Migrate DigitalOcean Droplet app: FastAPI | Ample

INFRASTRUCTURE

What it needs

PREREQUISITES

Before you start

TESTED CONFIGURATION

Exactly what was tested

STEP BY STEP

How to do it

  1. Inventory the source

List what DigitalOcean Droplet app provides beyond the component you are moving. Out of scope here: Cron jobs, local upload directories and firewall rules are not migrated; move uploads to a bucket and data to a managed database.

  1. Source step 1

Collect the process environment from the droplet (systemd unit, PM2 or supervisor config) into an env file kept out of the repository

  1. Source step 2

Replace the droplet's process manager and reverse proxy with the repository's start command; Ample provides HTTPS and supervision

  1. Source step 3

Inventory what else runs on the droplet: databases, cron, local uploads

  1. Deploy on Ample in parallel

pip install into .ample/python from requirements.txt, then uvicorn from run.py reading PORT on the python-3.12 template. Pass the exported variables with --env; keep the source running.

    ample deploy . --name <app-name> --public --start "python3 run.py" --env-file .env.production
    ```

6.  **Validate before cutover**

Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/configuration-secrets, /p/relational-records).

7.  **Cut over**

Add the custom domain with `ample domain add`, update DNS from the droplet IP, keep the droplet until verified, then power it off.

8.  **Rollback**

Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

## EXAMPLES

### Tested examples

- **FastAPI pattern fixture (destination)** (`tests/deploy-canaries/fastapi-patterns`): Verified destination basis: FastAPI compute.

## SUCCESS CHECKS

### How to know it worked

- destination app responds on its public URL (`/` on the live URL, expect ample canary fastapi patterns)
- configuration-secrets check from the destination example (`/p/configuration-secrets` on the live URL, expect see the pattern fixture checks)
- relational-records check from the destination example (`/p/relational-records` on the live URL, expect see the pattern fixture checks)
- data or object counts and checksums match the source

## LIMITATIONS

### Know the limits

- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from DigitalOcean Droplet app's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: Cron jobs, local upload directories and firewall rules are not migrated; move uploads to a bucket and data to a managed database.
- Verified on the python-3.12 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
- Managed PostgreSQL 16 only; extensions, connection limits and backup or restore procedures on the managed side are not verified beyond the pattern checks.

## COST

### Cost estimate

Estimated 10.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

- app server x1 `s-1vcpu-1gb`: 5.00 USD
- managed PostgreSQL database x1 `s-1vcpu-1gb`: 5.00 USD

Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.

## EVIDENCE

### Verification evidence

- canary_run on 2026-09-21T01:14:18Z at revision `50dbac567d2c5cc8e55e6c748a646be0025d9cfb-dirty (CLI 0.1.21)`: Destination side verified: the FastAPI pattern fixture deployed on Ample (pip install into .ample/python from requirements.txt, then uvicorn from run.py reading PORT on the python-3.12 template) and its checks passed (the app built, started and answered on its public HTTPS URL with encrypted configuration delivered). The source-side export from DigitalOcean Droplet app is documented from the vendor's standard tooling and was not executed by this catalog's evidence. (expires 2027-03-20T01:14:18Z)

## EXECUTION

### Execution binding

No execution binding. This recipe is documentation only; nothing is executed automatically.

## NEXT ACTIONS

### Typed next actions

- Browse the catalog index (`GET /v1/catalog` on the api origin; authentication not required, approval not required)
- Search published recipes by intent, stack and constraints (`POST /v1/catalog/search` on the api origin; authentication not required, approval not required)
- Prepare a side-effect-free deployment plan for an authorized project (`POST /v1/catalog/plan` on the api origin; authentication required, approval not required)
- Read the existing agent authentication setup (`GET /mcp/setup` on the api origin; authentication not required, approval not required)
- Browse DigitalOcean Droplet app (`GET /v1/catalog/nodes/migration%3Adigitalocean-droplet-app` on the api origin; authentication not required, approval not required)
- Browse FastAPI (`GET /v1/catalog/nodes/stack%3Aframework-fastapi` on the api origin; authentication not required, approval not required)
- Browse Migrate compute (`GET /v1/catalog/nodes/intent%3Amigrate-compute` on the api origin; authentication not required, approval not required)

Actions describe possible next steps. They are typed data, not commands, and grant no permission. Public discovery never provisions anything; planning requires your own authenticated token and approval happens in your client.