-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
176 lines (162 loc) · 5.95 KB
/
Copy path.env.example
File metadata and controls
176 lines (162 loc) · 5.95 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
# Environment variables for docker compose (see compose.yml).
# Copy to `.env`, then fill JWT/API keys and empty infrastructure secrets:
# - From main stack supabase-headless: node generate-keys.mjs --update-env
# - From vendored app: node vendor/supabase-headless/generate-keys.mjs --update-env
# Official Supabase reference: https://github.com/supabase/supabase/blob/master/docker/.env.example
# ============================================================
# PLATFORM (headless stack variables)
# ============================================================
# ---
# GENERAL (URLs, path prefixes, shared cross-service knobs)
# ---
PUBLIC_API_DOMAIN=localhost
PUBLIC_API_URL=https://${PUBLIC_API_DOMAIN}
APP_DOMAIN=localhost
APP_URL=https://${APP_DOMAIN}
AUTH_PREFIX=/auth/v1
REST_PREFIX=/rest/v1
REALTIME_PREFIX=/realtime/v1
STORAGE_PREFIX=/storage/v1
FUNCTIONS_PREFIX=/functions/v1
# Shared by Auth, PostgREST (PGRST_SERVER_TRACE_HEADER), Storage and Gateway.
REQUEST_ID_HEADER=X-Request-ID
# Shared by RustFS, imgproxy, and Storage.
S3_REGION=local
# Shared by Storage and RustFS.
GLOBAL_S3_BUCKET=supabase-global
# Shared by Storage and imgproxy (IMGPROXY_MAX_SRC_FILE_SIZE).
FILE_SIZE_LIMIT=52428800
# Storage's public S3 protocol endpoint (/storage/v1/s3).
# https://supabase.com/docs/guides/self-hosting/self-hosted-s3
S3_PROTOCOL_ACCESS_KEY_ID=
S3_PROTOCOL_ACCESS_KEY_SECRET=
# ---
# API KEYS & JWT SIGNING
# https://supabase.com/docs/guides/self-hosting/self-hosted-auth-keys
# ---
# HS256 symmetric secret. Auth refresh-token signing; also embedded in JWT_JWKS for legacy HS256 verification.
JWT_SECRET=
# Signing JWKs (EC private + symmetric). Auth (GOTRUE_JWT_KEYS).
JWT_KEYS=
# Verifying JWKS (EC public + symmetric). PostgREST, Realtime, Storage.
JWT_JWKS=
# Internal ES256 JWTs — gateway substitutes these for opaque keys before proxying. Never expose to clients.
ANON_KEY_ASYMMETRIC=
SERVICE_ROLE_KEY_ASYMMETRIC=
# Browser/mobile publishable key. Maps to the anon role.
SUPABASE_PUBLISHABLE_KEY=
# Server-only secret key. Maps to service_role and bypasses RLS; never expose to browsers or mobile apps.
SUPABASE_SECRET_KEY=
# Legacy HS256 JWT API keys. Optional/migration-only: the gateway accepts them alongside sb_* keys. Storage and Functions currently still require them.
