page:migrate:render postgresql:multi tenant relational data

Migrate Render PostgreSQL: Multi-tenant relational data

Summary

Move PostgreSQL data from Render PostgreSQL to Ample, one component at a time. Destination verified on Ample: a tenant column on every row and query, with a cross-tenant read returning nothing (tenant_isolation=ok). Source procedure: Take a logical backup with pg_dump -Fc using the external connection string. Not migrated automatically: Render's automatic backups and read replicas have no equivalent on the managed database. Cutover: Freeze writes with the user's go-ahead, take the final dump, restore, validate, redeploy with the managed DATABASE_URL, keep the Render database until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Prerequisites

Migration Source

Render PostgreSQL

Workflow Steps

  1. Inventory the source
    List what Render PostgreSQL provides beyond the component you are moving. Out of scope here: Render's automatic backups and read replicas have no equivalent on the managed database.
  2. Source step 1
    Take a logical backup with pg_dump -Fc using the external connection string.
  3. Source step 2
    Check the Postgres major version and extensions against the managed engine (PostgreSQL 16).
  4. Source step 3
    Restore into a scratch managed database first and compare row counts.
  5. Provision and restore
    Deploy the app once so a managed PostgreSQL 16 database exists (or create one with ample database create --engine postgres), then restore the dump with pg_restore using its connection string; keep migrations idempotent.
  6. Validate before cutover
    Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/multi-tenant-relational-data).
  7. Cut over
    Freeze writes with the user's go-ahead, take the final dump, restore, validate, redeploy with the managed DATABASE_URL, keep the Render database until confirmed.
  8. Rollback
    Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Examples

Success Checks

Limitations