add network restrictions and ssl to prod checklist

This commit is contained in:
Inian committed 2023-08-11 09:37:33 +08:00
1 parent d9a2a4d4f2
commit 11013b8ac6
1 file changed
+2
@@ -20,6 +20,8 @@ After developing your project and deciding it's Production Ready, you should run
- Enable replication on tables containing sensitive data by enabling Row Level Security (RLS) and setting row security policies:
- Go to the Authentication > Policies page in the Supabase Dashboard to enable RLS and create security policies.
- Go to the Database > Replication page in the Supabase Dashboard to manage replication tables.
- Turn on [SSL Enforcement](/docs/guides/platform/ssl-enforcement)
- Enable [Network Restrictions](/docs/guides/platform/network-restrictions) for your database.
- Enable 2FA on GitHub. Since your GitHub account gives you administrative rights to your Supabase project, you should protect it with a strong password and 2FA using a U2F key or a TOTP app.
- Ensure email confirmations are enabled in the `Settings > Auth` page.
- Use a custom SMTP server for auth emails so that your users can see that the mails are coming from a trusted domain (preferably the same domain that your app is hosted on). Grab SMTP credentials from any major email provider such as SendGrid, AWS SES, etc.