Files
2026-04-18 23:11:35 +02:00
..
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00
2026-04-18 23:11:35 +02:00

Supabase Self-Hosting

We do NOT vendor the Supabase docker-compose here — we track the official repo instead.

Bootstrap on a fresh Hetzner VPS (Debian/Ubuntu)

# 1. Install Docker + Compose plugin
curl -fsSL https://get.docker.com | sh
sudo usermod -aG docker $USER

# 2. Clone Supabase's official self-host setup
git clone --depth 1 https://github.com/supabase/supabase.git
cd supabase/docker

# 3. Seed env
cp .env.example .env
# Edit .env: set POSTGRES_PASSWORD, JWT_SECRET, ANON_KEY, SERVICE_ROLE_KEY, SMTP creds,
# SITE_URL, API_EXTERNAL_URL, STUDIO_DEFAULT_ORGANIZATION etc.

# 4. Pull + run
docker compose pull
docker compose up -d

Our repo owns

  • migrations/ — SQL migrations applied via Supabase CLI (supabase db push) to the self-hosted DB.
  • .env.example — the subset of Supabase env vars our client code depends on.
  • This README.

Reverse proxy

Caddy setup lives in a separate directory (not part of this milestone). The public edge terminates TLS and routes /auth/*, /rest/*, /realtime/*, /storage/*, /functions/* to the compose stack, and / to Supabase Studio (ACL-restricted).

Security notes

  • Rotate JWT_SECRET at first boot; never reuse the example.
  • SERVICE_ROLE_KEY never ships to any client — only edge functions / admin scripts.
  • Enable RLS on every user-facing table. Invite-only enforced via invites table + policy.