Commit Graph
95 Commits
Author SHA1 Message Date
Luiz Felipe Machado ff80bb1499 feat(self-hosted): function worker retries (#50618) 2026-09-30 13:15:41 +02:00
Luiz Felipe Machado 3fc8af387e feat(self-hosted): add function runtime errors (#50589) 2026-09-30 12:57:27 +02:00
Andrey A. c8b665caf2 feat(self-hosted): add api gateway logic for functions (#46810) 2026-09-30 11:14:47 +02:00
Naren 08fc3ec287 fix(self-hosted): grant supabase_functions_admin USAGE on extensions schema (#46526) 2026-09-23 11:05:00 +02:00
Vaibhav 1e444589c6 fix(self-hosted): standardize function auth responses (#48012) 2026-09-17 10:10:01 +02:00
Manuel Rubio e693f206f5 fix(self-hosted): remove expose of app.settings.jwt_secret (#45003) 2026-09-15 19:38:21 +02:00
Mandar Joshi 0a409db31c fix(self-hosted): proxy .well-known route for auth (#50306) 2026-09-15 19:01:59 +02:00
Siddharth Gaikwad 920459e9be fix(docker): ship volumes/storage so it is not created as root (#50299) 2026-09-15 18:50:00 +02:00
Raúl Barroso f5f897a29b feat(functions): inject env var function slug (#49617)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Feature (self-hosted Edge Functions)

## What is the current behavior?

The self-hosted Edge Functions router
(`docker/volumes/functions/main/index.ts`) doesn't tell a function which
slug a request resolved to. As a result, `@supabase/server`'s
`withOAuthProtectedResource` can't derive its canonical resource URL and
falls back to reconstructing it from the request path against the
internal `api-gw` origin, so the advertised OAuth Protected Resource is
/wrong for self-hosted deployments.

## What is the new behavior?

`main/index.ts` now injects `SUPABASE_FUNCTION_SLUG: service_name` per
request (after the `Deno.env.toObject()` snapshot, so nothing in the
container env can shadow it).

Combined with the operator's `SUPABASE_PUBLIC_URL`, the advertised
resource is the correct external
`{SUPABASE_PUBLIC_URL}/functions/v1/{slug}`, not the internal
`http://api-gw:8000`.

Verified on the docker stack: the slug is injected per-function, the
resource origin resolves to `SUPABASE_PUBLIC_URL`, and the `401`
`www-authenticate` carries the right `resource_metadata`.

## Additional context

Fixes AI-1128

Companion to `@supabase/server` [PR
#117](https://github.com/supabase/server/pull/117) and the [CLI slug
injection](https://github.com/supabase/cli/pull/6345)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Edge workers now receive the correct function slug in their runtime
environment, improving per-function request handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-28 12:32:30 +02:00
Etienne Stalmans 04ddc6bef8 chore: update cors for pg routes (#49136)
## I have read the
[CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md)
file.

YES

## What kind of change does this PR introduce?

Bug fix - config hardening

## What is the current behavior?

CORS is applied at the global level in a permissive mode

## What is the new behavior?

Self-hosted envoy config should apply CORS to the `/pg` routes. These
should only be called from the studio dashboard (when called via a
browser).

uses `SUPABASE_PUBLIC_URL`, which should mean this isn't a breaking
change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Security & Access**
  * Added stricter CORS controls for the `/pg/` route.
* Requests are limited to the configured public URL and localhost
origins.
* Standard HTTP methods and headers are supported, with preflight
responses cached for one hour.

* **Documentation**
* Updated self-hosting guidance to describe the `/pg/` route’s CORS
policy.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-08-17 10:28:09 -07:00
9ef9f1b8c1 feat(self-host): use @supabase/server in functions template and docs (#48996)
Updates the self-host Edge Functions template to use `@supabase/server`,
matching the CLI's `supabase functions new` templates (part of SDK-1150,
follows up on #45635 which exposed `SUPABASE_JWKS` to the functions
container). The `hello` example function now wraps its handler in
`withSupabase({ auth: 'none' })` and resolves the package through a
per-function `deno.json` import map, which the runtime auto-discovers,
so no dispatcher changes are needed. The self-hosted functions guide is
updated to match: the create-a-function snippet, a `ctx.supabaseAdmin`
example replacing the manual esm.sh `createClient` wiring, and a note
that `auth: 'user'` requires `SUPABASE_JWKS`. Verified on
`supabase/edge-runtime:v1.74.0` with the compose environment variables:
`curl /functions/v1/hello` returns the same response body as before, so
existing docs and troubleshooting pages stay accurate.

