public site.md
Host knowledge base with Flask: public-site delivery
Summary
Deploy a knowledge base built with Flask on Ample using the public web service pattern. Compute runs the app in an isolated microVM behind a public HTTPS URL, and a published bucket serves public assets from the CDN host. Verified on Flask: a versioned, immutable-cached asset uploaded to a published bucket and served from the CDN URL alongside the app's own public HTTPS URL. Not separately tested: your site content and build; treat the knowledge base-specific behavior as your application code.
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- CDN: verified (The CDN host serves objects from published buckets. It does not front app compute and is not a cache or key-value store.)
Prerequisites
- A Flask project that builds and starts with the documented commands (pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template)
- A bucket from
ample bucket createwith its credentials passed as encrypted S3_* environment variables - An Ample account token with servers:write, buckets:read
Exact tested configuration
- template:
python-3.12 - runtime:
python - size:
s-1vcpu-1gb - install:
python3 -m pip install --target .ample/python -r requirements.txt - start:
PYTHONPATH=.ample/python:${PYTHONPATH:-} python3 app.py
Steps
Build and start. pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template. The server must bind 0.0.0.0 on PORT.
Wire object storage. Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.
Deploy. Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --start "python3 app.py" --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...Verify. Fetch the live URL and the pattern self-test route(s) (/p/versioned-static-assets) from the example; then run your own checks. On failure read
ample logs <deployment_id> --kind buildthen--kind runtime.ample logs <deployment_id> --kind build
Tested examples
- Flask pattern fixture (tests/deploy-canaries/flask-patterns): Multi-pattern Flask app whose public web service module was checked live; the module is under tests/deploy-canaries/_pattern-modules.
Success checks
- app responds on its public URL (
/on the live URL, expect ample canary flask patterns) - versioned-static-assets self-test (
/p/versioned-static-assetson the live URL, expect a CDN URL whose content is served publicly)
Limitations
- Verified on the python-3.12 template at s-1vcpu-1gb with the example fixture; other sizes, templates and Flask major versions are not verified.
- The knowledge base itself (your site content and build) is application code and was not separately tested; the pattern checks are what was verified.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
- Apps auto-pause when idle and wake on the next request; always-on is an operator setting, not a plan feature.
- PutObject and GetObject with path-style addressing are verified; multipart upload, listing, presigned URLs and lifecycle rules are not.
- The CDN serves published-bucket objects only; cache rules, purge and TTL control are not verified (the fixture sets Cache-Control on upload and versions keys).
Cost estimate
Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
##Verification evidence
- canary_run on 2026-09-21T01:14:18Z at revision
50dbac567d2c5cc8e55e6c748a646be0025d9cfb-dirty (CLI 0.1.21): Flask pattern fixture deployed on Ample (pip install into .ample/python from requirements.txt, then waitress from app.py reading PORT on the python-3.12 template); checks passed for versioned-static-assets and configuration-secrets. Pattern proof: a versioned, immutable-cached asset uploaded to a published bucket and served from the CDN URL alongside the app's own public HTTPS URL. (expires 2027-03-20T01:14:18Z) - canary_run on 2026-09-20T01:54:51Z at revision
199ff1dfd52683832ae75d3f98b53a7a4bff7f96-dirty (CLI e3181f5): The same Flask app deployed with a --release-command migration; the marker it created was readable after activation. (expires 2027-03-19T01:54:51Z)
Last verified: 2026-09-21T01:14:18Z