Files
supabase/web/docs/guides/self-hosting.mdx
T
Copple ae4aa50a6a Merge pull request #2672 from ChronSyn/patch-3
[Misc] Update self-hosting docs with GoTrue env example
2021-09-06 12:33:39 +08:00

246 lines
9.2 KiB
Plaintext

---
id: self-hosting
title: Self Hosting
description: How to use configure and deploy Supabase.
---
Supabase is a [Hosted Platform](https://app.supabase.io), so you don't _have_ to deploy it yourself.
However, if you want to configure and deploy it yourself, that's also possible.
![Supabase Architecture](/img/supabase-architecture.png)
## Before you begin
The self-hosted version of Supabase does not include a UI yet.
We are working on this in stages, starting with our [UI library](https://github.com/supabase/ui) and with a [WIP PR here](https://github.com/supabase/supabase/pull/2281).
[[more context](https://github.com/supabase/supabase/discussions/1001#discussioncomment-558696)]
In the meantime, here are some suggestions for working with your Postgres Database:
- `pgadmin`: https://www.pgadmin.org
- `dbeaver`: https://dbeaver.com
- `BeeKeeper`: https://beekeeperstudio.io
- `HeidiSQL`: https://heidisql.com
- `Table Plus`: https://www.tableplus.io
## Get the Docker Compose
We provide a Docker Compose directory which is includes all of the tools required for building on top of Supabase.
Download the Docker files:
```bash
# 1. Copy an empty repo
git clone https://github.com/supabase/supabase
# 2. Move into the empty repo
cd supabase/docker
```
## Running Locally
Now that you have the Docker set up on your local machine, you can start it here by running
```bash
docker-compose up
```
## Deploying
### Configuring each service
Supabase is made up of several services. We have prefilled the `docker-compose` file with all the configuration you need to get started.
If you would like to change any of the configuration, you can update the env variables in the `docker-compose` file.
Here are a list of environment variables for each service:
- [Postgres](https://hub.docker.com/_/postgres/)
- [PostgREST](https://postgrest.org/en/v7.0.0/configuration.html)
- [Realtime](https://github.com/supabase/realtime#server-set-up)
- [GoTrue](https://github.com/supabase/gotrue)
- [Storage](https://github.com/supabase/storage-api)
- [Kong](https://docs.konghq.com/install/docker/)
### Update secrets
If you are deploying to production, you should update the default [passwords and secrets](https://github.com/supabase/supabase/blob/master/docker/.env).
### Update API keys
All config for the API Gateway is stored in the `kong` directory. Inside `kong.yml` you'll find the routing for all services, the routing rules,
and down the bottom you'll find the JWTs capable of accessing services that require API Key access.
See the full docs [here](https://docs.konghq.com/hub/kong-inc/key-auth/).
If you are deploying to production, you should encode a new `anon` and `service_role` API key and update
them [here](https://github.com/supabase/supabase/blob/b1e99d2ce1f63ba728230fb53a6de444f60bce1f/docker/dockerfiles/kong/kong.yml#L42).
After you have regenerated the JWT secret in the step above, use a JWT generator (for example, using [jsonwebtoken.io](https://www.jsonwebtoken.io/)) to regenerate the API Keys using the payloads below:
```bash
# anon Payload:
{
"iss": "supabase",
"iat": 1603968834,
"exp": 2550653634,
"aud": "",
"sub": "",
"role": "anon"
}
# service_role Payload:
{
"iss": "supabase",
"iat": 1603968834,
"exp": 2550653634,
"aud": "",
"sub": "",
"role": "service_role"
}
```
### Configuring email
GoTrue requires an SMTP server to send emails for all authentication actions.
You will need to provide the following [settings](https://github.com/supabase/gotrue#e-mail) inside the `.env` file [here](https://github.com/supabase/supabase/blob/027e7f7b97bbe7365db4f7f46abe480e05841006/docker/.env#L8).
### Deploying
See the following guides to deploy Docker Compose setup using your preferred tool and platform:
- [AWS with Docker Machine](https://docs.docker.com/machine/get-started-cloud/#amazon-web-services-aws)
- [Digital Ocean with Docker Machine](https://docs.docker.com/machine/get-started-cloud/#digitalocean)
- [Docker Swarm](https://docs.docker.com/engine/swarm/stack-deploy/)
- [AWS Fargate](https://aws.amazon.com/blogs/containers/deploy-applications-on-amazon-ecs-using-docker-compose/)
- [Using Kompose for Kubernetes](https://kubernetes.io/docs/tasks/configure-pod-container/translate-compose-kubernetes/)
### Example environment variable configuration
The default environment variable configuration for most services should be sufficient. The default GoTrue config may not support all the settings you require to get up and running.
