page:migrate:digitalocean spaces bucket:private document library
Migrate DigitalOcean Spaces Bucket: Private Document Library
Summary
Move object storage from DigitalOcean Spaces bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).
- Source Procedure: Inventory the Space with
rclone sizeors3cmd du. - Not Migrated Automatically: Spaces CDN settings, CORS rules, and per-object ACLs are not migrated; publish an Ample bucket for public delivery.
- Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the Space read-only until confirmed.
- Rollback: Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Workflow Steps
- Inventory the source: List what DigitalOcean Spaces bucket provides beyond the component you are moving. Out of scope here: Spaces CDN settings, CORS rules, and per-object ACLs are not migrated; publish an Ample bucket for public delivery.
- Source step 1: Inventory the Space with
rclone sizeors3cmd du. - Source step 2: Copy objects with
rclone syncfrom the Spaces endpoint to the Ample bucket endpoint using the issued credentials (path-style). - Source step 3: Verify a sample of objects by size and checksum after the copy.
- Create the destination bucket and copy: Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
- Command:
ample bucket create --name
- Command:
- Validate before cutover: Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).
- Cut over: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the Space read-only until confirmed.
- Rollback: Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Prerequisites
- Authorized access to the DigitalOcean Spaces bucket source and its export tooling.
- An inventory of every component in scope and out of scope.
- A validated backup or copy before any cutover.
- An Ample account token with
servers:write,buckets:write.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- No full source-product parity is claimed: Spaces CDN settings, CORS rules, and per-object ACLs are not migrated; publish an Ample bucket for public delivery.
- Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
Success Checks
- Destination app responds on its public URL:
http_getpath:/, expect:ample canary express patterns. - Private-document-library check from the destination example:
http_getpath:/p/private-document-library, expect:see the pattern fixture checks. - Data or object counts and checksums match the source:
manual, expect:operator comparison before cutover.
Examples
- Express pattern fixture (destination):
- Description: Verified destination basis: private document library.
- Source Ref:
tests/deploy-canaries/express-patterns.
Cost Estimate
- Currency: USD
- Monthly Amount: 5.0
- Basis: Size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty.
- Components:
- App server: size:
s-1vcpu-1gb, quantity: 1.0, monthly amount: 5.0. - Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
- App server: size: