mirror of
https://github.com/supabase/supabase.git
synced 2026-10-11 04:15:04 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## Problem The Docs E2E link checker found broken links throughout docs, starting with `phone-login.mdx` pointing to `/docs/guides/cli/config` (404). Old links like `/docs/guides/cli/config` still work on the live site because `supabase.com` has redirects set up for them, but these links break on the docs preview site, which is what the E2E check tests against. These issues look clean on the live site, and I didn't catch them in my first pass because I was testing production instead of the preview. The E2E check only tests the ~20 pages a given PR happens to touch, so fixing the pages it flagged kept exposing more of the same problem one page at a time as each fix pulled in a new file. To stop chasing this incrementally, I cross-referenced every `/docs/guides/*` and `/docs/reference/*` redirect source in `apps/www/lib/redirects.js` against actual usage across all of `apps/docs`, and verified each candidate against the live preview. ## Solution Rather than updating the Docs E2E link checker, this PR resolves the links. **Why:** we own these docs, so keeping the links clean without redirects is keeping the house maintained. See [Broken Window Theory](https://blog.codinghorror.com/the-broken-window-theory/). Updated every link still using an old path to point straight at the current page instead of relying on a redirect. This covers old links like: - `/docs/guides/cli/config` → `/docs/guides/local-development/cli/config` - `/docs/guides/cli/getting-started` → `/docs/guides/local-development/cli/getting-started` - `/docs/guides/cli/local-development` → `/docs/guides/local-development/database-migrations` - `/docs/guides/cli/managing-environments` → `/docs/guides/deployment/managing-environments` - `/docs/guides/cli/seeding-your-database` → `/docs/guides/local-development/seeding-your-database` - bare `/docs/guides/cli` → `/docs/guides/local-development` - `/docs/guides/platform/compute-add-ons` → `/docs/guides/platform/compute-and-disk` - `/docs/guides/platform/shared-responsibility-model` → `/docs/guides/deployment/shared-responsibility-model` - `/docs/guides/database` → `/docs/guides/database/overview` - `/docs/reference/javascript`, `/docs/reference/dart`, `/docs/reference/kotlin`, `/docs/reference/python`, `/docs/reference/csharp` → their `/introduction` pages (the redirect's own destination, `/start`, turned out to be dead even on production — a separate bug in `redirects.js` I didn't touch here) - and about 35 more of the same pattern, listed in the commit messages Also fixed a handful of dead heading anchors found along the way (links that resolve to the right page but point at a `#section` that got renamed or moved), including the original `#bigquery` anchor and a few in `connecting-to-postgres.mdx` where content moved to its own dedicated page. Left alone on purpose: - `content/guides/cli.mdx` — this page has no route in the docs app at all (no `app/guides/cli/` directory), so it 404s even in production before the `www` redirect ever fires. Fixing its internal link wouldn't change that; it needs an actual routing/content decision, not a link fix. - A few candidates that already resolve fine as-is (`pg_partman`, bare `/docs/reference/api`, bare `/docs/reference/cli`) — confirmed via curl, left untouched. ## Manual testing 1. Confirmed every new link target actually exists by checking the destination file/page and matching heading anchors. 2. Cross-referenced every `/docs/guides/*` and `/docs/reference/*` redirect source in `apps/www/lib/redirects.js` against real usage in `apps/docs`, and curl-verified each old path (404) and new path (200) against the live PR preview before fixing it. 3. Ran the Docs E2E link checker locally against changed pages. 4. Spot-checked the original broken link from CI (`/docs/guides/cli/config`) to confirm it now points to a working page.
128 lines
6.1 KiB
Plaintext
128 lines
6.1 KiB
Plaintext
---
|
|
title: 'Postgres SSL Enforcement'
|
|
description: 'Enforce SSL usage for all Postgres connections'
|
|
---
|
|
|
|
Your Supabase project supports connecting to the Postgres DB without SSL enabled to maximize client compatibility. For increased security, you can prevent clients from connecting if they're not using SSL.
|
|
|
|
Disabling SSL enforcement only applies to connections to Postgres, Supavisor (shared Connection Pooler) and PgBouncer (dedicated Connection Pooler); all HTTP APIs offered by Supabase (e.g., PostgREST, Storage, Auth) automatically enforce SSL on all incoming connections.
|
|
|
|
<Admonition type="caution">
|
|
|
|
Applying or updating SSL enforcement triggers a fast database reboot. On small projects this usually completes in a few seconds, but larger databases may see a longer interruption.
|
|
|
|
</Admonition>
|
|
|
|
## Manage SSL enforcement via the dashboard
|
|
|
|
SSL enforcement can be configured via the "Enforce SSL on incoming connections" setting under the SSL Configuration section in [Database Settings page](/dashboard/project/_/database/settings) of the dashboard.
|
|
|
|
<Admonition type="note">
|
|
|
|
Updating SSL enforcement requires a brief database reboot. This restarts only the database and involves a few minutes of downtime.
