docs: update shared responsibility model (#27746)

* docs: update shared responsiblity model

Adds a basic matrix of shared responsibility.
Outlines a few more security responsibilities held by the customer.
Links to the Supabase production readiness checklist.

* fix-typo: americanize spelling

* typo: run prettier over new content

* fix typo

* switch to graphic for shared responsibility model

* rerun prettier
This commit is contained in:
Etienne Stalmans authored and GitHub committed 2024-07-04 08:28:59 +02:00
1 parent 211ed6d02f
commit 31130fed4c
2 files changed
+21

No files matched your search

@@ -6,6 +6,19 @@ description: 'Running databases is a shared responsibility between you and Supab
Running databases is a shared responsibility between you and Supabase. There are some things that we can take care of for you, and some things that you are responsible for. This is by design: we want to give you the freedom to use your database however you want. While we _could_ put many more restrictions in place to ensure that you can’t do anything wrong, you will eventually find those restrictions prohibitive.
<img
alt="Shared responsibility model"
src="/docs/img/platform/shared-responsibility-model.png"
width="100%"
/>
To summarize, you are always responsible for:
- Your Supabase account
- Access management (Supabase account, database, tables, etc)
- Data
- Applying security controls
Generally, we aim to reduce your burden of managing infrastructure and knowing about Postgres internals, minimizing configuration as much as we can. Here are a few things that you should know:
## You share the security responsibility
@@ -16,6 +29,10 @@ If you have an inexperienced member on your team, then you probably shouldn’t
You are also responsible for ensuring that tables with sensitive data have the right level of access. You are also responsible for managing your database secrets and API keys, storing them safely in an encrypted store.
Supabase provides controls for [securing your data](/docs/guides/database/secure-data), and it is recommended that you always apply [Row Level Security](/docs/guides/database/postgres/row-level-security) (RLS).
We will also provide you with security alerts through [Security Advisor](https://supabase.com/dashboard/project/_/database/security-advisor) and applying the recommendations are your responsibility.
## You decide your own workflow
There are _many_ ways to work with Supabase.
@@ -44,6 +61,10 @@ You are responsible for using best-practices to optimize and manage your databas
You are responsible of provisioning enough compute to run the workload that your application requires. The Supabase Dashboard provides [observability tooling](https://supabase.com/dashboard/project/_/reports/database) to help with this.
## Before going to production
We recommend reviewing and applying the recommendations offered in our [Production Checklist](/docs/guides/platform/going-into-prod). This checklist covers the responsibilities discussed here and a few additional general production readiness best practices.
## Managing healthcare data
You can use Supabase to store and process Protected Health Information (PHI). You are responsible for the following
Binary file not shown.

After

Width:  |  Height:  |  Size: 325 KiB