{"catalogRevision":"cat_e0229f434a69b6e8","recipeId":"page:migrate:minio-bucket:tenant-scoped-object-prefixes","recipeRevision":"r1","canonicalPath":"/migrate/minio-bucket/tenant-scoped-object-prefixes","label":"Migrate MinIO bucket: Tenant-scoped object prefixes","family":"Migration guide","summary":"Move object storage from MinIO bucket to Ample, one component at a time. Destination verified on Ample: every tenant's objects stored under tenants/<id>/ in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1). Source procedure: Inventory the bucket with `mc du` or `rclone size`. Not migrated automatically: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated. Cutover: Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep MinIO read-only until confirmed. Rollback: keep the source untouched until you confirm; nothing at the source is changed or deleted by this guide.","representativeQueries":["Migrate MinIO bucket: Tenant-scoped object prefixes","Where can I host Tenant-scoped object prefixes?","I need a component-scoped export/import or reconfiguration procedure for Tenant-scoped object prefixes, with compatibility checks, verification and rollback."],"breadcrumbIds":["discovery","migration","migration:object-and-cdn-sources","migration:minio-bucket","page:migrate:minio-bucket:tenant-scoped-object-prefixes"],"breadcrumbs":[{"id":"discovery","label":"Agent hosting discovery","canonicalPath":"/discover/discovery","kind":"root"},{"id":"migration","label":"Migration sources by component","canonicalPath":"/discover/migration","kind":"facet"},{"id":"migration:object-and-cdn-sources","label":"Object and CDN sources","canonicalPath":"/discover/migration/object-and-cdn-sources","kind":"group"},{"id":"migration:minio-bucket","label":"MinIO bucket","canonicalPath":"/discover/migration/minio-bucket","kind":"atom"},{"id":"page:migrate:minio-bucket:tenant-scoped-object-prefixes","label":"Migrate MinIO bucket: Tenant-scoped object prefixes","canonicalPath":"/migrate/minio-bucket/tenant-scoped-object-prefixes","kind":"recipe"}],"parentIds":["migration:minio-bucket","pattern:tenant-scoped-object-prefixes","intent:migrate-objects"],"parents":[{"id":"migration:minio-bucket","label":"MinIO bucket","canonicalPath":"/discover/migration/minio-bucket","kind":"atom"},{"id":"pattern:tenant-scoped-object-prefixes","label":"Tenant-scoped object prefixes","canonicalPath":"/discover/pattern/tenant-scoped-object-prefixes","kind":"atom"},{"id":"intent:migrate-objects","label":"Migrate objects","canonicalPath":"/discover/intent/migrate-objects","kind":"atom"}],"resourceRequirements":["primitive:s3-compatible-object-storage"],"infrastructureRequirements":[{"primitiveId":"primitive:s3-compatible-object-storage","label":"S3-compatible object storage","canonicalPath":"/discover/primitive/s3-compatible-object-storage","status":"verified","summary":"Buckets are S3-compatible with issued credentials; PutObject and GetObject are verified by canary. Other S3 operations are not verified."}],"workload":"Tenant-scoped object prefixes","migrationSource":"MinIO bucket","releaseStatus":"published","supportStatus":"verified","executionStatus":"unbound","docsOnly":true,"prerequisites":["Authorized access to the MinIO bucket source and its export tooling","An inventory of every component in scope and out of scope","A validated backup or copy before any cutover","An Ample account token with servers:write, buckets:write"],"testedConfiguration":{"template":"node-22","runtime":"node","size":"s-1vcpu-1gb","install":"npm install","build":"npm run build --if-present","start":"npm run start"},"inputSchema":null,"outputSchema":null,"workflowSteps":[{"title":"Inventory the source","body":"List what MinIO bucket provides beyond the component you are moving. Out of scope here: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated."},{"title":"Source step 1","body":"Inventory the bucket with `mc du` or `rclone size`"},{"title":"Source step 2","body":"Copy objects with `mc mirror` or `rclone sync` from MinIO to the Ample bucket endpoint using the issued credentials (path-style)"},{"title":"Source step 3","body":"Verify a sample of objects by size and checksum after the copy"},{"title":"Create the destination bucket and copy","body":"Create the bucket, copy with rclone or the S3 CLI in path-style mode using the issued credentials, then pass the credentials to the app as encrypted S3_* variables.","command":"ample bucket create --name <bucket-name>"},{"title":"Validate before cutover","body":"Run the app's own checks and, for data, compare counts and checksums; the example checks are the pattern self-tests (/p/tenant-scoped-object-prefixes)."},{"title":"Cut over","body":"Switch the app's S3_* environment to the Ample bucket with a redeploy, verify reads and writes, keep MinIO read-only until confirmed."},{"title":"Rollback","body":"Point DNS or configuration back to the source. The source was never modified; deletion is a separate, user-executed step after validation."