page:migrate:minio bucket:private document library
Migrate MinIO bucket: Private document library
Move object storage from MinIO bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok).
Source procedure:
- Inventory the bucket with
mc duorrclone size. - Not migrated automatically: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated.
Cutover:
Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep MinIO read-only until confirmed.
Rollback:
Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Prerequisites:
- Authorized access to the MinIO bucket source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with servers:write, buckets:write
Workflow Steps:
- Inventory the source
List what MinIO bucket provides beyond the component you are moving. Out of scope here: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated. - Source step 1
Inventory the bucket withmc duorrclone size - Source step 2
Copy objects withmc mirrororrclone syncfrom MinIO to the Ample bucket endpoint using the issued credentials (path-style) - Source step 3
Verify a sample of objects by size and checksum after the copy - Create the destination bucket and copy
Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.ample bucket create --name - Validate before cutover
Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library). - Cut over
Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep MinIO read-only until confirmed. - Rollback
Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Success Checks:
- Destination app responds on its public URL
- Private-document-library check from the destination example
- Data or object counts and checksums match the source
Limitations:
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from MinIO bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated.
Cost Estimate:
- Currency: USD
- Monthly Amount: 5.0
- Components: app server (size: s-1vcpu-1gb, quantity: 1.0, monthlyAmount: 5.0)
- Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
Evidence Summary:
- Kind: canary_run
- Summary: Destination side verified: the Express pattern fixture deployed on Ample and its checks passed.
Last Verified At:
- 2026-09-21T02:34:39Z