page:migrate:cloudflare r2 bucket:private document library
Migrate Cloudflare R2 bucket: Private document library
Move object storage from Cloudflare R2 bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Source procedure: Inventory the bucket with rclone size or the R2 dashboard. Not migrated automatically: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep R2 read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Workflow Steps
Inventory the source
List what Cloudflare R2 bucket provides beyond the component you are moving. Out of scope here: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead.Source step 1
Inventory the bucket withrclone sizeor the R2 dashboard.Source step 2
Copy objects withrclone syncfrom the R2 S3-compatible endpoint to the Ample bucket endpoint using the issued credentials (path-style).Source step 3
Verify a sample of objects by size and checksum after the copy.Create the destination bucket and copy
Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.ample bucket create --name <bucket_name>Validate before cutover
Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).Cut over
Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep R2 read-only until confirmed.Rollback
Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Examples
- Express pattern fixture (destination)
Verified destination basis: private document library. Source Reference:tests/deploy-canaries/express-patterns
Success Checks
Destination app responds on its public URL
Kind:http_get
Path:/
Expect:ample canary express patternsPrivate-document-library check from the destination example
Kind:http_get
Path:/p/private-document-library
Expect:see the pattern fixture checksData or object counts and checksums match the source
Kind:manual
Expect:operator comparison before cutover
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Cloudflare R2 bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead.
- Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
Cost Estimate
- Currency: USD
- Monthly Amount: $5.00
- Basis: size prices from pricing.toml
- Components:
- Name: app server
Size: s-1vcpu-1gb
Quantity: 1.0
Monthly Amount: $5.00
- Name: app server
- Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.