page:migrate:digitalocean spaces bucket:public media library

Migrate DigitalOcean Spaces Bucket: Public Media Library

Summary

Move object storage from DigitalOcean Spaces bucket to Ample, one component at a time. Destination verified on Ample: an object written to a published bucket with an immutable Cache-Control header, a mapping row, and the CDN URL serving it publicly. Source procedure: Inventory the Space with rclone size or s3cmd du.

Not migrated automatically: Spaces CDN settings, CORS rules and per-object ACLs are not migrated; publish an Ample bucket for public delivery.
Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the Space read-only until confirmed.
Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Workflow Steps

  1. Inventory the source
    List what DigitalOcean Spaces bucket provides beyond the component you are moving. Out of scope here: Spaces CDN settings, CORS rules and per-object ACLs are not migrated; publish an Ample bucket for public delivery.

  2. Source step 1
    Inventory the Space with rclone size or s3cmd du

  3. Source step 2
    Copy objects with rclone sync from the Spaces endpoint to the Ample bucket endpoint using the issued credentials (path-style)

  4. Source step 3
    Verify a sample of objects by size and checksum after the copy

  5. Create the destination bucket and copy
    Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.

    ample bucket create --name <bucket-name>
    
  6. Validate before cutover
    Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/public-media-library).

  7. Cut over
    Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the Space read-only until confirmed.

  8. Rollback
    Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Limitations

Cost Estimate

Components

Success Checks

Examples

Evidence Summary

Next Actions