|
|
|
|
</Admonition>
|
|
|
|
## Manage SSL enforcement via the Management API
|
|
|
|
You can also manage SSL enforcement using the Management API:
|
|
|
|
```bash
|
|
# Get your access token from https://supabase.com/dashboard/account/tokens
|
|
export SUPABASE_ACCESS_TOKEN="your-access-token"
|
|
export PROJECT_REF="your-project-ref"
|
|
|
|
# Get current SSL enforcement status
|
|
curl -X GET "https://api.supabase.com/v1/projects/$PROJECT_REF/ssl-enforcement" \
|
|
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN"
|
|
|
|
# Enable SSL enforcement
|
|
curl -X PUT "https://api.supabase.com/v1/projects/$PROJECT_REF/ssl-enforcement" \
|
|
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{
|
|
"requestedConfig": {
|
|
"database": true
|
|
}
|
|
}'
|
|
|
|
# Disable SSL enforcement
|
|
curl -X PUT "https://api.supabase.com/v1/projects/$PROJECT_REF/ssl-enforcement" \
|
|
-H "Authorization: Bearer $SUPABASE_ACCESS_TOKEN" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{
|
|
"requestedConfig": {
|
|
"database": false
|
|
}
|
|
}'
|
|
```
|
|
|
|
## Manage SSL enforcement via the CLI
|
|
|
|
To get started:
|
|
|
|
1. [Install](/docs/guides/local-development) the Supabase CLI 1.37.0+.
|
|
1. [Log in](/docs/guides/local-development/database-migrations#log-in-to-the-supabase-cli) to your Supabase account using the CLI.
|
|
1. Ensure that you have [Owner or Admin permissions](/docs/guides/platform/access-control#manage-team-members) for the project that you are enabling SSL enforcement.
|
|
|
|
### Check enforcement status
|
|
|
|
You can use the `get` subcommand of the CLI to check whether SSL is currently being enforced:
|
|
|
|
```bash
|
|
supabase ssl-enforcement get --project-ref {ref} --experimental
|
|
```
|
|
|
|
Response if SSL is being enforced:
|
|
|
|
```bash
|
|
SSL is being enforced.
|
|
```
|
|
|
|
Response if SSL is not being enforced:
|
|
|
|
```bash
|
|
SSL is *NOT* being enforced.
|
|
```
|
|
|
|
### Update enforcement
|
|
|
|
The `update` subcommand is used to change the SSL enforcement status for your project:
|
|
|
|
```bash
|
|
supabase ssl-enforcement update --project-ref {ref} --enable-db-ssl-enforcement --experimental
|
|
```
|
|
|
|
Similarly, to disable SSL enforcement:
|
|
|
|
```bash
|
|
supabase ssl-enforcement update --project-ref {ref} --disable-db-ssl-enforcement --experimental
|
|
```
|
|
|
|
### A note about Postgres SSL modes
|
|
|
|
Postgres supports [multiple SSL modes](https://www.postgresql.org/docs/current/libpq-ssl.html#LIBPQ-SSL-PROTECTION) on the client side. These modes provide different levels of protection. Depending on your needs, it is important to verify that the SSL mode in use is performing the required level of enforcement and verification of SSL connections.
|
|
|
|
| SSL Mode | Encryption | Verifies CA | Verifies Hostname | Description |
|
|
| ------------- | ---------- | ----------- | ----------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
|
|
| `disable` | No | No | No | SSL is not used. All data is transmitted in plaintext. |
|
|
| `allow` | Optional | No | No | Tries a non-SSL connection first; falls back to SSL if the server requires it. |
|
|
| `prefer` | Optional | No | No | Tries an SSL connection first; falls back to non-SSL if the server doesn't support it. This is the default. |
|
|
| `require` | Yes | No | No | Always uses SSL, but does not verify the server certificate or hostname. |
|
|
| `verify-ca` | Yes | Yes | No | Uses SSL and verifies that the server certificate is signed by a trusted CA. |
|
|
| `verify-full` | Yes | Yes | Yes | Uses SSL, verifies the CA certificate, and confirms the hostname matches the certificate. Recommended when SSL enforcement is enabled. |
|
|
|
|
The strongest mode offered by Postgres is `verify-full` and this is the mode you most likely want to use when SSL enforcement is enabled. To use `verify-full` you will need to download the Supabase CA certificate for your database. The certificate is available through the dashboard under the SSL Configuration section in the [Database Settings page](/dashboard/project/_/database/settings).
|
|
|
|
Once the CA certificate has been downloaded, add it to the certificate authority list used by Postgres.
|
|
|
|
```bash
|
|
cat {location of downloaded prod-ca-2021.crt} >> ~/.postgres/root.crt
|
|
```
|
|
|
|
With the CA certificate added to the trusted certificate authorities list, use `psql` or your client library to connect to Supabase:
|
|
|
|
```bash
|
|
psql "postgresql://aws-0-eu-central-1.pooler.supabase.com:6543/postgres?sslmode=verify-full" -U postgres.<user>
|
|
```
|