page:migrate:minio bucket:private document library

Migrate MinIO bucket: Private document library

Move object storage from MinIO bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).

Source procedure:

Cutover:

Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep MinIO read-only until confirmed.

Rollback:

Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Prerequisites:

Workflow Steps:

  1. Inventory the source
    List what MinIO bucket provides beyond the component you are moving. Out of scope here: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated.
  2. Source step 1
    Inventory the bucket with mc du or rclone size
  3. Source step 2
    Copy objects with mc mirror or rclone sync from MinIO to the Ample bucket endpoint using the issued credentials (path-style)
  4. Source step 3
    Verify a sample of objects by size and checksum after the copy
  5. Create the destination bucket and copy
    Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
    ample bucket create --name  
    
  6. Validate before cutover
    Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).
  7. Cut over
    Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep MinIO read-only until confirmed.
  8. Rollback
    Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Success Checks:

Limitations:

Cost Estimate:

Evidence Summary:

Last Verified At:

Formats: