mirror of
https://github.com/supabase/supabase.git
synced 2026-10-06 01:45:10 +03:00
246 lines
9.2 KiB
Plaintext
246 lines
9.2 KiB
Plaintext
---
|
|
id: self-hosting
|
|
title: Self Hosting
|
|
description: How to use configure and deploy Supabase.
|
|
---
|
|
|
|
Supabase is a [Hosted Platform](https://app.supabase.io), so you don't _have_ to deploy it yourself.
|
|
However, if you want to configure and deploy it yourself, that's also possible.
|
|
|
|

|
|
|
|
## Before you begin
|
|
|
|
The self-hosted version of Supabase does not include a UI yet.
|
|
We are working on this in stages, starting with our [UI library](https://github.com/supabase/ui) and with a [WIP PR here](https://github.com/supabase/supabase/pull/2281).
|
|
[[more context](https://github.com/supabase/supabase/discussions/1001#discussioncomment-558696)]
|
|
|
|
In the meantime, here are some suggestions for working with your Postgres Database:
|
|
|
|
- `pgadmin`: https://www.pgadmin.org
|
|
- `dbeaver`: https://dbeaver.com
|
|
- `BeeKeeper`: https://beekeeperstudio.io
|
|
- `HeidiSQL`: https://heidisql.com
|
|
- `Table Plus`: https://www.tableplus.io
|
|
|
|
## Get the Docker Compose
|
|
|
|
We provide a Docker Compose directory which is includes all of the tools required for building on top of Supabase.
|
|
|
|
Download the Docker files:
|
|
|
|
```bash
|
|
# 1. Copy an empty repo
|
|
git clone https://github.com/supabase/supabase
|
|
|
|
# 2. Move into the empty repo
|
|
cd supabase/docker
|
|
```
|
|
|
|
## Running Locally
|
|
|
|
Now that you have the Docker set up on your local machine, you can start it here by running
|
|
|
|
```bash
|
|
docker-compose up
|
|
```
|
|
|
|
## Deploying
|
|
|
|
### Configuring each service
|
|
|
|
Supabase is made up of several services. We have prefilled the `docker-compose` file with all the configuration you need to get started.
|
|
If you would like to change any of the configuration, you can update the env variables in the `docker-compose` file.
|
|
|
|
Here are a list of environment variables for each service:
|
|
|
|
- [Postgres](https://hub.docker.com/_/postgres/)
|
|
- [PostgREST](https://postgrest.org/en/v7.0.0/configuration.html)
|
|
- [Realtime](https://github.com/supabase/realtime#server-set-up)
|
|
- [GoTrue](https://github.com/supabase/gotrue)
|
|
- [Storage](https://github.com/supabase/storage-api)
|
|
- [Kong](https://docs.konghq.com/install/docker/)
|
|
|
|
### Update secrets
|
|
|
|
If you are deploying to production, you should update the default [passwords and secrets](https://github.com/supabase/supabase/blob/master/docker/.env).
|
|
|
|
### Update API keys
|
|
|
|
All config for the API Gateway is stored in the `kong` directory. Inside `kong.yml` you'll find the routing for all services, the routing rules,
|
|
and down the bottom you'll find the JWTs capable of accessing services that require API Key access.
|
|
|
|
See the full docs [here](https://docs.konghq.com/hub/kong-inc/key-auth/).
|
|
|
|
If you are deploying to production, you should encode a new `anon` and `service_role` API key and update
|
|
them [here](https://github.com/supabase/supabase/blob/b1e99d2ce1f63ba728230fb53a6de444f60bce1f/docker/dockerfiles/kong/kong.yml#L42).
|
|
|
|
After you have regenerated the JWT secret in the step above, use a JWT generator (for example, using [jsonwebtoken.io](https://www.jsonwebtoken.io/)) to regenerate the API Keys using the payloads below:
|
|
|
|
|
|
```bash
|
|
# anon Payload:
|
|
{
|
|
"iss": "supabase",
|
|
"iat": 1603968834,
|
|
"exp": 2550653634,
|
|
"aud": "",
|
|
"sub": "",
|
|
"role": "anon"
|
|
}
|
|
# service_role Payload:
|
|
{
|
|
"iss": "supabase",
|
|
"iat": 1603968834,
|
|
"exp": 2550653634,
|
|
"aud": "",
|
|
"sub": "",
|
|
"role": "service_role"
|
|
}
|
|
```
|
|
|
|
### Configuring email
|
|
|
|
GoTrue requires an SMTP server to send emails for all authentication actions.
