page:migrate:supabase storage bucket:private document library
Migrate Supabase Storage bucket: Private document library
Move object storage from Supabase Storage bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Source procedure: Inventory objects through the Supabase Storage API or dashboard. Not migrated automatically: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Representative Queries
- Migrate Supabase Storage bucket: Private document library
- Where can I host Private document library?
- I need a component-scoped export/import or reconfiguration procedure for Private document library, with compatibility checks, verification and rollback.
Resource Requirements
- S3-compatible object storage
Infrastructure Requirements
- S3-compatible object storage : Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.
Workload
- Private document library
Migration Source
- Supabase Storage bucket
Execution Status
- Unbound
Prerequisites
- Authorized access to the Supabase Storage bucket source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with servers:write, buckets:write
Workflow Steps
- Inventory the source: List what Supabase Storage bucket provides beyond the component you are moving. Out of scope here: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
- Source step 1: Inventory objects through the Supabase Storage API or dashboard
- Source step 2: Copy objects with
rclone syncfrom the Supabase S3-compatible endpoint (or a scripted download) to the Ample bucket endpoint using the issued credentials - Source step 3: Verify a sample of objects by size and checksum after the copy
- Create the destination bucket and copy: Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
- Validate before cutover: Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).
- Cut over: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed.
- Rollback: Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Supabase Storage bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
- PutObject and GetObject with path-style addressing are verified; bulk copy tooling and other S3 operations are not.
Cost Estimate
- Currency: USD
- Monthly Amount: $5.0
- Components: app server (size: s-1vcpu-1gb, quantity: 1.0, monthlyAmount: $5.0)
Last Verified
- 2026-09-21T02:34:39Z
Evidence Summary
- Kind: canary_run
- Summary: Destination side verified: the Express pattern fixture deployed on Ample and its checks passed (a role-to-document access model with negative tests and a private-bucket round-trip for the allowed role). The source-side export from Supabase Storage bucket is documented from the vendor's standard tooling and was not executed by this catalog's evidence.
Next Actions
- Browse the catalog index: GET /v1/catalog
- Search published recipes by intent, stack and constraints: POST /v1/catalog/search
- Prepare a side-effect-free deployment plan for an authorized project: POST /v1/catalog/plan
- Read the existing agent authentication setup: GET /mcp/setup