For brevity, here is an example of what the environment variables for the auth / GoTrue container might look like once the service is deployed:
```sh
GOTRUE_OPERATOR_TOKEN=your-super-secret-operator-token
GOTRUE_JWT_DEFAULT_GROUP_NAME=authenticated
# Make sure this JWT secret matches what was configured during setup
GOTRUE_JWT_SECRET=your-super-secret-jwt-token-with-at-least-32-characters-long
# How long should JWT tokens be valid for?
GOTRUE_JWT_EXP=3600
# Since Supabase is based on Postgres, you shouldn't need to change this
GOTRUE_DB_DRIVER=postgres
# What schema should requests be routed to?
# There should be no reason to change this
DB_NAMESPACE=auth
# Where is our auth/GoTrue located
# You shouldn't need to change these unless the ports are mapped differently
GOTRUE_API_HOST=0.0.0.0
PORT=9999
# Email settings
# You must set these if you want to be able to send emails
GOTRUE_SMTP_HOST=smtp.your-email-host.com
GOTRUE_SMTP_PORT=465
GOTRUE_SMTP_USER=your-smtp-user
GOTRUE_SMTP_PASS=your-smtp-password
# Should users be required to confirm their email address before they can log in?
# If set to false, users won't have to confirm their registration
# If set to true, users will have to click the link in their email to confirm
GOTRUE_MAILER_AUTOCONFIRM=false
# What is the 'from' address that emails are sent from?
GOTRUE_SMTP_ADMIN_EMAIL=noreply@example.com
# Remove this if you don't want debug logs
GOTRUE_LOG_LEVEL=debug
# The connection string for your database
# `@db` says we're looking for the container called 'db' on our docker network
DATABASE_URL=postgres://postgres:your-super-secret-and-long-postgres-password@db:5432/postgres
# Email templates
# Invite user - provide a URL to a HTML or Text template
GOTRUE_MAILER_TEMPLATES_INVITE=https://example.com/path/to/your/invite/template.html
# Confirm registration - provide a URL to a HTML or Text template
GOTRUE_MAILER_TEMPLATES_CONFIRMATION=https://example.com/path/to/your/confirmation/template.html
# Password recovery - provide a URL to a HTML or Text template
GOTRUE_MAILER_TEMPLATES_RECOVERY=https://example.com/path/to/your/password_reset/template.HTML
# Magic link - provide a URL to a HTML or Text template
GOTRUE_MAILER_TEMPLATES_MAGIC_LINK=https://example.com/path/to/your/magic_link/template.html
# GoTrue URLs
# These are appended after the API_EXTERNAL_URL
# You shouldn't need to change these
GOTRUE_MAILER_URLPATHS_CONFIRMATION=/auth/v1/verify
GOTRUE_MAILER_URLPATHS_INVITE=/auth/v1/verify
GOTRUE_MAILER_URLPATHS_CONFIRMATION=/auth/v1/verify
GOTRUE_MAILER_URLPATHS_RECOVERY=/auth/v1/verify
# Site URLs
# This is where the user will be redirected to after clicking a link in an email and after oAuth
GOTRUE_SITE_URL=https://example.com/redirect_to_here
GOTRUE_URI_ALLOW_LIST=https://example.com/redirect_to_here
# This is the URL where your supabase stack is accessible
# i.e. this is the endpoint URL you would pass into a `createClient()` call in the supabase-js library
API_EXTERNAL_URL=https://database.example.com/
# Set this to true if you want to prevent signing up with email and password
GOTRUE_DISABLE_SIGNUP=true
# oAuth
# If you are not using oAuth to login (e.g. Login with Facebook), you can ignore the below
# If you want to disable oAuth for a specific provider, set the `GOTRUE_EXTERNAL_<provider>_ENABLED` to false
# Github oAuth
GOTRUE_EXTERNAL_GITHUB_CLIENT_ID=your_github_client_id
GOTRUE_EXTERNAL_GITHUB_SECRET=your_github_client_secret
GOTRUE_EXTERNAL_GITHUB_ENABLED=true
# Google oAuth
GOTRUE_EXTERNAL_GOOGLE_CLIENT_ID=your-google-client-id.apps.googleusercontent.com
GOTRUE_EXTERNAL_GOOGLE_SECRET=your-google-secret
GOTRUE_EXTERNAL_GOOGLE_ENABLED=true
# Facebook oAuth
GOTRUE_EXTERNAL_FACEBOOK_CLIENT_ID=your-facebook-client-id
GOTRUE_EXTERNAL_FACEBOOK_SECRET=your-facebook-app-secret
GOTRUE_EXTERNAL_FACEBOOK_ENABLED=true
# Add other oAuth provider details below
```
More details can be found in the 'Configuring each service section' above.
## One-click deploys
For some tools we also provide images and deployments into cloud marketplaces:
### Postgres
- AWS (Arm architecture) [one click deploy](https://aws.amazon.com/marketplace/pp/B08V22HK26?qid=1617156168590&sr=0-3)
- AWS [one click deploy](https://aws.amazon.com/marketplace/pp/B08915TCJ2)
- Digital Ocean [one click deploy](https://marketplace.digitalocean.com/apps/supabase-postgres)
- Docker [image](https://hub.docker.com/r/supabase/postgres)
### Realtime
- AWS [one click deploy](https://aws.amazon.com/marketplace/pp/B089N4FH7N?qid=1617156168590&sr=0-2)
- Digital Ocean [one click deploy](https://marketplace.digitalocean.com/apps/supabase-realtime)
- Docker [image](https://hub.docker.com/r/supabase/realtime)
## Next steps
- Got a question? [Ask here](https://github.com/supabase/supabase/discussions).
- Sign in: [app.supabase.io](https://app.supabase.io)