page:migrate:cloudfront distribution:public image delivery
Migrate CloudFront distribution: Public image delivery
Move CDN delivery from CloudFront distribution to Ample, one component at a time. Destination verified on Ample: public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role).
Source procedure:
- Record the distribution's origins, cache behaviors, TTLs and the object keys the app references.
- Not migrated automatically: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only.
Cutover:
- Redeploy the app with the new asset base URL, verify delivery from the CDN URL, keep the distribution until confirmed, then disable it.
Rollback:
- Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Prerequisites:
- Authorized access to the CloudFront distribution source and its export tooling.
- An inventory of every component in scope and out of scope.
- A validated backup or copy before any cutover.
- An Ample account token with servers:write, buckets:write.
Workflow Steps:
- Inventory the source: List what CloudFront distribution provides beyond the component you are moving. Out of scope here: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only.
- Source step 1: Record the distribution's origins, cache behaviors, TTLs and the object keys the app references.
- Source step 2: Copy the public assets into a published Ample bucket under versioned keys with immutable Cache-Control.
- Source step 3: Update the app to build asset URLs from the Ample public URL.
- Publish the destination bucket: Create and publish the asset bucket, upload versioned assets with immutable Cache-Control, and point the app at the public URL. Command:
ample bucket publish. - Validate before cutover: Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/public-media-library).
- Cut over: Redeploy the app with the new asset base URL, verify delivery from the CDN URL, keep the distribution until confirmed, then disable it.
- Rollback: Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Examples:
Next.js pattern fixture (destination)
- Description: Verified destination basis: public image delivery.
- Source Reference:
tests/deploy-canaries/next-js-patterns
Success Checks:
- Destination app responds on its public URL: Kind:
http_get, Path:/, Expect:ample canary next js patterns - Public-media-library check from the destination example: Kind:
http_get, Path:/p/public-media-library, Expect:see the pattern fixture checks - Data or object counts and checksums match the source: Kind:
manual, Expect:operator comparison before cutover
Limitations:
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from CloudFront distribution's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only.
- Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
- PutObject and GetObject with path-style addressing are verified; bulk copy tooling and other S3 operations are not.
Cost Estimate:
- Currency: USD
- Monthly Amount: 5.0
- Basis: size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty.
- Components:
- Name: app server
- Size: s-1vcpu-1gb
- Quantity: 1.0
- Monthly Amount: 5.0
- Name: app server
- Components:
- Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
Evidence Summary:
- Kind: canary_run
- Summary: Destination side verified: the Next.js pattern fixture deployed on Ample (next build then next start -H 0.0.0.0 -p $PORT on the node-22 template) and its checks passed (public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role)). The source-side export from CloudFront distribution is documented from the vendor's standard tooling and was not executed by this catalog's evidence.
- Observed At: 2026-09-21T02:34:39Z
- Implementation Revision: 1d28ae0-dirty (CLI 0.1.21)
- Expires At: 2027-03-20T02:34:39Z
- Scope:
- Checks:
/p/public-media-library - Destination Only: true
- Template: node-22
- Checks:
Next Actions:
Action ID: browse-catalog
Label: Browse the catalog index
Operation ID: catalog_index
Method: GET
Relative Path: /v1/catalogAction ID: search-recipes
Label: Search published recipes by intent, stack and constraints
Operation ID: search_recipes
Method: POST
Relative Path: /v1/catalog/search
Parameters: {"body":{"limit":5,"query":"Migrate CloudFront distribution: Public image delivery"}}Action ID: plan:page:migrate:cloudfront-distribution:public-image-delivery
Label: Prepare a side-effect-free deployment plan for an authorized project
Operation ID: plan_deployment
Method: POST
Relative Path: /v1/catalog/plan
Parameters: {"body":{"inputs":{},"projectId":"","recipeId":"page:migrate:cloudfront-distribution:public-image-delivery","recipeRevision":"r1"}}Action ID: auth-setup
Label: Read the existing agent authentication setup
Operation ID: existing_auth_setup
Method: GET
Relative Path: /mcp/setupAction ID: browse:migration:cloudfront-distribution
Label: Browse CloudFront distribution
Operation ID: browse_node
Method: GET
Relative Path: /v1/catalog/nodes/migration%3Acloudfront-distributionAction ID: browse:pattern:public-image-delivery
Label: Browse Public image delivery
Operation ID: browse_node
Method: GET
Relative Path: /v1/catalog/nodes/pattern%3Apublic-image-deliveryAction ID: browse:intent:migrate-cdn
Label: Browse Migrate CDN
Operation ID: browse_node
Method: GET
Relative Path: /v1/catalog/nodes/intent%3Amigrate-cdn