diff --git a/apps/docs/content/guides/self-hosting/docker.mdx b/apps/docs/content/guides/self-hosting/docker.mdx index aede885d840..e029e8e2618 100644 --- a/apps/docs/content/guides/self-hosting/docker.mdx +++ b/apps/docs/content/guides/self-hosting/docker.mdx @@ -514,9 +514,10 @@ sh run.sh recreate The `generate-keys.sh` script sets the following secrets automatically. You can also configure them manually in the `.env` file if needed: - `SECRET_KEY_BASE`: encryption key for securing Realtime and Supavisor communications. (Must be at least 64 characters; generate with `openssl rand -base64 48`) +- `REALTIME_DB_ENC_KEY`: encryption key used by Realtime for sensitive fields in the `_realtime` schema. (Must be exactly 16 characters; generate with `openssl rand -hex 8`) - `VAULT_ENC_KEY`: encryption key used by Supavisor for storing encrypted configuration. (Must be exactly 32 characters; generate with `openssl rand -hex 16`) - `PG_META_CRYPTO_KEY`: encryption key for securing connection strings used by Studio against postgres-meta. (Must be at least 32 characters; generate with `openssl rand -base64 24`) -- `LOGFLARE_PUBLIC_ACCESS_TOKEN`: API token for log ingestion and querying. Used by Vector and Studio to send and query logs. (Must be at least 32 characters; generate with `openssl rand -base64 24`) +- `LOGFLARE_PUBLIC_ACCESS_TOKEN`: API token for log ingestion used by Logflare and Vector. (Must be at least 32 characters; generate with `openssl rand -base64 24`) - `LOGFLARE_PRIVATE_ACCESS_TOKEN`: API token for Logflare management operations. Used by Studio for administrative tasks. Never expose client-side. (Must be at least 32 characters; generate with `openssl rand -base64 24`) - `S3_PROTOCOL_ACCESS_KEY_ID`: Access key ID (username-like) for [accessing](/docs/guides/self-hosting/self-hosted-s3) the S3 protocol endpoint in Storage. (Generate with `openssl rand -hex 16`) - `S3_PROTOCOL_ACCESS_KEY_SECRET`: Secret key (password-like) used with S3_PROTOCOL_ACCESS_KEY_ID. (Generate with `openssl rand -hex 32`) diff --git a/docker/.env.example b/docker/.env.example index 417e384fbf7..c944f572097 100644 --- a/docker/.env.example +++ b/docker/.env.example @@ -58,23 +58,34 @@ JWT_JWKS= DASHBOARD_USERNAME=supabase DASHBOARD_PASSWORD=this_password_is_insecure_and_should_be_updated -# Used by Realtime and Supavisor +# Encryption key for securing Realtime and Supavisor communications. +# (Must be at least 64 characters; generate with: openssl rand -base64 48) SECRET_KEY_BASE=UpNVntn3cDxHJpq99YMc1T1AQgQpc8kfYTuRgBiYa15BLrx8etQoXz3gZv1/u2oq -# Used by Supavisor +# Encryption key used by Realtime for sensitive fields in the `_realtime` schema. +# (Must be exactly 16 characters; generate with: `openssl rand -hex 8`) +REALTIME_DB_ENC_KEY=supabaserealtime + +# Encryption key used by Supavisor for storing encrypted configuration. +# (Must be exactly 32 characters; generate with: openssl rand -hex 16) VAULT_ENC_KEY=your-32-character-encryption-key -# Used by Studio to access Postgres via postgres-meta +# Encryption key for securing connection strings used by Studio against postgres-meta. +# (Must be at least 32 characters; generate with openssl rand -base64 24) PG_META_CRYPTO_KEY=your-encryption-key-32-chars-min -# Analytics - API tokens for log ingestion/querying, and for management -# If Logflare has to be externally exposed - configure securely! -# Used in the docker-compose.logs.yml override. +# API token for log ingestion used by Logflare and Vector. +# (Must be at least 32 characters; generate with openssl rand -base64 24) LOGFLARE_PUBLIC_ACCESS_TOKEN=your-super-secret-and-long-logflare-key-public +# API token used for Logflare management operations. Never expose client-side. +# (Must be at least 32 characters; generate with openssl rand -base64 24) LOGFLARE_PRIVATE_ACCESS_TOKEN=your-super-secret-and-long-logflare-key-private -# Access to Storage via S3 protocol endpoint (see below) +# Access key ID (username-like) for accessing the S3 protocol endpoint in Storage. +# (Generate with: openssl rand -hex 16) S3_PROTOCOL_ACCESS_KEY_ID=625729a08b95bf1b7ff351a663f3a23c +# Secret key (password-like) used with S3_PROTOCOL_ACCESS_KEY_ID. +# (Generate with: openssl rand -hex 32) S3_PROTOCOL_ACCESS_KEY_SECRET=850181e4652dd023b7a98c58ae0d2d34bd487ee0cc3254aed6eda37307425907 @@ -269,6 +280,8 @@ REGION=stub # Used by MinIO when added via: # docker compose -f docker-compose.yml -f docker-compose.s3.yml up -d MINIO_ROOT_USER=supa-storage +# Root administrator password for the RustFS or MinIO server. +# (Must be 8+ characters; generate with: openssl rand -hex 16) MINIO_ROOT_PASSWORD=secret1234 # Equivalent to project_ref as described here: diff --git a/docker/CONFIG.md b/docker/CONFIG.md index ae5ed04fd04..50cb34b88b5 100644 --- a/docker/CONFIG.md +++ b/docker/CONFIG.md @@ -126,7 +126,6 @@ These mirror the running PostgREST configuration so the dashboard can display co |---|---|---|---|---| | `LOGFLARE_API_KEY` | string | Self-hosted | Legacy alias for `LOGFLARE_PUBLIC_ACCESS_TOKEN`. | Deprecated. Declared in `apps/studio/turbo.jsonc` but not read by Studio code; kept only for backward compatibility with older deployments. | | `LOGFLARE_PRIVATE_ACCESS_TOKEN` | string | Both | Private API token Studio uses server-side to query Logflare endpoints (logs, charts). | Required for logs/analytics features to work on self-hosted. | -| `LOGFLARE_PUBLIC_ACCESS_TOKEN` | string | Self-hosted | Public API token used by the analytics (supabase/logflare) container for ingestion. | Not read by Studio code (despite being in `apps/studio/turbo.jsonc`). Passed through the `studio` service env in `docker-compose.yml` for parity only. | | `LOGFLARE_URL` | URL | Both | Base URL of the Logflare/analytics service. | E.g. `http://analytics:4000`. Used to build the `PROJECT_ANALYTICS_URL`. | | `NEXT_ANALYTICS_BACKEND_PROVIDER` | enum | Both | Historically intended to select the analytics container's backend (`postgres` or `bigquery`). | No-op today: not read by Studio code, and the `analytics` (supabase/logflare) container chooses its backend via `POSTGRES_BACKEND_URL` / `LOGFLARE_FEATURE_FLAG_OVERRIDE` instead. Safe to ignore. | | `NEXT_PUBLIC_ENABLE_LOGS` | boolean | Both | Historically intended to toggle visibility of log explorer pages. | Not read by Studio code today, and not declared in `apps/studio/turbo.jsonc`. Use `ENABLED_FEATURES_LOGS_ALL` (see Feature flags below) for runtime control of the logs section. | diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml index bdf8926ecc6..db9ab04a4f8 100644 --- a/docker/docker-compose.yml +++ b/docker/docker-compose.yml @@ -312,7 +312,7 @@ services: DB_PASSWORD: ${POSTGRES_PASSWORD} DB_NAME: ${POSTGRES_DB} DB_AFTER_CONNECT_QUERY: 'SET search_path TO _realtime' - DB_ENC_KEY: supabaserealtime + DB_ENC_KEY: ${REALTIME_DB_ENC_KEY:-supabaserealtime} # Legacy symmetric HS256 key API_JWT_SECRET: ${JWT_SECRET} diff --git a/docker/utils/generate-keys.sh b/docker/utils/generate-keys.sh index 23b0b1a4d3e..da1fc19218c 100644 --- a/docker/utils/generate-keys.sh +++ b/docker/utils/generate-keys.sh @@ -61,6 +61,7 @@ anon_key=$(gen_token "$anon_payload") service_role_key=$(gen_token "$service_role_payload") secret_key_base=$(gen_base64 48) +realtime_db_enc_key=$(gen_hex 8) vault_enc_key=$(gen_hex 16) pg_meta_crypto_key=$(gen_base64 24) @@ -81,6 +82,7 @@ echo "ANON_KEY=${anon_key}" echo "SERVICE_ROLE_KEY=${service_role_key}" echo "" echo "SECRET_KEY_BASE=${secret_key_base}" +echo "REALTIME_DB_ENC_KEY=${realtime_db_enc_key}" echo "VAULT_ENC_KEY=${vault_enc_key}" echo "PG_META_CRYPTO_KEY=${pg_meta_crypto_key}" echo "LOGFLARE_PUBLIC_ACCESS_TOKEN=${logflare_public_access_token}" @@ -123,6 +125,7 @@ sed \ -e "s|^ANON_KEY=.*$|ANON_KEY=${anon_key}|" \ -e "s|^SERVICE_ROLE_KEY=.*$|SERVICE_ROLE_KEY=${service_role_key}|" \ -e "s|^SECRET_KEY_BASE=.*$|SECRET_KEY_BASE=${secret_key_base}|" \ + -e "s|^REALTIME_DB_ENC_KEY=.*$|REALTIME_DB_ENC_KEY=${realtime_db_enc_key}|" \ -e "s|^VAULT_ENC_KEY=.*$|VAULT_ENC_KEY=${vault_enc_key}|" \ -e "s|^PG_META_CRYPTO_KEY=.*$|PG_META_CRYPTO_KEY=${pg_meta_crypto_key}|" \ -e "s|^LOGFLARE_PUBLIC_ACCESS_TOKEN=.*$|LOGFLARE_PUBLIC_ACCESS_TOKEN=${logflare_public_access_token}|" \