worker state.md
Host mcp server with Axum: worker execution and job state
Summary
Deploy a mcp server built with Axum as a public web service plus a dedicated worker process on Ample. ample plan --write discovers both services and their shared database and writes ample.toml; ample up reconciles the topology: a managed PostgreSQL 16 database, a public web microVM and a private worker microVM (kind worker, no public URL), both reading DATABASE_URL. Verified on Axum: a separately deployed worker service (kind worker, no public URL) sharing a declared managed PostgreSQL database with the web service, consuming a jobs table with row locks and marking jobs done once (worker=done attempts=1). Not separately tested: your job payloads, retry policy and scheduling; treat the mcp server-specific behavior as your application code.
Infrastructure requirements
- Compute: verified (Apps run in isolated x86_64 Firecracker microVMs that auto-pause when idle and wake on request; sizes are the priced VM sizes.)
- Postgres: verified (Managed PostgreSQL 16 runs in its own microVM and is auto-provisioned when an app needs a database and no DATABASE_URL is supplied.)
Prerequisites
- A repository with the web app and the worker as separate service directories (the fixture uses apps/web and apps/worker), each building and starting with the documented commands (cargo build --release in the rust builder image (stable toolchain, Cargo.lock committed, pure-Rust dependencies), then the release binary on the ubuntu-24.04 template reading PORT and DATABASE_URL; the worker starts with its own release binary (plain tokio-postgres) and binds no port)
- Both services read DATABASE_URL at runtime and share one jobs table; the worker claims rows with SELECT ... FOR UPDATE SKIP LOCKED and marks them done once
- An Ample account token with servers:write and databases:write (ample up creates the database)
Exact tested configuration
- template:
ubuntu-24.04 - runtime:
rust - size:
s-1vcpu-2gb - build:
cargo build --release - start:
./$(ls target/release/*.d | grep -v '/lib' | head -n 1 | sed 's/\.d$//')
Steps
- Plan the topology. Run the planner once. It discovers the web and worker services, infers kind = "worker" for the process without a port, declares the database each service needs, and writes ample.toml. Exit 2 means it left questions in the manifest; answer them with --answer or by editing the file.
ample plan --write .
- Share one database. Keep a single [databases.main] with engine = "postgres", drop any per-service database the planner added, and set DATABASE_URL = { database = "main" } under both [services.web.env] and [services.worker.env].
ample plan --offline .
- Apply. Reconcile the whole manifest in dependency order: the database first, then both services. It is idempotent and never destructive; exit 0 means everything applied, 2 needs input, 1 a failed resource (independent siblings still proceed and re-running resumes).
ample up .
- Verify. Fetch the web service URL and its worker status route (/p/worker-queue/status in the example) and confirm the worker processed the enqueued job; on failure read the worker service's runtime logs.
ample logs <deployment_id> --kind runtime
Tested examples
- Axum web + worker fixture (tests/deploy-canaries/axum-worker): A Axum web app (apps/web) and a worker process (apps/worker) sharing one managed PostgreSQL database; the queue module is under tests/deploy-canaries/_pattern-modules.
Success checks
- web service responds on its public URL (
/on the live URL, expect ample canary axum patterns) - worker consumed the enqueued job (
/p/worker-queue/statuson the live URL, expect worker=done attempts=1 result=processed-by-worker)
Limitations
- Verified on the ubuntu-24.04 template at s-1vcpu-2gb for both services with the example fixture; other sizes, templates and Axum major versions are not verified.
- The mcp server itself (your job payloads, retry policy and scheduling) is application code and was not separately tested; the worker-queue check is what was verified.
- The worker is a single long-running process supervised in its own microVM; there is no scheduler, cron or horizontal worker scaling in this recipe, and the check ran immediately after deploy so idle behavior of the worker VM is not verified.
- The worker service is private: it has no public URL and is reached only through the shared database; both services are placed with their database.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures are not verified; apps and their databases are placed together.
- Region, compliance attestations and request-duration limits are unknown and not claimed.
Cost estimate
Estimated 15.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- web server x1
s-1vcpu-1gb: 5.00 USD - worker server x1
s-1vcpu-1gb: 5.00 USD - managed PostgreSQL database x1
s-1vcpu-1gb: 5.00 USD
Always-on monthly price of the tested sizes for the web service, the worker service and the database; apps auto-pause when idle.
Verification evidence
- canary_run on 2026-09-21T02:46:37Z at revision
1d28ae0-dirty (CLI 0.1.21): Axum web service plus a separate Axum worker process deployed on Ample withample plan --writethenample up(cargo build --release in the rust builder image (stable toolchain, Cargo.lock committed, pure-Rust dependencies), then the release binary on the ubuntu-24.04 template reading PORT and DATABASE_URL); the web service enqueued a job that the private worker service consumed from the shared managed PostgreSQL database. Pattern proof: a separately deployed worker service (kind worker, no public URL) sharing a declared managed PostgreSQL database with the web service, consuming a jobs table with row locks and marking jobs done once (worker=done attempts=1). (expires 2027-03-20T02:46:37Z)
Last verified: 2026-09-21T02:46:37Z
Execution binding
MCP tool ample_up (registry mcp:ample_up), schema hash db7ca0facfe2cd28 observed 2026-09-21T03:19:59.525781+00:00 at revision 49962bcade4f, binding state current, required scopes: servers:write, databases:write.