From b3114508d0043fa92b01068d9a0848b7e2115732 Mon Sep 17 00:00:00 2001 From: Ahmed El-Sharnoby Date: Mon, 21 Aug 2023 23:46:23 +0000 Subject: [PATCH] Dashboard default credentials substitution in kong.yml --- apps/docs/pages/guides/self-hosting/docker.mdx | 7 ++++++- docker/.env.example | 3 ++- docker/docker-compose.yml | 2 ++ docker/volumes/api/kong.yml | 4 ++-- 4 files changed, 12 insertions(+), 4 deletions(-) diff --git a/apps/docs/pages/guides/self-hosting/docker.mdx b/apps/docs/pages/guides/self-hosting/docker.mdx index e2d9831e3ea..cbc7a4e3756 100644 --- a/apps/docs/pages/guides/self-hosting/docker.mdx +++ b/apps/docs/pages/guides/self-hosting/docker.mdx @@ -112,7 +112,12 @@ You will need to [restart](#restarting-all-services) the services for the change ### Dashboard Authentication -The dashboard is protected with Basic Authentication. The default user and password MUST be updated before using Supabase in production. You can update the `./docker/volumes/api/kong.yml` file with your own credentials. For example: +The dashboard is protected with Basic Authentication. The default user and password MUST be updated before using Supabase in production. +Update the following values in the `.env` file: + - `DASHBOARD_USERNAME`: The default username for the Dashboard + - `DASHBOARD_PASSWORD`: The default password for the Dashboard + +You can Also update the `./docker/volumes/api/kong.yml` file with your own credentials. For example: ```yaml docker/volumes/api/kong.yml basicauth_credentials: diff --git a/docker/.env.example b/docker/.env.example index 21304c2557b..b86c11239dc 100644 --- a/docker/.env.example +++ b/docker/.env.example @@ -7,7 +7,8 @@ POSTGRES_PASSWORD=your-super-secret-and-long-postgres-password JWT_SECRET=your-super-secret-jwt-token-with-at-least-32-characters-long ANON_KEY=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyAgCiAgICAicm9sZSI6ICJhbm9uIiwKICAgICJpc3MiOiAic3VwYWJhc2UtZGVtbyIsCiAgICAiaWF0IjogMTY0MTc2OTIwMCwKICAgICJleHAiOiAxNzk5NTM1NjAwCn0.dc_X5iR_VP_qT0zsiyj_I_OZ2T9FtRU2BBNWN8Bu4GE SERVICE_ROLE_KEY=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyAgCiAgICAicm9sZSI6ICJzZXJ2aWNlX3JvbGUiLAogICAgImlzcyI6ICJzdXBhYmFzZS1kZW1vIiwKICAgICJpYXQiOiAxNjQxNzY5MjAwLAogICAgImV4cCI6IDE3OTk1MzU2MDAKfQ.DaYlNEoUrrEn2Ig7tqibS-PHK5vgusbcbo7X36XVt4Q - +DASHBOARD_USERNAME=supabase +DASHBOARD_PASSWORD=this_password_is_insecure_and_should_be_updated ############ # Database - You can change these to any PostgreSQL database that has logical replication enabled. diff --git a/docker/docker-compose.yml b/docker/docker-compose.yml index e51fac0489a..0835f6b7a86 100644 --- a/docker/docker-compose.yml +++ b/docker/docker-compose.yml @@ -78,6 +78,8 @@ services: KONG_NGINX_PROXY_PROXY_BUFFERS: 64 160k SUPABASE_ANON_KEY: ${ANON_KEY} SUPABASE_SERVICE_KEY: ${SERVICE_ROLE_KEY} + DASHBOARD_USERNAME: ${DASHBOARD_USERNAME} + DASHBOARD_PASSWORD: ${DASHBOARD_PASSWORD} volumes: # https://github.com/supabase/supabase/issues/12661 - ./volumes/api/kong.yml:/home/kong/temp.yml:ro diff --git a/docker/volumes/api/kong.yml b/docker/volumes/api/kong.yml index 68828eac94c..4a07995037a 100644 --- a/docker/volumes/api/kong.yml +++ b/docker/volumes/api/kong.yml @@ -27,8 +27,8 @@ acls: ### basicauth_credentials: - consumer: DASHBOARD - username: supabase - password: this_password_is_insecure_and_should_be_updated + username: $DASHBOARD_USERNAME + password: $DASHBOARD_PASSWORD ###