enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

enh: prefix schema to enum migrations - #2040

Closed
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2
Closed

enh: prefix schema to enum migrations#2040
willnode wants to merge 1 commit into
supabase:masterfrom
willnode:fix-migration-2

Conversation

@willnode

Copy link
Copy Markdown

Add support for nonstandard search path migrations

What kind of change does this PR introduce?

Continuation of #1983 and fixes#1729

What is the current behavior?

The current migration script assumes the search path has been set to a custom schema.

ALTER USER supabase_auth_admin SET search_path = '$DB_NAMESPACE';

If this step missed, the default schema for all migrations is public. This should be fine if all tables and enums are prefixed accordingly, but currently it's not. All postgres enum is not prefixed with schema.

What is the new behavior?

All postgres enum will be prefixed with the schema. This should fixes issue #1729 where the migration is broken if search path is not set properly.

This doesn't introduce a breaking change, because if search_path is already set all enums stay on the former search_path .

Additional context

Haven't test. Will test soon.

Add support for nonstandard search path migrations
@willnode
willnode requested a review from a team as a code ownerMay 31, 2025 05:01
cstockton pushed a commit that referenced this pull request Aug 4, 2025
Add support for nonstandard search path migrations
Bewinxed pushed a commit that referenced this pull request Jan 19, 2026
## What kind of change does this PR introduce?
Big fix for #1729, #1848, #1983, and #2040 with an additional type fix.
## What is the current behavior?
The auth service cannot be deployed in a net new environment on
PostgreSQL 17.
## What is the new behavior?
The service is running properly with PostgreSQL 17 in a cleanroom
environment.
## Additional context
Here is a redacted version of the terraform I used to deploy it with. I
used my own container build with these fixes,
`ghcr.io/siennathesane/auth:v2.175.0`, that you can use to verify the
fix is valid, if you want.
```hcl
locals {
f2-auth-db-namespace = "auth"
}
resource "kubernetes_service_account" "f2-auth" {
metadata {
name = "f2-auth"
namespace = var.namespace
}
}
resource "kubernetes_manifest" "f2-auth-db" {
manifest = {
"apiVersion" = "postgresql.cnpg.io/v1"
"kind" = "Database"
"metadata" = {
"name" = "f2-auth-db"
"namespace" = var.namespace
}
"spec" = {
"cluster" = {
"name" = kubernetes_manifest.f2-cluster.object.metadata.name
}
"allowConnections" = true
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
"schemas" = [{
"name" = local.f2-auth-db-namespace
"owner" = kubernetes_secret_v1.f2-auth-db.data.username
}]
}
}
}
resource "kubernetes_config_map_v1" "f2-auth-initdb" {
metadata {
name = "sql-commands"
namespace = var.namespace
}
data = {
"script.sql" = <<-EOT
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} WITH LOGIN CREATEROLE CREATEDB REPLICATION BYPASSRLS;
GRANT ${kubernetes_secret_v1.f2-auth-db.data.username} TO postgres;
CREATE SCHEMA IF NOT EXISTS ${local.f2-auth-db-namespace} AUTHORIZATION ${kubernetes_secret_v1.f2-auth-db.data.username};
GRANT CREATE ON DATABASE postgres TO ${kubernetes_secret_v1.f2-auth-db.data.username};
ALTER USER ${kubernetes_secret_v1.f2-auth-db.data.username} SET search_path = '${local.f2-auth-db-namespace}';
EOT
}
}
resource "kubernetes_secret_v1" "f2-auth-db" {
metadata {
name = "auth-db"
namespace = var.namespace
labels = {
"cnpg.io/reload" = "true"
}
}
data = {
username = "[REDACTED]"
password = random_password.f2-auth-db-password.result
database = "auth"
}
type = "kubernetes.io/basic-auth"
}
resource "kubernetes_secret_v1" "f2-auth-jwt" {
metadata {
name = "auth-jwt"
namespace = var.namespace
}
data = {
anonKey = "[REDACTED]"
secret = "[REDACTED]"
serviceKey = "[REDACTED]"
}
type = "Opaque"
}
resource "random_password" "f2-auth-db-password" {
length = 16
special = false
}
resource "kubernetes_deployment_v1" "f2-auth" {
depends_on = [kubernetes_manifest.f2-auth-db]
timeouts {
create = "2m"
}
metadata {
name = "f2auth"
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
namespace = var.namespace
}
spec {
replicas = 1
selector {
match_labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
template {
metadata {
labels = {
"f2.pub/app" = "auth-${var.environment}"
}
}
spec {
image_pull_secrets { name = var.ghcr-pull-secret-name }
init_container {
name = "init-db"
image = "postgres:17-alpine"
command = ["psql", "-f", "/sql/script.sql"]
env {
name = "PGHOST"
value = "${kubernetes_manifest.f2-cluster.object.metadata.name}-rw"
}
env {
name = "PGPORT"
value = "5432"
}
env {
name = "PGDATABASE"
value = kubernetes_secret_v1.f2-auth-db.data.database
}
env {
name = "PGUSER"
value = kubernetes_secret_v1.f2-auth-db.data.username
}
env {
name = "PGPASSWORD"
value = kubernetes_secret_v1.f2-auth-db.data.password
}
volume_mount {
name = "sql-volume"
mount_path = "/sql"
}
}
volume {
name = "sql-volume"
config_map {
name = kubernetes_config_map_v1.f2-auth-initdb.metadata[0].name
}
}
container {
image = "ghcr.io/siennathesane/auth:${var.goauth-version}"
image_pull_policy = "Always"
name = "auth"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
port {
name = "http"
container_port = 9999
protocol = "TCP"
}
env {
name = "GOTRUE_DB_DRIVER"
value = "postgres"
}
env {
name = "DB_NAMESPACE"
value = "auth"
}
env {
name = "DATABASE_URL"
value = "postgres://${kubernetes_secret_v1.f2-auth-db.data.username}:[REDACTED]@${ kubernetes_manifest.f2-cluster.object.metadata.name}-rw:5432/${kubernetes_secret_v1.f2-auth-db.data.database}"
}
env {
name = "GOTRUE_JWT_SECRET"
value_from {
secret_key_ref {
name = "auth-jwt"
key = "secret"
}
}
}
env {
name = "API_EXTERNAL_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_SITE_URL"
value = "http://[REDACTED]"
}
env {
name = "GOTRUE_API_HOST"
value = "0.0.0.0"
}
env {
name = "PORT"
value = "9999"
}
}
}
}
}
}
```
Closes#1729Closes#1848Closes#1983Closes#2040
Signed-off-by: Sienna Satterwhite <sienna@r3t.io>
Co-authored-by: Chris Stockton <180184+cstockton@users.noreply.github.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Issue with migrations

1 participant

@willnode