private document library.md

Migrate Supabase Storage bucket: Private document library

Summary

Move object storage from Supabase Storage bucket to Ample, one component at a time. Destination verified on Ample: a role-to-document access model with negative tests (401 without identity, 403 for the wrong role) and a private-bucket round-trip for the allowed role (private=ok). Source procedure: Inventory objects through the Supabase Storage API or dashboard. Not migrated automatically: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.

Infrastructure requirements

Prerequisites

Exact tested configuration

Steps

  1. Inventory the source. List what Supabase Storage bucket provides beyond the component you are moving. Out of scope here: Supabase Storage RLS policies, signed URLs and image transformations are not migrated; enforce authorization in the app and stream private objects through it.
  2. Source step 1. Inventory objects through the Supabase Storage API or dashboard
  3. Source step 2. Copy objects with rclone sync from the Supabase S3-compatible endpoint (or a scripted download) to the Ample bucket endpoint using the issued credentials
  4. Source step 3. Verify a sample of objects by size and checksum after the copy
  5. Create the destination bucket and copy. Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.
   ample bucket create --name <bucket-name>
  1. Validate before cutover. Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/private-document-library).
  2. Cut over. Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep Supabase Storage read-only until confirmed.
  3. Rollback. Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation.

Tested examples

Success checks

Limitations

Cost estimate

Estimated 5.00 USD per month (size prices from pricing.toml at build revision a1b8c38919e59cd035ebabaced73cf84ece24371).

Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample.

Verification evidence

Execution binding

No execution binding. This recipe is documentation only; nothing is executed automatically.