}],"examples":[{"title":"Express pattern fixture (destination)","description":"Verified destination basis: tenant-scoped object prefixes.","sourceRef":"tests/deploy-canaries/express-patterns"}],"successChecks":[{"description":"destination app responds on its public URL","kind":"http_get","path":"/","expect":"ample canary express patterns"},{"description":"tenant-scoped-object-prefixes check from the destination example","kind":"http_get","path":"/p/tenant-scoped-object-prefixes","expect":"see the pattern fixture checks"},{"description":"data or object counts and checksums match the source","kind":"manual","expect":"operator comparison before cutover"}],"limitations":["Documentation only: nothing is executed automatically and no execution binding is offered.","The source-side procedure is documented from MinIO bucket's standard tooling and was not executed in this catalog's evidence; the destination side was verified with the pattern fixture.","No full source-product parity is claimed: MinIO bucket policies, versioning, replication, ILM rules and notifications are not migrated.","Verified on the node-22 template at s-1vcpu-1gb; region, compliance and request-duration limits are unknown.","PutObject and GetObject with path-style addressing are verified; bulk copy tooling and other S3 operations are not."],"costEstimate":{"currency":"USD","monthlyAmount":5.0,"authoritative":true,"basis":"size prices from pricing.toml (loaded by the API) at build revision 6d0f96391c85b4b09e47705170b42a8afb10d18d","components":[{"name":"app server","size":"s-1vcpu-1gb","quantity":1.0,"monthlyAmount":5.0}],"note":"Destination always-on monthly price of the tested sizes; apps auto-pause when idle. Source costs are unknown to Ample."},"evidenceSummary":[{"kind":"canary_run","summary":"Destination side verified: the Express pattern fixture deployed on Ample (npm install, npm run build --if-present, npm run start on the node-22 template) and its checks passed (every tenant's objects stored under tenants/<id>/ in a private bucket with an ownership row per object, reads refused for keys outside the caller's prefix or not owned (cross=forbidden), and a prefix-bound listing returning only that tenant's objects (own=1)). The source-side export from MinIO bucket is documented from the vendor's standard tooling and was not executed by this catalog's evidence.","observedAt":"2026-09-21T02:34:39Z","implementationRevision":"1d28ae0 (CLI 0.1.21)","expiresAt":"2027-03-20T02:34:39Z","scope":{"checks":["/p/tenant-scoped-object-prefixes"],"destinationOnly":true,"template":"node-22"}}],"lastVerifiedAt":"2026-09-21T02:34:39Z","mcpBinding":null,"unknowns":["region availability is unknown until a verified region fact is recorded","compliance attestations are unknown; none are claimed"],"formats":{"html":"https://ample.computer/migrate/minio-bucket/tenant-scoped-object-prefixes","markdown":"https://ample.computer/migrate/minio-bucket/tenant-scoped-object-prefixes.md","json":"https://api.ample.computer/v1/catalog/recipes/page%3Amigrate%3Aminio-bucket%3Atenant-scoped-object-prefixes"},"nextActions":[{"actionId":"browse-catalog","label":"Browse the catalog index","operationId":"catalog_index","method":"GET","relativePath":"/v1/catalog","origin":"api","parameters":{},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"search-recipes","label":"Search published recipes by intent, stack and constraints","operationId":"search_recipes","method":"POST","relativePath":"/v1/catalog/search","origin":"api","parameters":{"body":{"limit":5,"query":"Migrate MinIO bucket: Tenant-scoped object prefixes"}},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"plan:page:migrate:minio-bucket:tenant-scoped-object-prefixes","label":"Prepare a side-effect-free deployment plan for an authorized project","operationId":"plan_deployment","method":"POST","relativePath":"/v1/catalog/plan","origin":"api","parameters":{"body":{"inputs":{},"projectId":"<workspace or server id you own>","recipeId":"page:migrate:minio-bucket:tenant-scoped-object-prefixes","recipeRevision":"r1"}},"requiresAuthentication":true,"requiresApproval":false},{"actionId":"auth-setup","label":"Read the existing agent authentication setup","operationId":"existing_auth_setup","method":"GET","relativePath":"/mcp/setup","origin":"api","parameters":{},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"browse:migration:minio-bucket","label":"Browse MinIO bucket","operationId":"browse_node","method":"GET","relativePath":"/v1/catalog/nodes/migration%3Aminio-bucket","origin":"api","parameters":{"nodeId":"migration:minio-bucket"},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"browse:pattern:tenant-scoped-object-prefixes","label":"Browse Tenant-scoped object prefixes","operationId":"browse_node","method":"GET","relativePath":"/v1/catalog/nodes/pattern%3Atenant-scoped-object-prefixes","origin":"api","parameters":{"nodeId":"pattern:tenant-scoped-object-prefixes"},"requiresAuthentication":false,"requiresApproval":false},{"actionId":"browse:intent:migrate-objects","label":"Browse Migrate objects","operationId":"browse_node","method":"GET","relativePath":"/v1/catalog/nodes/intent%3Amigrate-objects","origin":"api","parameters":{"nodeId":"intent:migrate-objects"},"requiresAuthentication":false,"requiresApproval":false}]}