database is auto-provisioned and injected as DATABASE_URL, a private S3-compatible bucket holds objects with credentials delivered as encrypted environment variables, and a published bucket serves public assets from the CDN host. Verified on Nuxt: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Not separately tested: your image processing and profile-media rules; treat the client portal-specific behavior as your application code.
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
- CDN: verified (The CDN host serves objects from published buckets. It does not front app compute and is not a cache or key-value store.)
Prerequisites
- A Nuxt project that builds and starts with the documented commands (nuxt build then node .output/server/index.mjs (reads HOST and PORT) on the node-22 template)
- A PostgreSQL driver reading DATABASE_URL at runtime (auto-provisioned when omitted, or supplied with --env)
- A bucket from
ample bucket createwith its credentials passed as encrypted S3_* environment variables and a second, published bucket for public assets (CDN_*) - An Ample account token with servers:write, databases:read, buckets:read
Steps
Build and start. nuxt build then node .output/server/index.mjs (reads HOST and PORT) on the node-22 template. The server must bind 0.0.0.0 on PORT.
Implement the pattern on PostgreSQL. The fixture's module implements public image delivery: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.
Wire object storage. Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.
Deploy. Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...Verify. Fetch the live URL and the pattern self-test route(s) (/api/p/public-media-library, /api/p/private-document-library) from the example; then run your own checks. On failure read
ample logs <deployment_id> --kind buildthen--kind runtime.ample logs <deployment_id> --kind build
Success checks
- app responds on its public URL (
/on the live URL, expect ample canary nuxt patterns) - public-media-library self-test (
/api/p/public-media-libraryon the live URL, expect a CDN URL whose content is served publicly) - private-document-library self-test (
/api/p/private-document-libraryon the live URL, expect private=ok (with ?role=owner; 401 without, 403 for viewer))
Limitations
- Verified on the node-22 template at s-1vcpu-1gb with the example fixture; other sizes, templates and Nuxt major versions are not verified.
- The client portal itself (your image processing and profile-media rules) is application code and was not separately tested; the pattern checks are what was verified.
- Apps auto-pause when idle and wake on the next request; always-on is an operator setting, not a plan feature.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified; apps and their databases are placed together.
- The CDN serves published-bucket objects only; cache rules, purge and TTL control are not verified (the fixture sets Cache-Control on upload and versions keys).
Cost estimate
Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
Verification evidence
- canary_run on 2026-09-20T03:31:44Z at revision
03b6402b1b3e19178985f08ea4033804521d85d4-dirty (CLI b75e104): Nuxt pattern fixture deployed on Ample (nuxt build then node .output/server/index.mjs (reads HOST and PORT) on the node-22 template); checks passed for public-media-library, private-document-library and configuration-secrets. Pattern proof: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role). (expires 2027-03-19T03:31:44Z) - canary_run on 2026-09-20T01:54:51Z at revision
199ff1dfd52683832ae75d3f98b53a7a4bff7f96-dirty (CLI e3181f5): The same Nuxt app deployed with a --release-command migration; the marker it created was readable after activation. (expires 2027-03-19T01:54:51Z)
Last verified: 2026-09-20T03:31:44Z.