page:migrate:amazon s3 bucket:tenant scoped object prefixes
Migrate Amazon S3 bucket: Tenant-scoped object prefixes
Move object storage from Amazon S3 bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants// in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1).
Source procedure: Inventory the bucket (object count, total size, prefixes, largest objects) with aws s3 ls --recursive --summarize.
Not migrated automatically: Bucket policies, IAM conditions, lifecycle rules, versioning, replication and event notifications are not migrated; only PutObject and GetObject are verified on Ample.
Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the source bucket read-only until confirmed.
Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Representative Queries
- Migrate Amazon S3 bucket: Tenant-scoped object prefixes
- Where can I host Tenant-scoped object prefixes?
- I need a component-scoped export/import or reconfiguration procedure for Tenant-scoped object prefixes, with compatibility checks, verification and rollback.
Prerequisites
- Authorized access to the Amazon S3 bucket source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with
servers:write,buckets:write
Workflow Steps
Inventory the source
List what Amazon S3 bucket provides beyond the component you are moving. Out of scope here: Bucket policies, IAM conditions, lifecycle rules, versioning, replication and event notifications are not migrated; only PutObject and GetObject are verified on Ample.Source step 1
Inventory the bucket (object count, total size, prefixes, largest objects) withaws s3 ls --recursive --summarizeSource step 2
Copy objects withrclone syncoraws s3 syncfrom the S3 bucket to the Ample bucket endpoint using the issued credentials (path-style)Source step 3
Verify a sample of objects by size and checksum after the copyCreate the destination bucket and copy
Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encryptedS3_*variables.Validate before cutover
Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/tenant-scoped-object-prefixes).Cutover
Switch the app'sS3_*environment to the Ample bucket with a redeploy, verify reads and writes, keep the source bucket read-only until confirmed.Rollback
Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Amazon S3 bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: Bucket policies, IAM conditions, lifecycle rules, versioning, replication and event notifications are not migrated; only PutObject and GetObject are verified on Ample.
Cost Estimate
- Currency: USD
- Monthly Amount: $5.00
- Authoritative: true
- Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
Evidence Summary
- Destination side verified: the Express pattern fixture deployed on Ample (npm install, npm run build --if-present, npm run start on the node-22 template) and its checks passed. The source-side export from Amazon S3 bucket is documented from the vendor's standard tooling and was not executed by this catalog's evidence.