chore(self-hosted): remove backticks in headers in self-hosted how-to (#44184)

This commit is contained in:
Andrey A. authored and GitHub committed 2026-03-26 08:54:46 +01:00
1 parent 55852a0eb1
commit fe08059cb7
6 files changed
+20 -16

No files matched your search

@@ -446,7 +446,7 @@ See the [Configure Phone Login & MFA](/docs/guides/self-hosting/self-hosted-phon
Configuring the Supabase AI Assistant is optional. By adding **your own** `OPENAI_API_KEY` to `.env` you can enable AI services, which help with writing SQL queries, statements, and policies.
#### Setting database's `log_min_messages`
#### Setting log_min_messages in Postgres
By default, the database's `log_min_messages` configuration is set to `fatal` in [docker-compose.yml](https://github.com/supabase/supabase/blob/df8729a82b1847e2989c14ede27965612761d503/docker/docker-compose.yml#L466) to prevent redundant logs generated by Realtime. You can configure `log_min_messages` using any of the Postgres [Severity Levels](https://www.postgresql.org/docs/current/runtime-config-logging.html#RUNTIME-CONFIG-SEVERITY-LEVELS).
@@ -131,7 +131,7 @@ When `JWT_KEYS` is set, Auth will start signing new user session JWTs with the n
</Admonition>
## Rotating `sb_` API keys
## Rotating the new API keys
If your new API keys are compromised or you want to rotate them periodically, you can regenerate `sb_publishable` and `sb_secret` without touching the asymmetric key pair:
@@ -175,9 +175,9 @@ Regenerating asymmetric keys invalidates all ES256 user sessions. Plan a mainten
Below are a few notes on the details of the new authentication architecture.
### What `supabase-js` sends
### What client SDK sends
Every request includes two headers:
Every request via `supabase-js` includes two headers:
- `apikey` - the API key (`sb_` or legacy JWT)
- `Authorization` - when unauthenticated, the client SDK copies the API key here (`Bearer sb_publishable_xxx` or `Bearer eyJ...`). When authenticated, this contains the user session JWT minted by Auth.
@@ -24,7 +24,7 @@ This returns `"Hello from Edge Functions!"`.
## Create a new function
### Step 1: Create a new directory with an `index.ts` file in `volumes/functions/`:
### Step 1: Add a new function directory and the function code
```
mkdir -p volumes/functions/my-function &&
@@ -44,13 +44,13 @@ Deno.serve(async (req: Request) => {
})
```
### Step 2: Restart the functions service to pick up the new function:
### Step 2: Restart the functions service to pick up the new function
```bash
docker compose restart functions --no-deps
```
### Step 3: Invoke your function:
### Step 3: Invoke your function
```bash
curl -X POST http://<your-domain>:8000/functions/v1/my-function \
@@ -56,7 +56,7 @@ The default `.env.example` and `docker-compose.yml` include commented-out placeh
2. Set the **authorized redirect URL**, e.g., `https://<your-domain>/auth/v1/callback`
3. Copy the **client ID** and **client secret** into your `.env` file.
### Step 2: Configure variables in the `.env` file
### Step 2: Configure environment variables
Uncomment the lines for your provider in `.env` and add your client ID and secret, e.g., for Google:
@@ -66,7 +66,9 @@ GOOGLE_CLIENT_ID=your-client-id
GOOGLE_SECRET=your-client-secret
```
### Step 3: Enable the matching lines in `docker-compose.yml`
{/* supa-mdx-lint-disable-next-line Rule001HeadingCase */}
### Step 3: Enable the matching lines in Docker Compose configuration
Uncomment the corresponding `GOTRUE_EXTERNAL_` lines in the `auth` service's `environment`:
@@ -400,12 +402,12 @@ For detailed client-side integration, see [Social Login](/docs/guides/auth/socia
## Troubleshooting
### "Provider not enabled" or provider shows `false` in `/auth/v1/settings`
### "Provider not enabled" or provider seen as false in settings
- Check that `GOTRUE_EXTERNAL_*_ENABLED` is set to `true` in `docker-compose.yml`
- Verify the `.env` variable is not empty, e.g., check with `docker compose exec auth env | grep GOOGLE`
### Variables added to `.env` but provider still not working
### Variables added to the environment but provider still not working
Configuration variables from `.env` are **not** automatically available inside the container unless there's a matching passthrough definition in `docker-compose.yml`. Check, e.g., for:
@@ -415,7 +417,7 @@ GOTRUE_EXTERNAL_GOOGLE_ENABLED: ${GOOGLE_ENABLED}
Run `docker compose exec auth env | grep GOTRUE_EXTERNAL` to verify the variables are reaching the container.
### `SITE_URL` or redirect URL errors after login
### Site URL or redirect URL errors after login
After a successful OAuth login, the Auth service redirects to `SITE_URL` or a URL from `ADDITIONAL_REDIRECT_URLS`. Ensure:
@@ -23,7 +23,7 @@ The default `.env.example` and `docker-compose.yml` include commented-out SMS pr
To enable SMS delivery:
### Step 1: Uncomment and configure the settings in `.env`
### Step 1: Uncomment and configure the environment variables
```
SMS_PROVIDER=twilio
@@ -38,7 +38,9 @@ SMS_TWILIO_AUTH_TOKEN=your-auth-token
SMS_TWILIO_MESSAGE_SERVICE_SID=your-message-service-sid
```
### Step 2: Uncomment the matching lines in `docker-compose.yml`
{/* supa-mdx-lint-disable-next-line Rule001HeadingCase */}
### Step 2: Uncomment the matching lines in Docker Compose configuration
Uncomment the `GOTRUE_SMS_*` lines in the `auth` service's `environment` block:
@@ -200,7 +202,7 @@ Common causes:
- Provider credentials are wrong
- Phone number format is wrong (use E.164 format: `+1234567890`)
### Variables are configured in `.env` but not working
### Variables added to the environment but not working
Configuration variables from `.env` are **not** automatically available inside the container unless there's a matching passthrough definition in `docker-compose.yml`. Check, e.g., for:
@@ -147,7 +147,7 @@ kong:
KONG_SSL_CERT_KEY: /home/kong/server.key
```
### Step 3: Update configuration variables in `.env`
### Step 3: Update configuration variables
Edit your `.env` file to use HTTPS with the Kong HTTPS port: