## Problem
PR #50638 migrates API Gateway and Data API reports to OTEL, but the
shared Auth and Realtime metrics still select legacy BigQuery SQL and
the `logs.all` endpoint.
## Fix
Route all active hosted shared API reports through the existing OTEL
builders after feature flags load. Remove unused report variants and
their source-selection abstraction while preserving the legacy BigQuery
path for self-hosted Studio.
This PR is stacked on #50638.
## How to test
- Open the Auth observability report and confirm its seven shared metric
requests use `logs.all.otel` with a `/auth` request-path filter.
- Open the Realtime observability report and confirm its seven shared
metric requests use `logs.all.otel` with a `/realtime` request-path
filter.
- Open the Data API report and confirm its existing OTEL behavior
remains unchanged with a `/rest` request-path filter.
- Expected result: hosted reports wait for ConfigCat before querying,
while self-hosted Studio continues using the legacy BigQuery path.
- Run `./apps/studio/node_modules/.bin/vitest --run
apps/studio/components/interfaces/Reports/Reports.constants.otel.test.ts
--config apps/studio/vitest.config.ts`.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **Changes**
- Shared API reports now support filtering by Auth, Realtime, and
PostgREST traffic.
- Filters for Storage, GraphQL, Functions, and other previously
supported traffic types are no longer available.
- Report queries now consistently use edge log data, improving
consistency across request totals, routes, errors, response times, and
network traffic metrics.
- OpenTelemetry-backed reporting is now enabled consistently across
supported report types where available.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
The API Gateway and Data API observability reports still send legacy
BigQuery SQL to the logs.all endpoint. The Data API shared-report hook
also hardcodes logs.all, so the otelReports flag cannot move that report
to ClickHouse.
## Fix
- Add the ClickHouse requests-by-country query needed by API Gateway.
- Select API Gateway SQL and endpoint atomically from otelReports.
- Route the Data API PostgREST report through the existing tested OTEL
API query builders and logs.all.otel.
- Wait for ConfigCat before the Data API sends a request, avoiding an
initial legacy request while the flag loads.
- Keep logs.all behavior when the flag is disabled and leave other
shared reports unchanged.
## How to test
1. Enable otelReports and open API Gateway, then confirm its report
requests use logs.all.otel.
2. Open Data API and confirm all report requests use logs.all.otel with
a request.path filter for /rest.
3. Change the date range, add a filter, and refresh each report.
4. Disable otelReports and confirm both reports use logs.all.
All OTEL query shapes were tested individually against logs.all.otel.
The focused query suite and lint pass locally.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
- **New Features**
- API reports can use OpenTelemetry data when enabled.
- Added country-level request reporting, excluding requests without
country information.
- Added OpenTelemetry-backed PostgREST reports and Storage cache
hit/miss metrics.
- **Improvements**
- Reports wait for required configuration before loading data.
- Refreshing reports consistently refetches active metrics.
- Improved error handling for analytics query failures.
- Improved report accuracy with numeric time buckets and more precise
attribute filtering.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## Problem
The Network Traffic egress chart is derived from request logs and can
substantially undercount billed traffic. Showing it beside diagnostic
ingress data left customers with an untrustworthy egress number.
## Fix
Remove the log-derived egress chart, retain ingress, and add a Billable
egress callout that links to the selected organization’s Usage page. The
callout is shown only on hosted Studio, where organization billing data
is available.
## How to test
- Open API, Storage, Auth, or PostgREST observability.
- Confirm Network Traffic shows only the ingress chart.
- Confirm the Billable egress callout links to the organization Usage
page’s egress section.
- Expected result: diagnostic traffic and billable usage are no longer
presented as competing egress totals.
- Automated checks: git diff --check and final code review passed.
Focused lint could not run because missing dependencies require registry
access, and DNS for registry.npmjs.org is unavailable.
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Updates**
* Clarified Network Traffic report tooltips to explain that ingress is
measured from request logs.
* Platform deployment reports now display ingress data only; egress
charts are no longer shown.
* Added a notice linking to the Usage page for billable egress details.
* Applied the updated Network Traffic explanation consistently across
API overview, storage, and shared report views.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Refactor (naming consistency cleanup).
## What is the current behavior?
`ReportQueryLogs` exposed its SQL builder under a `sql:` field while
`ReportQueryDb` used `safeSql:`. Both already returned branded fragments
(`SafeLogSqlFragment` / `SafeSqlFragment`), so should consolidate on
`safeSql`.
## What is the new behavior?
Renames `sql:` → `safeSql:` on `ReportQueryLogs` so the two report-query
shapes use the same field name. Updates every Logs preset under
`PRESET_CONFIG[API|STORAGE]`, every entry and call site in
`SharedAPIReport.constants.ts`, and `getLogsSql` in `Reports.utils.tsx`.
Part of the analytics SQL safety series; PRs 10 (remaining analytics
callers) and 11 (ESLint rules) still to follow.
## Additional context
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit
* **Refactor**
* Enhanced query handling across API analytics reports (requests, top
routes, errors, performance metrics) and Storage analytics reports
(cache metrics) for improved consistency in query processing.
<!-- review_stack_entry_start -->
[](https://app.coderabbit.ai/change-stack/supabase/supabase/pull/46469?utm_source=github_walkthrough&utm_medium=github&utm_campaign=change_stack)
<!-- review_stack_entry_end -->
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.
YES
## What kind of change does this PR introduce?
Security / refactor — migrates `SharedAPIReport.constants.ts` to the
proven-authorship model (`SafeLogSqlFragment`).
## What is the current behavior?
All seven SQL builders in `SHARED_API_REPORT_SQL` return plain `string`
and interpolate filter values via `generateRegexpWhere`, which performs
manual quoting without sanitization. The source table name (`edge_logs`
/ `function_edge_logs`) is also interpolated as a raw string. Queries
are executed via a local `fetchLogs` function that calls `get()`
directly, bypassing the `executeAnalyticsSql` wire boundary.
## What is the new behavior?
- Each SQL builder is rewritten with the `safeLogSql` template tag and
returns `SafeLogSqlFragment`.
- Filter keys route through `quotedIdent` (predicates with invalid
identifiers are dropped); values route through `analyticsLiteral`
(single quotes and backslashes are escaped).
- A `SOURCE_TABLE` branded map covers the two possible source tables;
`sourceTable()` looks up the branded fragment instead of interpolating a
raw string.
- `fetchLogs` is removed; `useQueries` calls `executeAnalyticsSql`
directly with `method: 'get'`, routing through the shared wire boundary.
- The `queryFn` wraps the call in a try/catch that also checks
`data?.error`, preserving the original Sentry capture behaviour
(`'Shared API Report Error'`) for both network and API-level errors.
## Additional context
* rm assertion
* rm old button
* refetch on filterBy change
* pass sql to metrics for link
* pass sql to auth report
* pass sql to postgrest report
* pass sql to realtime report
* fix type errs
* add postgrest report
* fix type
* fix layout border top
* fix refreshes
* fix up loading state, title, telemetry src
* add shared api report filters, make headers look the same
* fix auth
* consolidate shared api hooks
* fix name