Configure S3-compatible access for Express | Ample

INFRASTRUCTURE

What it needs

PREREQUISITES

Before you start

TESTED CONFIGURATION

Exactly what was tested

STEP BY STEP

How to do it

  1. 1

Create the bucket

Create it once and keep the issued credentials out of the repository.

ample bucket create --name <bucket-name>
  1. 2

Configure the client with path-style addressing

Use @aws-sdk/client-s3 with forcePathStyle: true; virtual-host addressing is not verified.

  1. 3

Deploy with the credentials as encrypted env

Pass the five S3_* variables with --env; they are stored encrypted and reused on redeploys.

ample deploy . --name <app-name> --public --env S3_ENDPOINT=... --env S3_REGION=... --env S3_BUCKET=... --env S3_ACCESS_KEY_ID=... --env S3_SECRET_ACCESS_KEY=...
  1. 4

Test through the app

Expose a route (/storage) that writes then reads an object and reports s3=ok.

  1. 5

Verify

Fetch the live URL and run the success checks below. On failure read the build log, then the runtime log, fix the cause and deploy again; do not blind-retry.

ample logs <deployment_id> --kind build

EXAMPLES

Tested examples

SUCCESS CHECKS

How to know it worked

LIMITATIONS

Know the limits

COST

Cost estimate

Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Compute only. Buckets are allocation-priced per quota and capped by the plan; see ample usage.

EVIDENCE

Verification evidence

EXECUTION

Execution binding

MCP tool ample_deploy (registry mcp:ample_deploy), schema hash 876465fce906da0c observed 2026-09-20T01:55:48.667900+00:00 at revision 199ff1dfd526. Binding state at export: current. Required scopes: servers:write, buckets:read.

NEXT ACTIONS

Typed next actions

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.