From f47625528475f147a3808e0421b0dea7389561ad Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 17:57:57 +0200 Subject: [PATCH] supabase: own secrets, and unique ids for its containers The manifest declared its secrets as secrets.secret. and required a "secret" provision, so the controller saw no own secrets and every accept was refused (the influxdb defect of #180). The directories functions and storage shared their ids with the containers of the same name, which the host refuses as two resources with one identity. The containers are now edge-functions and storage-api; the placed directories keep their ids and paths. --- modules/supabase/module.json | 35 ++++++++++++++++------------------- 1 file changed, 16 insertions(+), 19 deletions(-) diff --git a/modules/supabase/module.json b/modules/supabase/module.json index 95358cd..862209e 100644 --- a/modules/supabase/module.json +++ b/modules/supabase/module.json @@ -28,9 +28,21 @@ } ], "requires": [ - "route", - "secret" + "route" ], + "own-secrets": { + "postgres": "${dir:state}/postgres.secret", + "jwt": "${dir:state}/jwt.secret", + "anon-key": "${dir:state}/anon-key.secret", + "service-role-key": "${dir:state}/service-role-key.secret", + "dashboard-user": "${dir:state}/dashboard-user.secret", + "dashboard": "${dir:state}/dashboard.secret", + "logflare": "${dir:state}/logflare.secret", + "pooler-vault": "${dir:state}/pooler-vault.secret", + "key-base-a": "${dir:state}/key-base-a.secret", + "key-base-b": "${dir:state}/key-base-b.secret", + "openai": "${dir:state}/openai.secret" + }, "contributes": { "route": { "label": "supabase", @@ -40,21 +52,6 @@ "binds": { "route": "${dir:state}/route.json" }, - "secrets": { - "secret": { - "postgres": "${dir:state}/postgres.secret", - "jwt": "${dir:state}/jwt.secret", - "anon-key": "${dir:state}/anon-key.secret", - "service-role-key": "${dir:state}/service-role-key.secret", - "dashboard-user": "${dir:state}/dashboard-user.secret", - "dashboard": "${dir:state}/dashboard.secret", - "logflare": "${dir:state}/logflare.secret", - "pooler-vault": "${dir:state}/pooler-vault.secret", - "key-base-a": "${dir:state}/key-base-a.secret", - "key-base-b": "${dir:state}/key-base-b.secret", - "openai": "${dir:state}/openai.secret" - } - }, "resources": [ { "id": "state", @@ -451,7 +448,7 @@ ] }, { - "id": "storage", + "id": "storage-api", "type": "container", "name": "supabase-storage", "image": "supabase/storage-api@sha256:1e85dad48e8b3e85890a555e5114dc7ee48c2e8be4cfd97dd4e3564b4f104fcd", @@ -476,7 +473,7 @@ "secrets-in-environment": "postgres-meta reads PG_META_DB_PASSWORD from the environment only" }, { - "id": "functions", + "id": "edge-functions", "type": "container", "name": "supabase-edge-functions", "image": "supabase/edge-runtime@sha256:6f7ac3b363f6b278ff9235672a81504ad07709a07f62c50cd4fffb6708842ff1",