page:migrate:supabase storage bucket:tenant scoped object prefixes
Migrate Supabase Storage bucket: Tenant-scoped object prefixes
Move object storage from Supabase Storage bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants// in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1). Source procedure: Inventory objects through the Supabase Storage API or dashboard. Not migrated automatically: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Representative Queries
- Migrate Supabase Storage bucket: Tenant-scoped object prefixes
- Where can I host Tenant-scoped object prefixes?
- I need a component-scoped export/import or reconfiguration procedure for Tenant-scoped object prefixes, with compatibility checks, verification and rollback.
Workflow Steps
- Inventory the source: List what Supabase Storage bucket provides beyond the component you are moving. Out of scope here: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
- Source step 1: Inventory objects through the Supabase Storage API or dashboard.
- Source step 2: Copy objects with
rclone syncfrom the Supabase S3-compatible endpoint (or a scripted download) to the Ample bucket endpoint using the issued credentials. - Source step 3: Verify a sample of objects by size and checksum after the copy.
- Create the destination bucket and copy: Create the bucket, copy with
rcloneor the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encryptedS3_*variables. - Validate before cutover: Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (
/p/tenant-scoped-object-prefixes). - Cut over: Switch the app's
S3_*environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed. - Rollback: Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from Supabase Storage bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
Cost Estimate
- Currency: USD
- Monthly Amount: 5.0
- Basis: Size prices from pricing.toml (loaded by the API)
- Components: 1. App server, size
s-1vcpu-1gb, monthly amount: 5.0 - Note: Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
Success Checks
- Destination app responds on its public URL
- Tenant-scoped-object-prefixes check from the destination example
- Data or object counts and checksums match the source
Evidence Summary
- Destination side verified: the Express pattern fixture deployed on Ample and its checks passed.
Next Actions
- Browse the catalog index:
GET /v1/catalog - Search published recipes by intent:
POST /v1/catalog/search - Prepare a side-effect-free deployment plan for an authorized project:
POST /v1/catalog/plan - Read the existing agent authentication setup:
GET /mcp/setup - Browse Supabase Storage bucket:
GET /v1/catalog/nodes/migration%3Asupabase-storage-bucket - Browse Tenant-scoped object prefixes:
GET /v1/catalog/nodes/pattern%3Atenant-scoped-object-prefixes - Browse Migrate objects:
GET /v1/catalog/nodes/intent%3Amigrate-objects