private document library.md
Migrate DigitalOcean Spaces bucket: Private document library
Summary
Move object storage from DigitalOcean Spaces bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Source procedure: Inventory the Space with rclone size or s3cmd du. Not migrated automatically: Spaces CDN settings, CORS rules and per-object ACLs are not migrated; publish an Ample bucket for public delivery. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the Space read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.
Infrastructure requirements
- S3-compatible object storage: verified (Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified.)
Prerequisites
- Authorized access to the DigitalOcean Spaces bucket source and its export tooling
- An inventory of every component in scope and out of scope
- A validated backup or copy before any cutover
- An Ample account token with servers:write, buckets:write
Exact tested configuration
- template:
node-22 - runtime:
node - size:
s-1vcpu-1gb - install:
npm install - build:
npm run build --if-present - start:
npm run start
Steps
- Inventory the source. List what DigitalOcean Spaces bucket provides beyond the component you are moving. Out of scope here: Spaces CDN settings, CORS rules and per-object ACLs are not migrated; publish an Ample bucket for public delivery.
- Source step 1. Inventory the Space with
rclone sizeors3cmd du - Source step 2. Copy objects with
rclone syncfrom the Spaces endpoint to the Ample bucket endpoint using the issued credentials (path-style) - Source step 3. Verify a sample of objects by size and checksum after the copy
- Create the destination bucket and copy. Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
ample bucket create --name <bucket-name>
- Validate before cutover. Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).
- Cut over. Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep the Space read-only until confirmed.
- Rollback. Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.
Tested examples
- Express pattern fixture (destination) (tests/deploy-canaries/express-patterns): Verified destination basis: private document library.
Success checks
- destination app responds on its public URL (
/on the live URL, expect ample canary express patterns) - private-document-library check from the destination example (
/p/private-document-libraryon the live URL, expect see the pattern fixture checks) - data or object counts and checksums match the source
Limitations
- Documentation only: nothing is executed automatically and no execution binding is offered.
- The source-side procedure is documented from DigitalOcean Spaces bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.
- No full source-product parity is claimed: Spaces CDN settings, CORS rules and per-object ACLs are not migrated; publish an Ample bucket for public delivery.
- Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.
- PutObject and GetObject with path-style addressing are verified; bulk copy tooling and other S3 operations are not.