page:migrate:backblaze b2 s3 bucket:tenant scoped object prefixes

Migrate Backblaze B2 S3 bucket: Tenant-scoped object prefixes

Move object storage from Backblaze B2 S3 bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants// in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1).

Source procedure:

Cutover:

Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep B2 read-only until confirmed.

Rollback:

Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Workflow Steps

  1. Inventory the source

    • List what Backblaze B2 S3 bucket provides beyond the component you are moving.
    • Out of scope here: B2 file versions, lifecycle rules and application-key restrictions are not migrated.
  2. Source step 1

    • Inventory the bucket with rclone size or the B2 dashboard.
  3. Source step 2

    • Copy objects with rclone sync from the B2 S3-compatible endpoint to the Ample bucket endpoint using the issued credentials (path-style).
  4. Source step 3

    • Verify a sample of objects by size and checksum after the copy.
  5. Create the destination bucket and copy

    • Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
    • Command: ample bucket create --name
  6. Validate before cutover

    • Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/tenant-scoped-object-prefixes).
  7. Cut over

    • Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep B2 read-only until confirmed.
  8. Rollback

    • Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Limitations

Cost Estimate

Evidence Summary

Next Actions