Host knowledge base with Phoenix: Postgres-backed content | Ample
INFRASTRUCTURE
What it needs
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
- CDN: verified (The CDN host serves objects from published buckets. It does not front app compute and is not a cache or key-value store.)
PREREQUISITES
Before you start
- A Phoenix project that builds and starts with the documented commands (mix deps.get, MIX_ENV=prod mix compile and mix release in the builder, then the release bin script with PHX_SERVER=true on the elixir-1.18 template; PORT, DATABASE_URL and SECRET_KEY_BASE read in config/runtime.exs)
- A PostgreSQL driver reading DATABASE_URL at runtime (auto-provisioned when omitted, or supplied with --env)
- A bucket from
ample bucket createwith its credentials passed as encrypted S3_* environment variables - An Ample account token with servers:write, databases:read, buckets:read
TESTED CONFIGURATION
Exactly what was tested
- build:
MIX_ENV=prod mix compile && MIX_ENV=prod mix release --overwrite - install:
mix local.hex --force && mix local.rebar --force && MIX_ENV=prod mix deps.get --only prod - runtime:
elixir - size:
s-1vcpu-1gb - start:
PHX_SERVER=true _build/prod/rel/$(ls _build/prod/rel | head -n 1)/bin/$(ls _build/prod/rel | head -n 1) start - template:
elixir-1.18
STEP BY STEP
How to do it
Build and start
mix deps.get, MIX_ENV=prod mix compile and mix release in the builder, then the release bin script with PHX_SERVER=true on the elixir-1.18 template; PORT, DATABASE_URL and SECRET_KEY_BASE read in config/runtime.exs. The server must bind 0.0.0.0 on PORT.Implement the pattern on PostgreSQL
The fixture's module implements relational records: a workspace-scoped table, an explicit state machine (draft to review to published) that rejects invalid transitions, and a cross-workspace read that returns nothing (transitions=true isolation=true). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.Wire object storage
Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket. Publish only the bucket that serves public assets and reference its CDN URL.Deploy
Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.
ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=... --env CDN_PUBLIC_URL=...
- Verify
Fetch the live URL and the pattern self-test route(s) (/p/relational-records) from the example; then run your own checks. On failure readample logs <deployment_id> --kind buildthen--kind runtime.
ample logs <deployment_id> --kind build
EXAMPLES
Tested examples
- Phoenix pattern fixture (
tests/deploy-canaries/phoenix-patterns): Multi-pattern Phoenix app whose relational records module was checked live; the module is under tests/deploy-canaries/_pattern-modules.
SUCCESS CHECKS
How to know it worked
- app responds on its public URL (
/on the live URL, expect ample canary phoenix patterns) - relational-records self-test (
/p/relational-recordson the live URL, expect records=ok transitions=true isolation=true)
LIMITATIONS
Know the limits
- Verified on the elixir-1.18 template at s-1vcpu-1gb with the example fixture; other sizes, templates and Phoenix major versions are not verified.
- The knowledge base itself (your record schema, states and access rules) is application code and was not separately tested; the pattern checks are what was verified.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
- Apps auto-pause when idle and wake on the next request; always-on is an operator setting, not a plan feature.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified; apps and their databases are placed together.
- PutObject and GetObject with path-style addressing are verified; multipart upload, listing, presigned URLs and lifecycle rules are not.
- The CDN serves published-bucket objects only; cache rules, purge and TTL control are not verified (the fixture sets Cache-Control on upload and versions keys).
COST
Cost estimate
Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.
EVIDENCE
Verification evidence
- canary_run on 2026-09-20T23:45:31Z at revision
4d1511e574302f3904b75088bd4048a0975218b3-dirty (CLI 0.1.21): Phoenix pattern fixture deployed on Ample (mix deps.get, MIX_ENV=prod mix compile and mix release in the builder, then the release bin script with PHX_SERVER=true on the elixir-1.18 template; PORT, DATABASE_URL and SECRET_KEY_BASE read in config/runtime.exs); checks passed for relational-records and configuration-secrets. Pattern proof: a workspace-scoped table, an explicit state machine (draft to review to published) that rejects invalid transitions, and a cross-workspace read that returns nothing (transitions=true isolation=true). (expires 2027-03-19T23:45:31Z) - canary_run on 2026-09-20T23:45:31Z at revision
4d1511e574302f3904b75088bd4048a0975218b3-dirty (CLI 0.1.21): The same Phoenix app deployed with a --release-command migration; the marker it created was readable after activation. (expires 2027-03-19T23:45:31Z)
EXECUTION
Execution binding
MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f. Binding state at export: current. Required scopes: servers:write, databases:read, buckets:read.
NEXT ACTIONS
Typed next actions
- Browse the catalog index (
GET /v1/catalogon the api origin; authentication not required, approval not required) - Search published recipes by intent, stack and constraints (
POST /v1/catalog/searchon the api origin; authentication not required, approval not required) - Prepare a side-effect-free deployment plan for an authorized project (
POST /v1/catalog/planon the api origin; authentication required, approval not required) - Read the existing agent authentication setup (
GET /mcp/setupon the api origin; authentication not required, approval not required) - Browse Knowledge base (
GET /v1/catalog/nodes/workload%3Aknowledge-baseon the api origin; authentication not required, approval not required) - Browse Phoenix (
GET /v1/catalog/nodes/stack%3Aframework-phoenixon the api origin; authentication not required, approval not required) - Browse Relational records (
GET /v1/catalog/nodes/pattern%3Arelational-recordson the api origin; authentication not required, approval not required) - Browse Deploy web app (
GET /v1/catalog/nodes/intent%3Adeploy-web-appon the api origin; authentication not required, approval not required)
Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.