{"catalogRevision":"cat_f13ab9a494120b5e","recipeId":"page:migrate:backblaze-b2-s3-bucket:tenant-scoped-object-prefixes","recipeRevision":"r1","canonicalPath":"/migrate/backblaze-b2-s3-bucket/tenant-scoped-object-prefixes","label":"Migrate Backblaze B2 S3 bucket: Tenant-scoped object prefixes","family":"Migration guide","summary":"Move object storage from Backblaze B2 S3 bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants/<id>/ in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1). Source procedure: Inventory the bucket with `rclone size` or the B2 dashboard. Not migrated automatically: B2 file versions, lifecycle rules and application-key restrictions are not migrated. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep B2 read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.","representativeQueries":["Migrate Backblaze B2 S3 bucket: Tenant-scoped object prefixes","Where can I host Tenant-scoped object prefixes?","I need a component-scoped export/import or reconfiguration procedure for Tenant-scoped object prefixes, with compatibility checks, verification and rollback."],"breadcrumbIds":["discovery","migration","migration:object-and-cdn-sources","migration:backblaze-b2-s3-bucket","page:migrate:backblaze-b2-s3-bucket:tenant-scoped-object-prefixes"],"breadcrumbs":[{"id":"discovery","label":"Agent hosting discovery","canonicalPath":"/discover/discovery","kind":"root"},{"id":"migration","label":"Migration sources by component","canonicalPath":"/discover/migration","kind":"facet"},{"id":"migration:object-and-cdn-sources","label":"Object and CDN sources","canonicalPath":"/discover/migration/object-and-cdn-sources","kind":"group"},{"id":"migration:backblaze-b2-s3-bucket","label":"Backblaze B2 S3 bucket","canonicalPath":"/discover/migration/backblaze-b2-s3-bucket","kind":"atom"},{"id":"page:migrate:backblaze-b2-s3-bucket:tenant-scoped-object-prefixes","label":"Migrate Backblaze B2 S3 bucket: Tenant-scoped object prefixes","canonicalPath":"/migrate/backblaze-b2-s3-bucket/tenant-scoped-object-prefixes","kind":"recipe"}],"parentIds":["migration:backblaze-b2-s3-bucket","pattern:tenant-scoped-object-prefixes","intent:migrate-objects"],"parents":[{"id":"migration:backblaze-b2-s3-bucket","label":"Backblaze B2 S3 bucket","canonicalPath":"/discover/migration/backblaze-b2-s3-bucket","kind":"atom"},{"id":"pattern:tenant-scoped-object-prefixes","label":"Tenant-scoped object prefixes","canonicalPath":"/discover/pattern/tenant-scoped-object-prefixes","kind":"atom"},{"id":"intent:migrate-objects","label":"Migrate objects","canonicalPath":"/discover/intent/migrate-objects","kind":"atom"}],"resourceRequirements":["primitive:s3-compatible-object-storage"],"infrastructureRequirements":[{"primitiveId":"primitive:s3-compatible-object-storage","label":"S3-compatible object storage","canonicalPath":"/discover/primitive/s3-compatible-object-storage","status":"verified","summary":"Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified."}],"workload":"Tenant-scoped object prefixes","migrationSource":"Backblaze B2 S3 bucket","releaseStatus":"published","supportStatus":"verified","executionStatus":"unbound","docsOnly":true,"prerequisites":["Authorized access to the Backblaze B2 S3 bucket source and its export tooling","An inventory of every component in scope and out of scope","A validated backup or copy before any cutover","An Ample account token with servers:write, buckets:write"],"testedConfiguration":{"template":"node-22","runtime":"node","size":"s-1vcpu-1gb","install":"npm install","build":"npm run build --if-present","start":"npm run start"},"inputSchema":null,"outputSchema":null,"workflowSteps":[{"title":"Inventory the source","body":"List what Backblaze B2 S3 bucket provides beyond the component you are moving. Out of scope here: B2 file versions, lifecycle rules and application-key restrictions are not migrated."},{"title":"Source step 1","body":"Inventory the bucket with `rclone size` or the B2 dashboard"},{"title":"Source step 2","body":"Copy objects with `rclone sync` from the B2 S3-compatible endpoint to the Ample bucket endpoint using the issued credentials (path-style)"},{"title":"Source step 3","body":"Verify a sample of objects by size and checksum after the copy"},{"title":"Create the destination bucket and copy","body":"Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.","command":"ample bucket create --name <bucket-name>"},{"title":"Validate before cutover","body":"Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/tenant-scoped-object-prefixes)."},{"title":"Cut over","body":"Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep B2 read-only until confirmed."},{"title":"Rollback","body":"Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation."