page:migrate:render postgresql:multi tenant relational data
Migrate Render PostgreSQL: Multi-tenant relational data
Summary
Move PostgreSQL data from Render PostgreSQL to Ample, one component at a time. Destination verified on Ample: a tenant column on every row and query, with a cross-tenant read returning nothing (tenant_isolation=ok). Source procedure: Take a logical backup with pg_dump -Fc using the external connection string. Not migrated automatically: Render's automatic backups and read replicas have no equivalent on the managed database. Cutover: Freeze writes with the user's go-ahead, take the final dump, restore, validate, redeploy with the managed DATABASE_URL, keep the Render database until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Prerequisites
- Authorized access to the Render PostgreSQL source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with servers:write, databases:read
Migration Source
Render PostgreSQL
Workflow Steps
- Inventory the source
List what Render PostgreSQL provides beyond the component you are moving. Out of scope here: Render's automatic backups and read replicas have no equivalent on the managed database. - Source step 1
Take a logical backup withpg_dump -Fcusing the external connection string. - Source step 2
Check the Postgres major version and extensions against the managed engine (PostgreSQL 16). - Source step 3
Restore into a scratch managed database first and compare row counts. - Provision and restore
Deploy the app once so a managed PostgreSQL 16 database exists (or create one withample database create --engine postgres), then restore the dump with pg_restore using its connection string; keep migrations idempotent. - Validate before cutover
Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/multi-tenant-relational-data). - Cut over
Freeze writes with the user's go-ahead, take the final dump, restore, validate, redeploy with the managed DATABASE_URL, keep the Render database until confirmed. - Rollback
Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Examples
- Express pattern fixture (destination)
Verified destination basis: multi-tenant relational data.
Success Checks
- Destination app responds on its public URL
Expected: ample canary express patterns. - Multi-tenant relational data check from the destination example
Expected: see the pattern fixture checks. - Data or object counts and checksums match the source
Expected: operator comparison before cutover.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Render PostgreSQL's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: Render's automatic backups and read replicas have no equivalent on the managed database.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures on the managed side are not verified beyond the pattern checks.