page:guides:next js:object client

Configure S3-compatible access for Next.js

Summary

Configure S3-compatible access for a Next.js app on Ample. Create a bucket with ample bucket create, pass its endpoint, region, bucket name and keys as encrypted environment variables, and use @aws-sdk/client-s3 inside a dynamic route handler with forcePathStyle: true. The app writes and reads objects through the S3-compatible endpoint; the bucket stays private.

Representative Queries

Infrastructure Requirements

Workload

Configure S3-compatible access.

Prerequisites

  1. An S3 client in the app (@aws-sdk/client-s3 inside a dynamic route handler with forcePathStyle: true) reading S3_ENDPOINT, S3_REGION, S3_BUCKET, S3_ACCESS_KEY_ID and S3_SECRET_ACCESS_KEY.
  2. A bucket created with ample bucket create and its credentials from ample bucket credentials .
  3. An Ample account token with servers:write and buckets:read.

Workflow Steps

  1. Create the bucket
    Create it once and keep the issued credentials out of the repository. Command: ample bucket create --name
  2. Configure the client with path-style addressing
    Use @aws-sdk/client-s3 inside a dynamic route handler with forcePathStyle: true; virtual-host addressing is not verified.
  3. Deploy with the credentials as encrypted env
    Pass the five S3_* variables with --env; they are stored encrypted and reused on redeploys.
    Command: ample deploy . --name --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  4. Test through the app
    Expose a route (/api/storage) that writes then reads an object and reports s3=ok.
  5. Verify
    Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.
    Command: ample logs --kind build

Examples

Next.js bucket canary

Write and read an object with the injected credentials.
Source reference: tests/deploy-canaries/next-bucket-uploads.

Success Checks

Limitations

Cost Estimate

Evidence Summary

  1. Kind: Canary Run
    Summary: Next.js route handler using @aws-sdk/client-s3 with injected bucket credentials: PutObject then GetObject returned s3=ok at request time.
    Observed At: 2026-09-20T01:13:26Z
  2. Kind: Canary Run
    Summary: ample bucket create issued credentials; PutObject and GetObject succeeded through the public S3 endpoint; publish exposed the object through the CDN host with an ETag; unpublish and delete cleaned up.
    Observed At: 2026-09-20T01:13:26Z

Formats