mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
feat(self-hosting): add SAML SSO env config and open Kong routes (#43385)
This commit is contained in:
1 parent
d2a4e2848d
commit
f128106801
4 files changed
+66
-11
No files matched your search
+25
-4
@@ -166,7 +166,7 @@ ENABLE_PHONE_AUTOCONFIRM=true
|
||||
## OAuth / Social login providers
|
||||
|
||||
# Uncomment and fill in the providers you want to enable.
|
||||
# You must ALSO uncomment the matching GOTRUE_EXTERNAL_* lines in docker-compose.yml.
|
||||
# You must ALSO uncomment the matching GOTRUE_EXTERNAL_* lines in docker-compose.yml
|
||||
# Documentation: https://supabase.com/docs/guides/self-hosting/self-hosted-oauth
|
||||
# GOOGLE_ENABLED=false
|
||||
# GOOGLE_CLIENT_ID=
|
||||
@@ -182,7 +182,7 @@ ENABLE_PHONE_AUTOCONFIRM=true
|
||||
|
||||
# Phone / SMS provider configuration
|
||||
# Uncomment to configure SMS delivery for phone auth and phone MFA.
|
||||
# You must ALSO uncomment the matching GOTRUE_SMS_* lines in docker-compose.yml.
|
||||
# You must ALSO uncomment the matching GOTRUE_SMS_* lines in docker-compose.yml
|
||||
# Documentation: https://supabase.com/docs/guides/self-hosting/self-hosted-phone-mfa
|
||||
# SMS_PROVIDER=twilio
|
||||
# SMS_OTP_EXP=60
|
||||
@@ -200,7 +200,7 @@ ENABLE_PHONE_AUTOCONFIRM=true
|
||||
|
||||
# Multi-factor authentication (MFA)
|
||||
# Uncomment to change MFA defaults.
|
||||
# You must ALSO uncomment the matching GOTRUE_MFA_* lines in docker-compose.yml.
|
||||
# You must ALSO uncomment the matching GOTRUE_MFA_* lines in docker-compose.yml
|
||||
|
||||
# App Authenticator (TOTP) - enabled by default
|
||||
# MFA_TOTP_ENROLL_ENABLED=true
|
||||
@@ -210,9 +210,30 @@ ENABLE_PHONE_AUTOCONFIRM=true
|
||||
# MFA_PHONE_ENROLL_ENABLED=false
|
||||
# MFA_PHONE_VERIFY_ENABLED=false
|
||||
|
||||
## Maximum MFA factors a user can enroll
|
||||
# Maximum MFA factors a user can enroll
|
||||
# MFA_MAX_ENROLLED_FACTORS=10
|
||||
|
||||
## SAML SSO
|
||||
|
||||
# You must ALSO uncomment the matching GOTRUE_* lines in docker-compose.yml
|
||||
# Documentation: https://supabase.com/docs/guides/self-hosting/self-hosted-saml-sso
|
||||
|
||||
# SAML_ENABLED=true
|
||||
# SAML_PRIVATE_KEY=<your-base64-encoded-private-key>
|
||||
|
||||
# Optional: accept encrypted SAML assertions from IdPs (default: false)
|
||||
# SAML_ALLOW_ENCRYPTED_ASSERTIONS=false
|
||||
|
||||
# Optional: how long relay state tokens remain valid (default: 2m0s)
|
||||
# SAML_RELAY_STATE_VALIDITY_PERIOD=2m0s
|
||||
|
||||
# Optional: override the SAML entity ID / ACS base URL
|
||||
# Defaults to API_EXTERNAL_URL if not set
|
||||
# SAML_EXTERNAL_URL=https://supabase.example.com:8000
|
||||
|
||||
# Optional: rate limit on the ACS endpoint (requests per second, default: 15)
|
||||
# SAML_RATE_LIMIT_ASSERTION=15
|
||||
|
||||
|
||||
############
|
||||
# Storage - Configuration for Storage
|
||||
|
||||
Reference in new issue
Block a user