fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: Migration error with different auth schema - #1983

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration
Closed

fix: Migration error with different auth schema#1983
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration

Conversation

@willnode

Copy link
Copy Markdown

What kind of change does this PR introduce?

Fixes#1729

What is the current behavior?

Doesn't nicely play if default schema is other than "auth"

What is the new behavior?

Migration will be fine

Additional context

Add any other context or screenshots.

image

@willnode
willnode requested a review from a team as a code ownerApril 9, 2025 02:23
@willnode

willnode commented Apr 9, 2025

Copy link
Copy Markdown
Author

I have confirmed that executing this to the DB directly will make it healthy

altertype factor_type add value 'phone';
altertableauth.mfa_factors add column if not exists phone text unique default null;
altertableauth.mfa_challenges add column if not exists otp_code textnull;
createunique indexif not exists unique_verified_phone_factor onauth.mfa_factors (user_id, phone);
insert intopublic.schema_migrations (version) values ('20240729123726');

@willnode

Copy link
Copy Markdown
Author

image

If you wonder what happens if we completely discard schema in enum types.

@hf

hf commented Apr 14, 2025

Copy link
Copy Markdown
Contributor

Hmm this seems off. Are you specifying your schema in the migrations correctly?

@willnode

Copy link
Copy Markdown
Author

Here's my compose file: https://github.com/willnode/supabase-docker/blob/main/docker-compose.yml.

I do not set "DB_NAMESPACE" and I do not set the default postgres search path to be "auth" since I want to use my external postgres database. The only thing that prevents me from using my external database is this PR.

I could reverse this change, so the enum would be namespaced correctly, but it would be adding namespace for enum types from migrations/20221003041349_add_mfa_schema.up.sql and every migration files of it after.

@willnode

Copy link
Copy Markdown
Author

OK I understand whythe "default" way to install in docker works, the search path is set in the script:

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

We do not set separate postgres account in each docker service, so we don't have the opportunity to set this. We just set one postgres account to all services in the compose file. Setting the search path is not a reasonable option in this case.

cstockton added a commit to cangqiaoyuzhuo/auth that referenced this pull request Dec 10, 2025
## What kind of change does this PR introduce?
Big fix for supabase#1729, supabase#1848, supabase#1983, and supabase#2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closessupabase#1729Closessupabase#1848Closessupabase#1983Closessupabase#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

2 participants

@willnode@hf