Host subscription content with Rails: authorized file delivery | Ample

INFRASTRUCTURE

What it needs

Before you start

Exactly what was tested

How to do it

  1. 1

Build and start

bundle install into vendor/bundle from Gemfile.lock (development and test groups skipped), then Puma via rails server reading PORT on the ruby-3.4 template with RAILS_ENV=production. The server must bind 0.0.0.0 on PORT.

  1. 2

Implement the pattern on PostgreSQL

The fixture's module implements generated downloads: an export query rendered to a CSV artifact stored with metadata in a private bucket and returned only to an authorized caller (401 without token, export=ok rows=3). Copy the approach into your schema; keep migrations idempotent and run them with --release-command.

  1. 3

Wire object storage

Create the bucket(s), then pass endpoint, region, bucket and keys as --env values. Use path-style addressing. Keep private data in an unpublished bucket.

  1. 4

Deploy

Run the synchronous deploy once and read the result (exit 0 live, 1 failed, 2 blocked). Re-running with no change is a no-op.

ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. 5

Verify

Fetch the live URL and the pattern self-test route(s) (/p/generated-downloads) from the example; then run your own checks. On failure read ample logs <deployment_id> --kind build then --kind runtime.

ample logs <deployment_id> --kind build

Tested examples

How to know it worked

Know the limits

Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Always-on monthly price of the tested sizes; apps and databases auto-pause when idle. Buckets are allocation-priced per quota and not included.

Verification evidence

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-21T03:19:59.461917+00:00 at revision 49962bcade4f. Binding state at export: current. Required scopes: servers:write, databases:read, buckets:read.

Typed next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.