fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(migrations): update types that are not set on the schema - #1848

Closed
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development
Closed

fix(migrations): update types that are not set on the schema#1848
ffimnsr wants to merge 1 commit into
supabase:masterfrom
ffimnsr:development

Conversation

@ffimnsr

Copy link
Copy Markdown

What kind of change does this PR introduce?

This changeset updates the migrations schema that's causing trouble on new supabase/auth installations whether it's using docker or not. The types are not set on the schema which causes the migrations to fail. And it adds residual types to public schema.

What is the current behavior?

Issue #1729 was closed despite not resolving the problem.

What is the new behavior?

Add the relevant types to the proper schema.

Additional context

image
image

@ffimnsr
ffimnsr requested a review from a team as a code ownerNovember 27, 2024 14:43
This changeset updates the migrations schema that's causing trouble on new
supabase/auth installations whether its using docker or not. The types are not
set on the schema which causes the migrations to fail. And it adds residual
types on public schema.
Signed-off-by: Edward Fitz Abucay <ffimnsr@gmail.com>
@ffimnsr

Copy link
Copy Markdown
Author

It seems the main problem here is the migrator-cmd executes the sql migrations in public schema. That's why when the next sql instruction comes up, it tries to find it in public and that's the reason it fails. That's why I force the schema migrations to use the namespace types.

@patrickwjh

patrickwjh commented Dec 11, 2024

Copy link
Copy Markdown

Would be nice if this merge request would fix the migration errors. Right now it is not possible for me to start a new docker container because i get always an error that the factor_type doesn't exists.

I can only fix it by manually creating that type in the DB.

So this migration ist the problem in my case: 20240729123726_add_mfa_phone_config.up.sql

@coveralls

Copy link
Copy Markdown

Pull Request Test Coverage Report for Build 12053898208

Warning: This coverage report may be inaccurate.

This pull request's base commit is no longer the HEAD commit of its target branch. This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 56.998%

TotalsCoverage Status
Change from base Build 12045179447:0.0%
Covered Lines:9546
Relevant Lines:16748

💛 - Coveralls

@ffimnsr

Copy link
Copy Markdown
Author

@patrickwjh you might need to create the auth user before doing the migration and set its search path to auth or your custom DB_NAMESPACE.

This PR only solves the problem like if the auth user is not created before doing the migration and that would result in the above screenshots which scatters the types to default schema. A scenario where user will move all created item ownership to auth user afterwards (after running the migration).

Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@ffimnsr@patrickwjh@coveralls