ANON_KEY=
SERVICE_ROLE_KEY=
# ---
# POSTGRESQL (db, db-migrate, postgres-meta)
# ---
POSTGRES_DB=postgres
POSTGRES_USER=postgres
POSTGRES_PASSWORD=
POSTGRES_PORT=5432
POSTGRES_MAX_CONNECTIONS=100
POSTGRES_SHARED_BUFFERS=1GB
POSTGRES_EFFECTIVE_CACHE_SIZE=3GB
POSTGRES_MAINTENANCE_WORK_MEM=512MB
POSTGRES_WORK_MEM=32MB
# Log queries slower than this many milliseconds.
POSTGRES_LOG_MIN_DURATION_STATEMENT=200
DB_CPU_LIMIT=4.0
DB_MEMORY_LIMIT=4G
DB_SHM_SIZE=2GB
# Role passwords (db/init.sql bootstrap).
AUTH_DB_PASSWORD=
STORAGE_DB_PASSWORD=
# ---
# SUPABASE AUTH (GOTRUE) — wired in compose.yml
# https://github.com/supabase/auth?tab=readme-ov-file#configuration
# ---
GOTRUE_URI_ALLOW_LIST=${APP_URL}/*
GOTRUE_EXTERNAL_EMAIL_ENABLED=true
AUTH_DB_POOL_SIZE=10
GOTRUE_RATE_LIMIT_HEADER=X-Forwarded-For
GOTRUE_SECURITY_REFRESH_TOKEN_ROTATION_ENABLED=true
# fatal, error, warn, info, debug
GOTRUE_LOG_LEVEL=warn
# Skip email confirmation until SMTP is configured. Set false in production with real SMTP.
GOTRUE_MAILER_AUTOCONFIRM=true
GOTRUE_JWT_EXP=3600
# ---
# REALTIME — wired in compose.yml
# https://github.com/supabase/realtime?tab=readme-ov-file#server-setup
# ---
REALTIME_SECRET_KEY_BASE=
# Exactly 16 characters.
REALTIME_DB_ENC_KEY=
REALTIME_DB_POOL_SIZE=5
# Stable internal tenant identifier used by both Realtime seeding and the gateway Host rewrite.
REALTIME_TENANT_ID=realtime-dev
# Max 63 chars total: supabase_realtime_messages_replication_slot_ (45) + suffix (≤18).
REALTIME_SLOT_NAME_SUFFIX=local
REALTIME_DASHBOARD_AUTH=basic_auth
REALTIME_DASHBOARD_USER=admin
REALTIME_DASHBOARD_PASSWORD=
# info, emergency, alert, critical, error, warning, notice, debug
REALTIME_LOG_LEVEL=warning
# ---
# POSTGREST (rest) — wired in compose.yml
# https://docs.postgrest.org/en/latest/references/configuration.html
# ---
# Schemas exposed via the Data API. Add `graphql_public` if you enable it.
PGRST_DB_SCHEMAS=public
PGRST_DB_EXTRA_SEARCH_PATH=public,extensions
PGRST_DB_ANON_ROLE=anon
PGRST_DB_MAX_ROWS=1000
PGRST_DB_POOL=20
# Bootstrap + Rest.
PGRST_AUTH_USER=authenticator
PGRST_AUTH_PASSWORD=
# crit, error, warn, info, debug
PGRST_LOG_LEVEL=warn
# ---
# RUSTFS (S3) — wired in compose.yml
# ---
RUSTFS_ACCESS_KEY=
RUSTFS_SECRET_KEY=
RUSTFS_CONSOLE_ENABLE=false
# debug, info, warn, error
RUSTFS_LOG_LEVEL=warn
# ---
# IMGPROXY — wired in compose.yml
# https://docs.imgproxy.net/latest/configuration/options
# ---
IMGPROXY_MAX_SRC_RESOLUTION=25
# error, warn, info, debug
IMGPROXY_LOG_LEVEL=warn
IMGPROXY_FAIL_ON_DEPRECATION=true
# ---
# STORAGE API — wired in compose.yml
# https://github.com/supabase/storage?tab=readme-ov-file#development
# ---
STORAGE_DB_POOL_SIZE=15
# pino levels: trace, debug, info, warn, error, fatal, silent
STORAGE_LOG_LEVEL=warn
STORAGE_JWT_CACHING_ENABLED=true
STORAGE_TENANT_ID=default
# ---
# EDGE FUNCTIONS — wired in compose.yml (keys only; SUPABASE_URL is http://gateway:8080 in compose)
# ---
# ---
# GATEWAY (Caddy) — wired in compose.yml
# ---
CADDY_CONTACT_EMAIL=admin@localhost
# The apikey/JWT is the auth boundary, and no cookies/credentials are used, so a wildcard is safe for bearer-token SDK apps. Pin a concrete origin like ${APP_URL} to block other browser origins at the CORS layer.
CORS_ALLOWED_ORIGIN=*
GATEWAY_RATE_LIMIT_EVENTS=100
GATEWAY_RATE_LIMIT_WINDOW=1s
# Public path for the Realtime admin UI consumed by Caddy gateway (Caddy proxies {$REALTIME_DASHBOARD_PREFIX}/* -> realtime:4000).
REALTIME_DASHBOARD_PREFIX=/admin
# DEBUG, INFO, WARN, ERROR (Caddy log level)
CADDY_LOG_LEVEL=WARN
# ============================================================
# APPLICATION
# Append product-specific vars below. Keep platform vars above.
# ============================================================