The `docker/.gitignore` change: `volumes/functions/**` ignores
self-hosters' own functions, but it also hid the new `deno.json`, which
must ship with the repo for the `hello` import to resolve. The allowlist
entries follow the existing `main/index.ts` pattern.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Edge Functions now support authenticated invocation with publishable
or secret API keys.
* Function handlers can access authenticated and administrative Supabase
clients through the request context.
* Added automatic environment configuration and JWT verification
support.

* **Documentation**
* Updated the self-hosting guide with the new function setup and
authentication workflow.
* Improved local function examples for supported access patterns and
privileged operations.

* **Tests**
* Updated self-hosted smoke tests to validate publishable-key function
access.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Kalleby Santos <kalleby_santos@hotmail.com>
Co-authored-by: Kalleby Santos <105971119+kallebysantos@users.noreply.github.com>
2026-08-14 12:00:11 +03:00
Andrey A. 5a8eecf509 feat(self-hosted): envoy is the default api gateway (#48153) 2026-08-11 11:55:26 +02:00
Andrey A. 18bad2e61c chore(self-hosted): remove em-dashes (#48498) 2026-07-30 17:20:22 +00:00
Kalleby Santos 9cf6ae1f67 feat(self-host): functions expose jwks (#45635) 2026-07-08 15:32:12 +02:00
Luiz Felipe Machado 9777f051d6 feat(self-hosted): restrict rest root anon (#45462) 2026-07-07 13:16:23 +02:00
Andrey A. e7abda8dce fix(self-hosted): change default api external url to contain /auth/v1 (#47640) 2026-07-07 12:28:47 +02:00
Inder Singh 5d8d1f359f chore(self-hosted): use /bin/sh shebang in kong-entrypoint.sh (#46897) 2026-06-13 10:30:39 +00:00
Andrey A. 098157eb90 fix(self-hosted): block access to tenants and openapi realtime api (#46856) 2026-06-12 11:48:58 +02:00
Luiz Felipe Machado 94ac6f3fa3 fix(self-hosted): reject access via internal jwt api keys when translation is enabled (#46023) 2026-05-26 17:03:13 +02:00
Sonu Yadav 1f28a37569 fix(self-hosted): allow configuring supavisor tenant db_host via env var (#41273) 2026-05-14 22:54:20 +02:00
Luiz Felipe Machado 5fa012cfa9 docs(self-hosted): clarify envoy api gateway setup (#45238) 2026-04-29 09:33:53 +00:00
Luiz Felipe Machado 53060160aa fix(self-hosted): api key translation should depend on the sb_ keys present (#45195) 2026-04-24 12:17:50 +02:00
Luiz Felipe Machado e080513666 feat: add Envoy API gateway for self-hosted Docker Compose (#43838) 2026-04-22 11:20:32 +02:00
Andrey A. b34d8e6609 add routes for saml sso to self-hosted proxy configs (#44440) 2026-04-01 18:18:50 +02:00
Luiz Felipe Machado f128106801 feat(self-hosting): add SAML SSO env config and open Kong routes (#43385) 2026-04-01 15:42:36 +02:00
Andrey A. d6f10cae9f fix: adjust proxy configs for new api keys and auth (#43837) 2026-03-17 11:17:59 +01:00
Atharv Gaur edf51dfd98 fix(self-hosted): add hybrid JWT verification for edge functions docker template 2026-03-16 16:56:29 +01:00
Andrey A. 6190518640 add new opaque api keys and new auth to self-hosted 2026-03-16 12:00:10 +01:00
Andrey A. 997999779f add caddy and nginx configs for self-hosted 2026-03-03 14:04:35 +01:00
Inder Singh 97d9865ed4 feat(docker): add deno-cache volume and use Deno.serve 2026-02-18 18:34:34 +01:00
Inder Singh 3aef6f08b8 feat(self-hosted): update vector service and config 2026-02-16 14:10:47 +00:00
Andrey A. f24df26d7b fix: do not expose analytics by default 2026-02-16 13:23:16 +01:00
Etienne Stalmans a3d789f564 chore: updates to analytics route kong 2026-02-16 09:39:30 +01:00
Ivan Vasilov 6aa59ffe29 chore: Add volume to Studio container for SQL snippets (#41557)
* Add snippets volume.

