Commit Graph
86 Commits
Author SHA1 Message Date
Etienne Stalmans 04ddc6bef8 chore: update cors for pg routes (#49136)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix - config hardening

## What is the current behavior?

CORS is applied at the global level in a permissive mode

## What is the new behavior?

Self-hosted envoy config should apply CORS to the `/pg` routes. These
should only be called from the studio dashboard (when called via a
browser).

uses `SUPABASE_PUBLIC_URL`, which should mean this isn't a breaking
change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Security & Access**
  * Added stricter CORS controls for the `/pg/` route.
* Requests are limited to the configured public URL and localhost
origins.
* Standard HTTP methods and headers are supported, with preflight
responses cached for one hour.

* **Documentation**
* Updated self-hosting guidance to describe the `/pg/` route’s CORS
policy.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 10:28:09 -07:00
9ef9f1b8c1 feat(self-host): use @supabase/server in functions template and docs (#48996)
Updates the self-host Edge Functions template to use `@supabase/server`,
matching the CLI's `supabase functions new` templates (part of SDK-1150,
follows up on #45635 which exposed `SUPABASE_JWKS` to the functions
container). The `hello` example function now wraps its handler in
`withSupabase({ auth: 'none' })` and resolves the package through a
per-function `deno.json` import map, which the runtime auto-discovers,
so no dispatcher changes are needed. The self-hosted functions guide is
updated to match: the create-a-function snippet, a `ctx.supabaseAdmin`
example replacing the manual esm.sh `createClient` wiring, and a note
that `auth: 'user'` requires `SUPABASE_JWKS`. Verified on
`supabase/edge-runtime:v1.74.0` with the compose environment variables:
`curl /functions/v1/hello` returns the same response body as before, so
existing docs and troubleshooting pages stay accurate.

The `docker/.gitignore` change: `volumes/functions/**` ignores
self-hosters' own functions, but it also hid the new `deno.json`, which
must ship with the repo for the `hello` import to resolve. The allowlist
entries follow the existing `main/index.ts` pattern.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Edge Functions now support authenticated invocation with publishable
or secret API keys.
* Function handlers can access authenticated and administrative Supabase
clients through the request context.
* Added automatic environment configuration and JWT verification
support.

* **Documentation**
* Updated the self-hosting guide with the new function setup and
authentication workflow.
* Improved local function examples for supported access patterns and
privileged operations.

* **Tests**
* Updated self-hosted smoke tests to validate publishable-key function
access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Kalleby Santos <kalleby_santos@hotmail.com>
Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com>
2026-08-14 12:00:11 +03:00
Andrey A. 5a8eecf509 feat(self-hosted): envoy is the default api gateway (#48153) 2026-08-11 11:55:26 +02:00
Andrey A. 18bad2e61c chore(self-hosted): remove em-dashes (#48498) 2026-07-30 17:20:22 +00:00
Kalleby Santos 9cf6ae1f67 feat(self-host): functions expose jwks (#45635) 2026-07-08 15:32:12 +02:00
Luiz Felipe Machado 9777f051d6 feat(self-hosted): restrict rest root anon (#45462) 2026-07-07 13:16:23 +02:00
Andrey A. e7abda8dce fix(self-hosted): change default api external url to contain /auth/v1 (#47640) 2026-07-07 12:28:47 +02:00
Inder Singh 5d8d1f359f chore(self-hosted): use /bin/sh shebang in kong-entrypoint.sh (#46897) 2026-06-13 10:30:39 +00:00
Andrey A. 098157eb90 fix(self-hosted): block access to tenants and openapi realtime api (#46856) 2026-06-12 11:48:58 +02:00
Luiz Felipe Machado 94ac6f3fa3 fix(self-hosted): reject access via internal jwt api keys when translation is enabled (#46023) 2026-05-26 17:03:13 +02:00
Sonu Yadav 1f28a37569 fix(self-hosted): allow configuring supavisor tenant db_host via env var (#41273) 2026-05-14 22:54:20 +02:00
Luiz Felipe Machado 5fa012cfa9 docs(self-hosted): clarify envoy api gateway setup (#45238) 2026-04-29 09:33:53 +00:00
Luiz Felipe Machado 53060160aa fix(self-hosted): api key translation should depend on the sb_ keys present (#45195) 2026-04-24 12:17:50 +02:00
Luiz Felipe Machado e080513666 feat: add Envoy API gateway for self-hosted Docker Compose (#43838) 2026-04-22 11:20:32 +02:00
Andrey A. b34d8e6609 add routes for saml sso to self-hosted proxy configs (#44440) 2026-04-01 18:18:50 +02:00
Luiz Felipe Machado f128106801 feat(self-hosting): add SAML SSO env config and open Kong routes (#43385) 2026-04-01 15:42:36 +02:00
Andrey A. d6f10cae9f fix: adjust proxy configs for new api keys and auth (#43837) 2026-03-17 11:17:59 +01:00
Atharv Gaur edf51dfd98 fix(self-hosted): add hybrid JWT verification for edge functions docker template 2026-03-16 16:56:29 +01:00
Andrey A. 6190518640 add new opaque api keys and new auth to self-hosted 2026-03-16 12:00:10 +01:00
Andrey A. 997999779f add caddy and nginx configs for self-hosted 2026-03-03 14:04:35 +01:00
Inder Singh 97d9865ed4 feat(docker): add deno-cache volume and use Deno.serve 2026-02-18 18:34:34 +01:00
Inder Singh 3aef6f08b8 feat(self-hosted): update vector service and config 2026-02-16 14:10:47 +00:00
Andrey A. f24df26d7b fix: do not expose analytics by default 2026-02-16 13:23:16 +01:00
Etienne Stalmans a3d789f564 chore: updates to analytics route kong 2026-02-16 09:39:30 +01:00
Ivan Vasilov 6aa59ffe29 chore: Add volume to Studio container for SQL snippets (#41557)
* Add snippets volume.