}],"examples":[{"title":"Express pattern fixture (destination)","description":"Verified destination basis: tenant-scoped object prefixes.","sourceRef":"tests/deploy-canaries/express-patterns"}],"successChecks":[{"description":"destination app responds on its public URL","kind":"http_get","path":"/","expect":"ample canary express patterns"},{"description":"tenant-scoped-object-prefixes check from the destination example","kind":"http_get","path":"/p/tenant-scoped-object-prefixes","expect":"see the pattern fixture checks"},{"description":"data or object counts and checksums match the source","kind":"manual","expect":"operator comparison before cutover"}],"limitations":["Documentation only: nothing is executed automatically and no execution binding is offered.","The source-side procedure is documented from Backblaze B2 S3 bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.","No full source-product parity is claimed: B2 file versions, lifecycle rules and application-key restrictions are not migrated.","Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.","PutObject and GetObject with path-style addressing are verified; bulk copy tooling and other S3 operations are not."],"costEstimate":{"currency":"USD","monthlyAmount":5.0,"authoritative":true,"basis":"size prices from pricing.toml (loaded by the API) at build revision 9a468b28b6a4a0552d6b9b26703935ac032a7aa9","components":[{"name":"app server","size":"s-1vcpu-1gb","quantity":1.0,"monthlyAmount":5.0}],"note":"Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample."},"evidenceSummary":[{"kind":"canary_run","summary":"Destination side verified: the Express pattern fixture deployed on Ample (npm install, npm run build --if-present, npm run start on the node-22 template) and its checks passed (every tenant's objects stored under tenants/<id>/ in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1)). The source-side export from Backblaze B2 S3 bucket is documented from the vendor's standard tooling and was not executed by this catalog's evidence.","observedAt":"2026-09-21T02:34:39Z","implementationRevision":"1d28ae0 (CLI 0.1.21)","expiresAt":"2027-03-20T02:34:39Z","scope":{"checks":["/p/tenant-scoped-object-prefixes"],"destinationOnly":true,"template":"node-22"}}],"lastVerifiedAt":"2026-09-21T02:34:39Z","mcpBinding":null,"unknowns":["region availability is unknown until a verified region fact is recorded","compliance attestations are unknown; none are claimed"],"formats":{"html":"https://ample.computer/migrate/backblaze-b2-s3-bucket/tenant-scoped-object-prefixes","markdown":"https://ample.computer/migrate/backblaze-b2-s3-bucket/tenant-scoped-object-prefixes.md","json":"https://api.ample.computer/v1/catalog/recipes/page%3Amigrate%3Abackblaze-b2-s3-bucket%3Atenant-scoped-object-prefixes"},"nextActions":[{"actionId":"browse-catalog","label":"Browse the catalog index","operationId":"catalog_index","method":"GET","relativePath":"/v1/catalog","origin":"api","parameters":{},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"search-recipes","label":"Search published recipes by intent, stack and constraints","operationId":"search_recipes","method":"POST","relativePath":"/v1/catalog/search","origin":"api","parameters":{"body":{"limit":5,"query":"Migrate Backblaze B2 S3 bucket: Tenant-scoped object prefixes"}},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"plan:page:migrate:backblaze-b2-s3-bucket:tenant-scoped-object-prefixes","label":"Prepare a side-effect-free deployment plan for an authorized project","operationId":"plan_deployment","method":"POST","relativePath":"/v1/catalog/plan","origin":"api","parameters":{"body":{"inputs":{},"projectId":"<workspace or server id you own>","recipeId":"page:migrate:backblaze-b2-s3-bucket:tenant-scoped-object-prefixes","recipeRevision":"r1"}},"requiresAuthentication":true,"requiresApproval":false},{"actionId":"auth-setup","label":"Read the existing agent authentication setup","operationId":"existing_auth_setup","method":"GET","relativePath":"/mcp/setup","origin":"api","parameters":{},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"browse:migration:backblaze-b2-s3-bucket","label":"Browse Backblaze B2 S3 bucket","operationId":"browse_node","method":"GET","relativePath":"/v1/catalog/nodes/migration%3Abackblaze-b2-s3-bucket","origin":"api","parameters":{"nodeId":"migration:backblaze-b2-s3-bucket"},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"browse:pattern:tenant-scoped-object-prefixes","label":"Browse Tenant-scoped object prefixes","operationId":"browse_node","method":"GET","relativePath":"/v1/catalog/nodes/pattern%3Atenant-scoped-object-prefixes","origin":"api","parameters":{"nodeId":"pattern:tenant-scoped-object-prefixes"},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"browse:intent:migrate-objects","label":"Browse Migrate objects","operationId":"browse_node","method":"GET","relativePath":"/v1/catalog/nodes/intent%3Amigrate-objects","origin":"api","parameters":{"nodeId":"intent:migrate-objects"},"requiresAuthentication":false,"requiresApproval":false}]}