|
|
You will need to provide the following [settings](https://github.com/supabase/gotrue#e-mail) inside the `.env` file [here](https://github.com/supabase/supabase/blob/027e7f7b97bbe7365db4f7f46abe480e05841006/docker/.env#L8).
|
|
|
|
|
|
### Deploying
|
|
|
|
See the following guides to deploy Docker Compose setup using your preferred tool and platform:
|
|
|
|
- [AWS with Docker Machine](https://docs.docker.com/machine/get-started-cloud/#amazon-web-services-aws)
|
|
- [Digital Ocean with Docker Machine](https://docs.docker.com/machine/get-started-cloud/#digitalocean)
|
|
- [Docker Swarm](https://docs.docker.com/engine/swarm/stack-deploy/)
|
|
- [AWS Fargate](https://aws.amazon.com/blogs/containers/deploy-applications-on-amazon-ecs-using-docker-compose/)
|
|
- [Using Kompose for Kubernetes](https://kubernetes.io/docs/tasks/configure-pod-container/translate-compose-kubernetes/)
|
|
|
|
|
|
### Example environment variable configuration
|
|
|
|
The default environment variable configuration for most services should be sufficient. The default GoTrue config may not support all the settings you require to get up and running.
|
|
|
|
For brevity, here is an example of what the environment variables for the auth / GoTrue container might look like once the service is deployed:
