page:migrate:supabase storage bucket:public media library
Migrate Supabase Storage bucket: Public media library
Summary
Move object storage from Supabase Storage bucket to Ample, one component at a time. Destination verified on Ample: an object written to a published bucket with an immutable Cache-Control header, a mapping row, and the CDN URL serving it publicly.
- Source procedure: Inventory objects through the Supabase Storage API or dashboard.
- Not migrated automatically: Supabase Storage RLS policies, signed URLs, and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
- Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed.
- Rollback: Keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Resource Requirements
- S3-compatible object storage
Infrastructure Requirements
| Primitive ID |
Label |
Status |
Summary |
| primitive:s3-compatible-object-storage |
S3-compatible object storage |
verified |
Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified. |
Workflow Steps
- Inventory the source: List what Supabase Storage bucket provides beyond the component you are moving. Out of scope here: Supabase Storage RLS policies, signed URLs, and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
- Source step 1: Inventory objects through the Supabase Storage API or dashboard.
- Source step 2: Copy objects with
rclone sync from the Supabase S3-compatible endpoint (or a scripted download) to the Ample bucket endpoint using the issued credentials.
- Source step 3: Verify a sample of objects by size and checksum after the copy.
- Create the destination bucket and copy: Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
- Validate before cutover: Run the app's checks and, for data, compare counts and checksums.
- Cut over: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed.
- Rollback: Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Success Checks
- The destination app responds on its public URL.
- Public-media-library check from the destination example.
- Data or object counts and checksums match the source.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- No full source-product parity is claimed; enforce authorization in the app and stream private objects through it.
Cost Estimate
| Currency |
Monthly Amount |
Authoritative |
Basis |
Components |
Note |
| USD |
5.0 |
true |
Size prices from pricing.toml (loaded by the API) at build revision 1ac5595375130d45290090e82ed0f554ccd45405-dirty |
app server (s-1vcpu-1gb) |
Destination always-on monthly price of the tested sizes; apps auto-pause when idle. |
Evidence Summary
- The Express pattern fixture deployed on Ample and its checks passed.
Formats
Next Actions