mirror of
https://github.com/supabase/supabase.git
synced 2026-10-05 09:25:06 +03:00
The Managing secrets guide is the only place that tells you where a local secret has to sit for the Edge Function runtime to load it. Neither the supabase agent skill nor Supacademy covers it. The page named supabase/functions/.env once, in prose, and never had the reader create it. The eval in supabase/evals#285 reproduces what that produces: across three runs on codex-gpt-5.6-luna-no-skills, every run built a function reading its key from the environment, started the stack, and answered missing_api_key. Two of the three wrote supabase/functions/.env.example and stopped, which is a template with the variable name in it rather than the file the runtime reads. Local secrets is now a five-step procedure that creates the file with a working value, ignores it, creates the function that reads the key, starts the stack, and calls the function to confirm. That last step is the one that tells the reader whether it worked. The function is created before the stack starts, so a reader following the steps literally from a fresh project has something to call. The gitignore instruction moved out of its admonition and into step 2, carrying its consequence with it. It's an instruction the reader has to follow, so it belongs in the procedure rather than beside it. Recovery for a variable the function can't see gets its own section rather than trailing the procedure. "I set it and the function cannot read it" is the most repeated shape in the feedback on this page, and as loose sentences mid-section it had no entry in the table of contents.