|
|
|
|
```sh
|
|
GOTRUE_OPERATOR_TOKEN=your-super-secret-operator-token
|
|
GOTRUE_JWT_DEFAULT_GROUP_NAME=authenticated
|
|
|
|
# Make sure this JWT secret matches what was configured during setup
|
|
GOTRUE_JWT_SECRET=your-super-secret-jwt-token-with-at-least-32-characters-long
|
|
|
|
# How long should JWT tokens be valid for?
|
|
GOTRUE_JWT_EXP=3600
|
|
|
|
# Since Supabase is based on Postgres, you shouldn't need to change this
|
|
GOTRUE_DB_DRIVER=postgres
|
|
|
|
# What schema should requests be routed to?
|
|
# There should be no reason to change this
|
|
DB_NAMESPACE=auth
|
|
|
|
# Where is our auth/GoTrue located
|
|
# You shouldn't need to change these unless the ports are mapped differently
|
|
GOTRUE_API_HOST=0.0.0.0
|
|
PORT=9999
|
|
|
|
# Email settings
|
|
# You must set these if you want to be able to send emails
|
|
GOTRUE_SMTP_HOST=smtp.your-email-host.com
|
|
GOTRUE_SMTP_PORT=465
|
|
GOTRUE_SMTP_USER=your-smtp-user
|
|
GOTRUE_SMTP_PASS=your-smtp-password
|
|
|
|
# Should users be required to confirm their email address before they can log in?
|
|
# If set to false, users won't have to confirm their registration
|
|
# If set to true, users will have to click the link in their email to confirm
|
|
GOTRUE_MAILER_AUTOCONFIRM=false
|
|
|
|
# What is the 'from' address that emails are sent from?
|
|
GOTRUE_SMTP_ADMIN_EMAIL=noreply@example.com
|
|
|
|
# Remove this if you don't want debug logs
|
|
GOTRUE_LOG_LEVEL=debug
|
|
|
|
# The connection string for your database
|
|
# `@db` says we're looking for the container called 'db' on our docker network
|
|
DATABASE_URL=postgres://postgres:your-super-secret-and-long-postgres-password@db:5432/postgres
|
|
|
|
# Email templates
|
|
# Invite user - provide a URL to a HTML or Text template
|
|
GOTRUE_MAILER_TEMPLATES_INVITE=https://example.com/path/to/your/invite/template.html
|
|
|
|
# Confirm registration - provide a URL to a HTML or Text template
|
|
GOTRUE_MAILER_TEMPLATES_CONFIRMATION=https://example.com/path/to/your/confirmation/template.html
|
|
|
|
# Password recovery - provide a URL to a HTML or Text template
|
|
GOTRUE_MAILER_TEMPLATES_RECOVERY=https://example.com/path/to/your/password_reset/template.HTML
|
|
|
|
# Magic link - provide a URL to a HTML or Text template
|
|
GOTRUE_MAILER_TEMPLATES_MAGIC_LINK=https://example.com/path/to/your/magic_link/template.html
|
|
|
|
# GoTrue URLs
|
|
# These are appended after the API_EXTERNAL_URL
|
|
# You shouldn't need to change these
|
|
GOTRUE_MAILER_URLPATHS_CONFIRMATION=/auth/v1/verify
|
|
GOTRUE_MAILER_URLPATHS_INVITE=/auth/v1/verify
|
|
GOTRUE_MAILER_URLPATHS_CONFIRMATION=/auth/v1/verify
|
|
GOTRUE_MAILER_URLPATHS_RECOVERY=/auth/v1/verify
|
|
|
|
# Site URLs
|
|
# This is where the user will be redirected to after clicking a link in an email and after oAuth
|
|
GOTRUE_SITE_URL=https://example.com/redirect_to_here
|
|
GOTRUE_URI_ALLOW_LIST=https://example.com/redirect_to_here
|
|
|
|
# This is the URL where your supabase stack is accessible
|
|
# i.e. this is the endpoint URL you would pass into a `createClient()` call in the supabase-js library
|
|
API_EXTERNAL_URL=https://database.example.com/
|
|
|
|
# Set this to true if you want to prevent signing up with email and password
|
|
GOTRUE_DISABLE_SIGNUP=true
|
|
|
|
# oAuth
|
|
# If you are not using oAuth to login (e.g. Login with Facebook), you can ignore the below
|
|
# If you want to disable oAuth for a specific provider, set the `GOTRUE_EXTERNAL_<provider>_ENABLED` to false
|
|
# Github oAuth
|
|
GOTRUE_EXTERNAL_GITHUB_CLIENT_ID=your_github_client_id
|
|
GOTRUE_EXTERNAL_GITHUB_SECRET=your_github_client_secret
|
|
GOTRUE_EXTERNAL_GITHUB_ENABLED=true
|
|
|
|
# Google oAuth
|
|
GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID=your-google-client-id.apps.googleusercontent.com
|
|
GOTRUE_EXTERNAL_GOOGLE_SECRET=your-google-secret
|
|
GOTRUE_EXTERNAL_GOOGLE_ENABLED=true
|
|
|
|
# Facebook oAuth
|
|
GOTRUE_EXTERNAL_FACEBOOK_CLIENT_ID=your-facebook-client-id
|
|
GOTRUE_EXTERNAL_FACEBOOK_SECRET=your-facebook-app-secret
|
|
GOTRUE_EXTERNAL_FACEBOOK_ENABLED=true
|
|
|
|
# Add other oAuth provider details below
|
|
```
|
|
|
|
More details can be found in the 'Configuring each service section' above.
|
|
|
|
## One-click deploys
|
|
|
|
For some tools we also provide images and deployments into cloud marketplaces:
|
|
|
|
### Postgres
|
|
|
|
- AWS (Arm architecture) [one click deploy](https://aws.amazon.com/marketplace/pp/B08V22HK26?qid=1617156168590&sr=0-3)
|
|
- AWS [one click deploy](https://aws.amazon.com/marketplace/pp/B08915TCJ2)
|
|
- Digital Ocean [one click deploy](https://marketplace.digitalocean.com/apps/supabase-postgres)
|
|
- Docker [image](https://hub.docker.com/r/supabase/postgres)
|
|
|
|
### Realtime
|
|
|
|
- AWS [one click deploy](https://aws.amazon.com/marketplace/pp/B089N4FH7N?qid=1617156168590&sr=0-2)
|
|
- Digital Ocean [one click deploy](https://marketplace.digitalocean.com/apps/supabase-realtime)
|
|
- Docker [image](https://hub.docker.com/r/supabase/realtime)
|
|
|
|
## Next steps
|
|
|
|
- Got a question? [Ask here](https://github.com/supabase/supabase/discussions).
|
|
- Sign in: [app.supabase.io](https://app.supabase.io)
|