fix: do not expose analytics by default

This commit is contained in:
Andrey A. authored and GitHub committed 2026-02-16 13:23:16 +01:00
1 parent a3d789f564
commit f24df26d7b
3 files changed
+42 -36

No files matched your search

+2 -2
View File
@@ -356,8 +356,8 @@ services:
container_name: supabase-analytics
image: supabase/logflare:1.30.3
restart: unless-stopped
ports:
- 4000:4000
# ports:
# - 4000:4000
# Uncomment to use Big Query backend for analytics
# volumes:
# - type: bind
+23 -23
View File
@@ -197,29 +197,29 @@ services:
- name: cors
## Analytics routes
- name: analytics-v1-api
_comment: 'Analytics: /analytics/v1/api/endpoints/* -> http://logflare:4000/api/endpoints/*'
url: http://analytics:4000/api/endpoints
routes:
- name: analytics-v1-api
strip_path: true
paths:
- /analytics/v1/api/endpoints/
# auth on analytics dashboard
- name: analytics-v1
_comment: 'Analytics: /analytics/v1/* -> http://logflare:4000/*'
url: http://analytics:4000/
routes:
- name: dashboard-v1-all
strip_path: true
paths:
- /analytics/v1
plugins:
- name: cors
- name: basic-auth
config:
hide_credentials: true
## Not used - Studio and Vector talk directly to analytics via Docker networking.
## If external access is needed, add routes with key-auth matching Logflare's x-api-key auth.
# - name: analytics-v1-api
# _comment: 'Analytics: /analytics/v1/api/endpoints/* -> http://logflare:4000/api/endpoints/*'
# url: http://analytics:4000/api/endpoints
# routes:
# - name: analytics-v1-api
# strip_path: true
# paths:
# - /analytics/v1/api/endpoints/
# - name: analytics-v1
# _comment: 'Analytics: /analytics/v1/* -> http://logflare:4000/*'
# url: http://analytics:4000/
# routes:
# - name: dashboard-v1-all
# strip_path: true
# paths:
# - /analytics/v1
# plugins:
# - name: cors
# - name: basic-auth
# config:
# hide_credentials: true
## Secure Database routes
- name: meta
+17 -11
View File
@@ -177,7 +177,8 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
uri: 'http://analytics:4000/api/logs?source_name=gotrue.logs.prod'
@@ -189,7 +190,8 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
uri: 'http://analytics:4000/api/logs?source_name=realtime.logs.prod'
@@ -201,7 +203,8 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
uri: 'http://analytics:4000/api/logs?source_name=postgREST.logs.prod'
@@ -213,13 +216,13 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
# We must route the sink through kong because ingesting logs before logflare is fully initialised will
# lead to broken queries from studio. This works by the assumption that containers are started in the
# following order: vector > db > logflare > kong
uri: 'http://kong:8000/analytics/v1/api/logs?source_name=postgres.logs'
# Route directly to analytics like other sinks. Retry handles the startup
# race where analytics may not be ready yet when early DB logs arrive.
uri: 'http://analytics:4000/api/logs?source_name=postgres.logs'
logflare_functions:
type: 'http'
inputs:
@@ -228,7 +231,8 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
uri: 'http://analytics:4000/api/logs?source_name=deno-relay-logs'
@@ -240,7 +244,8 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
uri: 'http://analytics:4000/api/logs?source_name=storage.logs.prod.2'
@@ -253,7 +258,8 @@ sinks:
codec: 'json'
method: 'post'
request:
retry_max_duration_secs: 10
retry_max_duration_secs: 30
retry_initial_backoff_secs: 1
headers:
x-api-key: ${LOGFLARE_PUBLIC_ACCESS_TOKEN?LOGFLARE_PUBLIC_ACCESS_TOKEN is required}
uri: 'http://analytics:4000/api/logs?source_name=cloudflare.logs.prod'