Migrate CloudFront distribution: Public image delivery | Ample
INFRASTRUCTURE
What it needs
- CDN: verified (The CDN host serves objects from published buckets. It does not front app compute and is not a cache or key-value store.)
PREREQUISITES
Before you start
- Authorized access to the CloudFront distribution source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with servers:write, buckets:write
TESTED CONFIGURATION
Exactly what was tested
- build:
npm run build --if-present - install:
npm install - runtime:
node - size:
s-1vcpu-1gb - start:
npm run start - template:
node-22
STEP BY STEP
How to do it
- 1
Inventory the source
List what CloudFront distribution provides beyond the component you are moving. Out of scope here: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only.
- 2
Source step 1
Record the distribution's origins, cache behaviors, TTLs and the object keys the app references
- 3
Source step 2
Copy the public assets into a published Ample bucket under versioned keys with immutable Cache-Control
- 4
Source step 3
Update the app to build asset URLs from the Ample public URL
- 5
Publish the destination bucket
Create and publish the asset bucket, upload versioned assets with immutable Cache-Control, and point the app at the public URL.
ample bucket publish <bucket-name>
- 6
Validate before cutover
Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/public-media-library).
- 7
Cut over
Redeploy the app with the new asset base URL, verify delivery from the CDN URL, keep the distribution until confirmed, then disable it.
- 8
Rollback
Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
EXAMPLES
Tested examples
- Next.js pattern fixture (destination) (
tests/deploy-canaries/next-js-patterns): Verified destination basis: public image delivery.
SUCCESS CHECKS
How to know it worked
- destination app responds on its public URL (
/on the live URL, expect ample canary next js patterns) - public-media-library check from the destination example (
/p/public-media-libraryon the live URL, expect see the pattern fixture checks) - data or object counts and checksums match the source
LIMITATIONS
Know the limits
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from CloudFront distribution's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: CloudFront cache behaviors, Lambda@Edge and CloudFront Functions, signed URLs and custom TTLs are not migrated; Ample verifies delivery of published bucket objects only.
- Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
- PutObject and GetObject with path-style addressing are verified; bulk copy tooling and other S3 operations are not.
COST
Cost estimate
Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).
- app server x1
s-1vcpu-1gb: 5.00 USD
Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.
EVIDENCE
Verification evidence
- canary_run on 2026-09-21T02:34:39Z at revision
1d28ae0-dirty (CLI 0.1.21): Destination side verified: the Next.js pattern fixture deployed on Ample (next build then next start -H 0.0.0.0 -p $PORT on the node-22 template) and its checks passed (public objects in a published bucket served from the CDN URL, kept separate from private objects in an unpublished bucket that require authorization (private=ok only for the allowed role)). The source-side export from CloudFront distribution is documented from the vendor's standard tooling and was not executed by this catalog's evidence. (expires 2027-03-20T02:34:39Z)
EXECUTION
Execution binding
No execution binding. This recipe is documentation only; nothing is executed automatically.
NEXT ACTIONS
Typed next actions
- Browse the catalog index (
GET /v1/catalogon the api origin; authentication not required, approval not required) - Search published recipes by intent, stack and constraints (
POST /v1/catalog/searchon the api origin; authentication not required, approval not required) - Prepare a side-effect-free deployment plan for an authorized project (
POST /v1/catalog/planon the api origin; authentication required, approval not required) - Read the existing agent authentication setup (
GET /mcp/setupon the api origin; authentication not required, approval not required) - Browse CloudFront distribution (
GET /v1/catalog/nodes/migration%3Acloudfront-distributionon the api origin; authentication not required, approval not required) - Browse Public image delivery (
GET /v1/catalog/nodes/pattern%3Apublic-image-deliveryon the api origin; authentication not required, approval not required) - Browse Migrate CDN (
GET /v1/catalog/nodes/intent%3Amigrate-cdnon the api origin; authentication not required, approval not required)
Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.