From 980c1bc3cbe87ca653e82d52e4215cbf614724cc Mon Sep 17 00:00:00 2001 From: "Andrey A." <56412611+aantti@users.noreply.github.com> Date: Fri, 15 May 2026 09:37:20 +0200 Subject: [PATCH] chore(self-hosted): update prerequisites and example in docs (#45948) --- apps/docs/content/guides/self-hosting/docker.mdx | 14 ++++++++++---- .../guides/self-hosting/self-hosted-auth-keys.mdx | 14 ++++++++------ 2 files changed, 18 insertions(+), 10 deletions(-) diff --git a/apps/docs/content/guides/self-hosting/docker.mdx b/apps/docs/content/guides/self-hosting/docker.mdx index d6ee98a7de5..3f0e7fc1701 100644 --- a/apps/docs/content/guides/self-hosting/docker.mdx +++ b/apps/docs/content/guides/self-hosting/docker.mdx @@ -38,7 +38,7 @@ You need the following installed on your system: - **macOS**: Install [Docker Desktop](https://docs.docker.com/desktop/install/mac-install/) - **Windows**: Install [Docker Desktop](https://docs.docker.com/desktop/install/windows-install/) {/* supa-mdx-lint-disable-next-line Rule003Spelling */} -- OpenSSL and Node.js 16+ (when switching to the [new API keys](/docs/guides/self-hosting/self-hosted-auth-keys) and new auth) +- OpenSSL ## System requirements @@ -63,7 +63,9 @@ size="small" type="underlined" defaultActiveId="general" -> +> + + ```sh # Get the code @@ -91,13 +93,16 @@ docker compose pull ``` + ```sh # Get the code using git sparse checkout -git clone --filter=blob:none --no-checkout https://github.com/supabase/supabase +git clone --filter=blob:none --no-checkout --depth=1 --quiet https://github.com/supabase/supabase cd supabase -git sparse-checkout set --cone docker && git checkout master +git sparse-checkout init --cone +git sparse-checkout set docker +git checkout --quiet cd .. # Make your new supabase project directory @@ -122,6 +127,7 @@ docker compose pull ``` + diff --git a/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx b/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx index e8510944c77..d2048c3225f 100644 --- a/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx +++ b/apps/docs/content/guides/self-hosting/self-hosted-auth-keys.mdx @@ -10,7 +10,6 @@ You can configure self-hosted Supabase to use the [new API keys](/docs/guides/ge {/* supa-mdx-lint-disable-next-line Rule003Spelling */} -- Ensure OpenSSL and Node.js 16+ are available on the machine where you will generate new keys - Complete the [Docker setup guide](/docs/guides/self-hosting/docker), including running `generate-keys.sh` so that `JWT_SECRET`, `ANON_KEY`, and `SERVICE_ROLE_KEY` are set in your `.env` file - If you are upgrading an existing self-hosted Supabase environment, make sure to check the [changelog](https://github.com/supabase/supabase/blob/master/docker/CHANGELOG.md) and add/update the following files: - `.env.example` (merge new sections into your `.env` file) @@ -36,7 +35,7 @@ The script reads `JWT_SECRET` from `.env` and includes it as a symmetric key ins -After updating `.env`, enable new authentication by uncommenting these lines in `docker-compose.yml`: +The following configuration should be uncommented in the `.env` file for the new authentication to work correctly: ```yaml name=docker-compose.yml auth: @@ -44,6 +43,11 @@ auth: # JSON array of signing JWKs (EC private + legacy symmetric) GOTRUE_JWT_KEYS: ${JWT_KEYS:-[]} +rest: + environment: + # PostgREST accepts a plain-text symmetric secret, a single JWK, or a JWKS. + PGRST_JWT_SECRET: ${JWT_JWKS:-${JWT_SECRET}} + realtime: environment: # JWKS for token verification (EC public + legacy symmetric) @@ -55,8 +59,6 @@ storage: JWT_JWKS: ${JWT_JWKS:-{"keys":[]}} ``` -PostgREST does not need uncommenting - it already uses `PGRST_JWT_SECRET: ${JWT_JWKS:-${JWT_SECRET}}` which automatically picks up `JWT_JWKS` when set. - Podman does not support nested variable interpolation (`${A:-${B}}`). If you are using Podman, replace each nested expression with the required variable directly - see the inline comments in `docker-compose.yml` for the exact substitutions. @@ -84,14 +86,14 @@ Test with the new publishable key: ```sh curl http:///rest/v1/ \ --H "apikey: your-supabase-publishable-key" +-H "apikey: your-supabase-secret-key" ``` You should receive a valid response from PostgREST. Then verify that the legacy key still works: ```sh curl http:///rest/v1/ \ --H "apikey: your-anon-key" +-H "apikey: your-service-role-key" ``` Both should work and return the same result.