page:migrate:cloudflare r2 bucket:private document library

Migrate Cloudflare R2 bucket: Private document library

Move object storage from Cloudflare R2 bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Source procedure: Inventory the bucket with rclone size or the R2 dashboard. Not migrated automatically: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep R2 read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Workflow Steps

  1. Inventory the source
    List what Cloudflare R2 bucket provides beyond the component you are moving. Out of scope here: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead.

  2. Source step 1
    Inventory the bucket with rclone size or the R2 dashboard.

  3. Source step 2
    Copy objects with rclone sync from the R2 S3-compatible endpoint to the Ample bucket endpoint using the issued credentials (path-style).

  4. Source step 3
    Verify a sample of objects by size and checksum after the copy.

  5. Create the destination bucket and copy
    Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.

    ample bucket create --name <bucket_name>
    
  6. Validate before cutover
    Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).

  7. Cut over
    Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep R2 read-only until confirmed.

  8. Rollback
    Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Examples

Success Checks

Limitations

Cost Estimate