From 11013b8ac67de8043edc53cd0dee25e4131a33ef Mon Sep 17 00:00:00 2001 From: Inian Date: Fri, 4 Aug 2023 14:17:13 +0800 Subject: [PATCH] add network restrictions and ssl to prod checklist --- apps/docs/pages/guides/platform/going-into-prod.mdx | 2 ++ 1 file changed, 2 insertions(+) diff --git a/apps/docs/pages/guides/platform/going-into-prod.mdx b/apps/docs/pages/guides/platform/going-into-prod.mdx index 6e8bd43de81..289e437cda0 100644 --- a/apps/docs/pages/guides/platform/going-into-prod.mdx +++ b/apps/docs/pages/guides/platform/going-into-prod.mdx @@ -20,6 +20,8 @@ After developing your project and deciding it's Production Ready, you should run - Enable replication on tables containing sensitive data by enabling Row Level Security (RLS) and setting row security policies: - Go to the Authentication > Policies page in the Supabase Dashboard to enable RLS and create security policies. - Go to the Database > Replication page in the Supabase Dashboard to manage replication tables. +- Turn on [SSL Enforcement](/docs/guides/platform/ssl-enforcement) +- Enable [Network Restrictions](/docs/guides/platform/network-restrictions) for your database. - Enable 2FA on GitHub. Since your GitHub account gives you administrative rights to your Supabase project, you should protect it with a strong password and 2FA using a U2F key or a TOTP app. - Ensure email confirmations are enabled in the `Settings > Auth` page. - Use a custom SMTP server for auth emails so that your users can see that the mails are coming from a trusted domain (preferably the same domain that your app is hosted on). Grab SMTP credentials from any major email provider such as SendGrid, AWS SES, etc.