* Bump the studio version.

* Add missing whitespace.
2026-01-27 10:34:57 +01:00
Andrey A. 878667cc2d fix: filter out realtime healtcheck logging and increase hc interval 2026-01-23 16:58:30 +00:00
Vaibhav cdc1a93eb0 fix: quote dashboard credentials in kong.yml to handle special characters 2026-01-23 17:49:35 +01:00
Tilman Vogel b2de1dbf5a fix(docker): vector.yml - do not set error_severity to null 2026-01-23 16:06:26 +00:00
CorwinRail 65fd868cfe fix: update realtime route for supabase-realtime (#39963)
- fixes issue with realtime logs not showing in studio
- appname changed to "realtime-dev.supabase-realitme"
2025-11-05 15:07:01 +01:00
Andrey A. ab2e1e8918 fix: restrict access to mcp server in self-hosted (#39849)
* add routes for local remote mcp
* add additional plugins to kong to restrict mcp
* prohibit access to /api/mcp and /mcp by default
* add comments to warn the user about local access only
2025-10-27 13:39:30 +01:00
Han Qiao 6026a824a3 fix: update queries for local edge function and cron logs (#39388) 2025-10-13 15:20:23 +08:00
Ziinc 671aea0a4a fix: use LOGFLARE_PRIVATE_ACCESS_TOKEN for querying, LOGFLARE_PUBLIC_… (#36169)
* fix: use LOGFLARE_PRIVATE_ACCESS_TOKEN for querying, LOGFLARE_PUBLIC_ACCESS_TOKEN for ingestion

* chore: prettier

* chore: remove logging

* chore: remove unused import
2025-06-05 14:52:29 +08:00
419eba99a1 fix(self-hosted): self hosted docker compose (#30674)
* fix(self-host): ensure migrations connect back to postgres database

* fix(self-host): use supabase_admin user for supavisor pooler

* fix(self-host): services healthchecks

* fix(self-host): vector config path

* feat(ci): add smoke test for self-hosted stack

---------

Co-authored-by: Shawal Mbalire <mbalireshawal@gmail.com>
Co-authored-by: Robson Martins <robson@controle.digital>
2024-11-28 11:37:08 +00:00
Andrew Valleteau 4bad8499ae feat: introduce _supabase database add supavisor to self-hosted (#29596)
* chore: move _analytics to a distinct database

Following: https://github.com/supabase/cli/pull/2707

BREAKING CHANGES:
When migrating from an older version you will need to manually create the new internal _supabase
database and analytics schema the same way the  and  do.
Via:

* feat: add supavisor to the self-hosted stack

* chore(docs): add docs about supavisor

* chore: fix reviewdog warning

* chore: fix typo

* chore: apply pr comments
2024-10-08 13:49:09 +02:00
Filipe CabaçoandRodrigo Mansueli 03aa5c3474 fix: Add Realtime API Routes (#23237)
Exposes the API routes for Realtime appropriately via Kong configuration.

Also alters the analytics configuration to avoid extra logs due to having only one analytics server instead of a cluster

Co-authored-by: Rodrigo Mansueli <rodrigo@mansueli.com>
2024-04-25 09:58:25 +01:00
Filipe Cabaço 88c6e29590 fix: Change vector to use LOGFLARE_API_KEY env var (#22860) 2024-04-22 16:37:24 +08:00
d1a38abccd fix(docker): Add JWT init script (#17033)
* Add JWT init script

* newline

---------

Co-authored-by: Ant Wilson <awalias@users.noreply.github.com>
Co-authored-by: Bobbie Soedirgo <bobbie@soedirgo.dev>
2023-11-15 15:41:32 +08:00
jm-bh 928d2b614c fix: fallible expression 2023-09-11 17:50:00 -05:00
Ziinc cf5e464306 Merge branch 'master' into fix/self-hosted-vector-postgres-log-level 2023-09-11 16:51:43 +08:00
Filipe Cabaço 5b364c2cb1 chore: Move logging into Docker logs only
Change the Vector ingestion to use docker logs directly from the docker socket instead of syslog via an open port
2023-09-02 23:29:09 +01:00
Ahmed El-Sharnoby b3114508d0 Dashboard default credentials substitution in kong.yml 2023-08-26 00:19:18 +03:00