page:migrate:backblaze b2 s3 bucket:tenant scoped object prefixes
Migrate Backblaze B2 S3 bucket: Tenant-scoped object prefixes
Move object storage from Backblaze B2 S3 bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants// in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1).
Source procedure:
- Inventory the bucket with
rclone sizeor the B2 dashboard. - Not migrated automatically: B2 file versions, lifecycle rules and application-key restrictions are not migrated.
Cutover:
Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep B2 read-only until confirmed.
Rollback:
Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Workflow Steps
Inventory the source
- List what Backblaze B2 S3 bucket provides beyond the component you are moving.
- Out of scope here: B2 file versions, lifecycle rules and application-key restrictions are not migrated.
Source step 1
- Inventory the bucket with
rclone sizeor the B2 dashboard.
- Inventory the bucket with
Source step 2
- Copy objects with
rclone syncfrom the B2 S3-compatible endpoint to the Ample bucket endpoint using the issued credentials (path-style).
- Copy objects with
Source step 3
- Verify a sample of objects by size and checksum after the copy.
Create the destination bucket and copy
- Create the bucket, copy with
rcloneor the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables. - Command:
ample bucket create --name
- Create the bucket, copy with
Validate before cutover
- Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (
/p/tenant-scoped-object-prefixes).
- Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (
Cut over
- Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep B2 read-only until confirmed.
Rollback
- Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Backblaze B2 S3 bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: B2 file versions, lifecycle rules and application-key restrictions are not migrated.
- Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
Cost Estimate
- Currency: USD
- Monthly Amount: $5.00
- Basis: size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty.
- Components:
- App server: size s-1vcpu-1gb, quantity 1.0, monthly amount $5.00.
Evidence Summary
- Kind: canary_run
- Summary: Destination side verified: the Express pattern fixture deployed on Ample and its checks passed. The source-side export from Backblaze B2 S3 bucket is documented from the vendor's standard tooling and was not executed by this catalog's evidence.
- Observed At: 2026-09-21T02:34:39Z
- Implementation Revision: 1d28ae0-dirty (CLI 0.1.21)
- Expires At: 2027-03-20T02:34:39Z
Next Actions
- Browse the catalog index
- Search published recipes by intent, stack and constraints
- Prepare a side-effect-free deployment plan for an authorized project
- Read the existing agent authentication setup
- Browse Backblaze B2 S3 bucket
- Browse Tenant-scoped object prefixes
- Browse Migrate objects