page:migrate:cloudflare r2 bucket:tenant scoped object prefixes
Migrate Cloudflare R2 bucket: Tenant-scoped object prefixes
Move object storage from Cloudflare R2 bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants// in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1).
Source procedure: Inventory the bucket with rclone size or the R2 dashboard. Not migrated automatically: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep R2 read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Representative Queries
- Migrate Cloudflare R2 bucket: Tenant-scoped object prefixes
- Where can I host Tenant-scoped object prefixes?
- I need a component-scoped export/import or reconfiguration procedure for Tenant-scoped object prefixes, with compatibility checks, verification and rollback.
Prerequisites
- Authorized access to the Cloudflare R2 bucket source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with
servers:write,buckets:write
Workflow Steps
Inventory the source
List what Cloudflare R2 bucket provides beyond the component you are moving. Out of scope here: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead.Source step 1
Inventory the bucket withrclone sizeor the R2 dashboard.Source step 2
Copy objects withrclone syncfrom the R2 S3-compatible endpoint to the Ample bucket endpoint using the issued credentials (path-style).Source step 3
Verify a sample of objects by size and checksum after the copy.Create the destination bucket and copy
Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encryptedS3_*variables.Validate before cutover
Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/tenant-scoped-object-prefixes).Cut over
Switch the app'sS3_*environment to the Ample bucket with a redeploy, verify reads and writes, keep R2 read-only until confirmed.Rollback
Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Cloudflare R2 bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: R2 public buckets with custom domains, Workers bindings and lifecycle rules are not migrated; publish an Ample bucket for public assets instead.
- Verified on the
node-22template ats-1vcpu-1gb; region, compliance and request-duration limits are unknown. PutObjectandGetObjectwith path-style addressing are verified; bulk copy tooling and other S3 operations are not.
Success Checks
- Destination app responds on its public URL
Expected:ample canary express patterns - Tenant-scoped-object-prefixes check from the destination example
Expected: see the pattern fixture checks - Data or object counts and checksums match the source
Expected: operator comparison before cutover.
Cost Estimate
- Currency: USD
- Monthly Amount: 5.0
- Basis: size prices from
pricing.toml(loaded by the API) at build revision1ac5595375130d45290090e82ed0f554ccd45405-dirty- Components:
- App server:
s-1vcpu-1gb, Quantity: 1.0, Monthly Amount: 5.0
- App server:
- Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
- Components: