From 3a3661019f4f7dd79a5941bc379741bf45396047 Mon Sep 17 00:00:00 2001 From: Nik Richers Date: Fri, 31 Jul 2026 16:00:47 -0700 Subject: [PATCH] docs: update architecture diagram and references from Kong to Envoy (#48557) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? This is a docs update. The shared architecture diagram and several docs pages still described Kong as Supabase's API gateway, even though the hosted platform has run Envoy since 2025. Both diagram variants are rebuilt with real, accessible text — the originals rendered every label as an outlined vector path with zero `` elements — so the gateway name can be kept current going forward, and the platform-facing prose that named Kong directly is updated to Envoy. Closes DOCS-1262. ## What is the current behavior? - The architecture diagram (used on the Architecture overview, Auth architecture, Self-hosting Docker, and Contributing guide pages) shows "KONG / docs.konghq.com" as the gateway box - The Architecture overview page has a "Kong (API gateway)" component section - The Auth architecture page states "Kong API gateway. This is shared between all Supabase products." - `README.md` and `apps/docs/public/humans.txt` credit Kong instead of Envoy ## What is the new behavior? - Rebuilt `supabase-architecture.svg` and `supabase-architecture--light.svg` with real `` elements; the gateway box now reads "ENVOY / envoyproxy.io" with identical layout, colors, and shadows otherwise - Updated the diagram alt text and the "Kong (API gateway)" section (now "Envoy (API gateway)", with the correct docs link, license, and language) on the Architecture overview page - Updated the "Kong API gateway" bullet and diagram alt text on the Auth architecture page - Updated the Kong credit to Envoy in `README.md` and `apps/docs/public/humans.txt` **Intentionally excluded:** - Self-hosted Docker Compose pages (`docker.mdx`, `enable-mcp.mdx`, `self-hosted-auth-keys.mdx`, `self-hosted-envoy.mdx`, `self-hosted-functions.mdx`, `self-hosted-proxy-https.mdx`) — these describe the self-hosted stack, which still defaults to Kong today and is already owned by an open PR (#48153) that flips that default - `i18n/README.*.md` (29 files) — translation risk without native-speaker review; only the English `README.md` was updated ## Open questions - [ ] #48153 merges and the self-hosted default actually flips to Envoy — once it does, revisit the self-hosting Docker Compose pages excluded from this PR and the self-hosting-analytics reference TODO - [ ] Confirm whether all legacy platform instances have fully migrated to Envoy — until then, this PR's wording says "Envoy" without claiming Kong is gone everywhere (some legacy instances may still silently be on Kong) - [ ] Current Envoy response header names confirmed for the logs guide TODO (`x-kong-proxy-latency` / `x-kong-upstream-latency`) - [ ] i18n README translations (29 files) follow up separately with native-speaker review ## Additional context - Verification: rendered both new SVGs with `rsvg-convert` and visually diffed against the originals — layout, spacing, colors, and shadows are pixel-equivalent; only the top-box label text changed | Check | Result | | --- | --- | | `rsvg-convert` render, dark variant | pass — diagram unchanged except gateway label | | `rsvg-convert` render, light variant | pass — diagram unchanged except gateway label | | Preview URL, Architecture overview | pass — 200 | | Preview URL, Auth architecture | pass — 200 | ### Before & After #### [Architecture overview](https://supabase.com/docs/guides/getting-started/architecture) | [Before (production)](https://supabase.com/docs/guides/getting-started/architecture) | [After (PR preview)](https://docs-git-nikrichers-docs-1262-architecture-docs-84e339-supabase.vercel.app/docs/guides/getting-started/architecture) | | --- | --- | | ![Before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/getting-started-before-crop-a67d5681.png) | ![After](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/getting-started-after-crop-7d2b027a.png) | #### [Auth