* Bump the studio version.

* Add missing whitespace.
2026-01-27 10:34:57 +01:00
Andrey A. 878667cc2d fix: filter out realtime healtcheck logging and increase hc interval 2026-01-23 16:58:30 +00:00
Vaibhav cdc1a93eb0 fix: quote dashboard credentials in kong.yml to handle special characters 2026-01-23 17:49:35 +01:00
Tilman Vogel b2de1dbf5a fix(docker): vector.yml - do not set error_severity to null 2026-01-23 16:06:26 +00:00
CorwinRail 65fd868cfe fix: update realtime route for supabase-realtime (#39963)
- fixes issue with realtime logs not showing in studio
- appname changed to "realtime-dev.supabase-realitme"
2025-11-05 15:07:01 +01:00
Andrey A. ab2e1e8918 fix: restrict access to mcp server in self-hosted (#39849)
* add routes for local remote mcp
* add additional plugins to kong to restrict mcp
* prohibit access to /api/mcp and /mcp by default
* add comments to warn the user about local access only
2025-10-27 13:39:30 +01:00
Han Qiao 6026a824a3 fix: update queries for local edge function and cron logs (#39388) 2025-10-13 15:20:23 +08:00
Ziinc 671aea0a4a fix: use LOGFLARE_PRIVATE_ACCESS_TOKEN for querying, LOGFLARE_PUBLIC_… (#36169)
* fix: use LOGFLARE_PRIVATE_ACCESS_TOKEN for querying, LOGFLARE_PUBLIC_ACCESS_TOKEN for ingestion

* chore: prettier

* chore: remove logging

* chore: remove unused import
2025-06-05 14:52:29 +08:00
419eba99a1 fix(self-hosted): self hosted docker compose (#30674)
* fix(self-host): ensure migrations connect back to postgres database

* fix(self-host): use supabase_admin user for supavisor pooler

* fix(self-host): services healthchecks

* fix(self-host): vector config path

* feat(ci): add smoke test for self-hosted stack

---------

Co-authored-by: Shawal Mbalire <mbalireshawal@gmail.com>
Co-authored-by: Robson Martins <robson@controle.digital>
2024-11-28 11:37:08 +00:00
Andrew Valleteau 4bad8499ae feat: introduce _supabase database add supavisor to self-hosted (#29596)
* chore: move _analytics to a distinct database

Following: https://github.com/supabase/cli/pull/2707

BREAKING CHANGES:
When migrating from an older version you will need to manually create the new internal _supabase
database and analytics schema the same way the  and  do.
Via:

* feat: add supavisor to the self-hosted stack

* chore(docs): add docs about supavisor

* chore: fix reviewdog warning

* chore: fix typo

* chore: apply pr comments
2024-10-08 13:49:09 +02:00
Filipe CabaçoandRodrigo Mansueli 03aa5c3474 fix: Add Realtime API Routes (#23237)
Exposes the API routes for Realtime appropriately via Kong configuration.

Also alters the analytics configuration to avoid extra logs due to having only one analytics server instead of a cluster

Co-authored-by: Rodrigo Mansueli <rodrigo@mansueli.com>
2024-04-25 09:58:25 +01:00
Filipe Cabaço 88c6e29590 fix: Change vector to use LOGFLARE_API_KEY env var (#22860) 2024-04-22 16:37:24 +08:00
d1a38abccd fix(docker): Add JWT init script (#17033)
* Add JWT init script

* newline

---------

Co-authored-by: Ant Wilson <awalias@users.noreply.github.com>
Co-authored-by: Bobbie Soedirgo <bobbie@soedirgo.dev>
2023-11-15 15:41:32 +08:00
jm-bh 928d2b614c fix: fallible expression 2023-09-11 17:50:00 -05:00
Ziinc cf5e464306 Merge branch 'master' into fix/self-hosted-vector-postgres-log-level 2023-09-11 16:51:43 +08:00
Filipe Cabaço 5b364c2cb1 chore: Move logging into Docker logs only
Change the Vector ingestion to use docker logs directly from the docker socket instead of syslog via an open port
2023-09-02 23:29:09 +01:00
Ahmed El-Sharnoby b3114508d0 Dashboard default credentials substitution in kong.yml 2023-08-26 00:19:18 +03:00
TzeYiing bf7cc8f66b fix: add upcase to log level 2023-08-23 03:25:21 +08:00
TzeYiing 35a13a8c7a fix: update vector to set postgres logs to LOG instead of INFO 2023-08-23 03:16:10 +08:00
Qiao Han 39d0fd1235 fix: use dashboard path as catch all 2023-07-30 00:14:24 +08:00
Copple e9e89c12de minor cleanup 2023-07-28 16:12:27 +02:00
Copple f3a74537c5 Adding some sensible defaults 2023-07-28 14:22:19 +02:00
Copple 9ee7f87a42 Add basic auth using Kong. Since we now expose the dashboard using Kong, then we can disable the port on docker compose 2023-07-28 14:01:06 +02:00
Ahmed El-Sharnoby c44a81533b Add environment variables substitution for kong.yml 2023-07-24 08:28:04 +00:00
Copple 4712cf1f31 Revert "Add environment variables substitution for kong.yml" 2023-07-17 15:33:01 +02:00
Ahmed El-Sharnoby 59e3ea10e7 Add environment variables substitution for kong.yml 2023-07-05 13:08:53 +00:00