architecture](https://supabase.com/docs/guides/auth/architecture) | [Before (production)](https://supabase.com/docs/guides/auth/architecture) | [After (PR preview)](https://docs-git-nikrichers-docs-1262-architecture-docs-84e339-supabase.vercel.app/docs/guides/auth/architecture) | | --- | --- | | ![Before](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/auth-before-c68a7267.png) | ![After](https://moijyfpvgnmgoxvwcikq.supabase.co/storage/v1/object/public/pr-proof/supabase/supabase/pr48557/auth-after-3de5c4c5.png) | ### Test plan - [ ] Diagram renders correctly in both light and dark mode on the preview - [ ] "Envoy (API gateway)" section reads correctly on the Architecture overview page - [ ] Auth architecture bullet reads "Envoy API gateway" - [ ] The two TODO-marked follow-ups (logs guide, self-hosting-analytics) are acceptable to leave for later rather than block this PR --------- Co-authored-by: Nik Richers Co-authored-by: Miranda Limonczenko --- README.md | 2 +- .../docs/content/guides/auth/architecture.mdx | 4 +- .../guides/getting-started/architecture.mdx | 14 ++--- apps/docs/public/humans.txt | 2 +- .../img/supabase-architecture--light.svg | 51 +++++++++++++------ .../docs/public/img/supabase-architecture.svg | 51 +++++++++++++------ 6 files changed, 81 insertions(+), 43 deletions(-) diff --git a/README.md b/README.md index 08120545543..0b5a5e6f455 100644 --- a/README.md +++ b/README.md @@ -57,7 +57,7 @@ You can also [self-host](https://supabase.com/docs/guides/hosting/overview) and - [Storage](https://github.com/supabase/storage-api) a RESTful API for managing files in S3, with Postgres handling permissions. - [pg_graphql](http://github.com/supabase/pg_graphql/) a PostgreSQL extension that exposes a GraphQL API. - [postgres-meta](https://github.com/supabase/postgres-meta) is a RESTful API for managing your Postgres, allowing you to fetch tables, add roles, and run queries, etc. -- [Kong](https://github.com/Kong/kong) is a cloud-native API gateway. +- [Envoy](https://github.com/envoyproxy/envoy) is a cloud-native, high-performance edge and service proxy. #### Client libraries diff --git a/apps/docs/content/guides/auth/architecture.mdx b/apps/docs/content/guides/auth/architecture.mdx index b4c0a53092b..3665526c40c 100644 --- a/apps/docs/content/guides/auth/architecture.mdx +++ b/apps/docs/content/guides/auth/architecture.mdx @@ -6,12 +6,12 @@ subtitle: 'The architecture behind Supabase Auth.' There are four major layers to Supabase Auth: 1. [Client layer.](#client-layer) This can be one of the Supabase client SDKs, or manually made HTTP requests using the HTTP client of your choice. -1. Kong API gateway. This is shared between all Supabase products. +1. Envoy API gateway. This is shared between all Supabase products. 1. [Auth service](#auth-service) (formerly known as GoTrue). 1. [Postgres database.](#postgres) This is shared between all Supabase products. Diagram showing the architecture of Supabase. The Kong API gateway sits in front of 7 services: GoTrue, PostgREST, Realtime, Storage, pg_meta, Functions, and pg_graphql. All the services talk to a single Postgres instance. - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -171,4 +171,23 @@ + +ENVOY +envoyproxy.io +POSTGRESQL +postgresql.org +GoTrue +PostgREST +Realtime +Storage +pg-meta +Functions +pg_graphql +/auth +/rest +/realtime +/storage +/pg +/functions +/graphql diff --git a/apps/docs/public/img/supabase-architecture.svg b/apps/docs/public/img/supabase-architecture.svg index 2b0ad6325a9..6b4dfd3dc8f 100644 --- a/apps/docs/public/img/supabase-architecture.svg +++ b/apps/docs/public/img/supabase-architecture.svg @@ -15,69 +15,69 @@ - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + - + @@ -171,4 +171,23 @@ + +ENVOY +envoyproxy.io +POSTGRESQL +postgresql.org +GoTrue +PostgREST +Realtime +Storage +pg-meta +Functions +pg_graphql +/auth +/rest +/realtime +/storage +/pg +/functions +/graphql