Skip to content

Self-Hosted Supabase Stack

The Planovi VPS runs a complete, self-hosted deployment of the Supabase open-source platform orchestrated via Docker Compose. This stack provides the database, authentication, RESTful API layer, object storage, and serverless Edge Functions for the entire ecosystem.


🧩 Container Services Breakdown

graph TD
    Client["🌐 Client Traffic (via Nginx)"] --> Kong["🚪 supabase-kong (:8000)"]
    
    Kong -->|"/auth/v1"| Auth["🔑 supabase-auth (:9999)"]
    Kong -->|"/rest/v1"| Postgrest["⚡ supabase-postgrest (:3000)"]
    Kong -->|"/storage/v1"| Storage["📁 supabase-storage (:5000)"]
    Kong -->|"/functions/v1"| EdgeRuntime["⚡ supabase-edge-runtime (:9000)"]

    Studio["📊 supabase-studio (:3000)"] --> PgMeta["🛠️ supabase-pg-meta (:8080)"]
    
    Auth --> DB["💾 supabase-db (PostgreSQL 15 :5432)"]
    Postgrest --> DB
    Storage --> DB
    EdgeRuntime --> DB
    PgMeta --> DB

1. Database (supabase-db)

  • Image: supabase/postgres:15.1.0.147
  • Port: Internal Docker network 5432 (Network alias: db)
  • Health Check: pg_isready -U postgres every 5s with 5 retries.
  • Data Volume: supabase-db-data mounted at /var/lib/postgresql/data.
  • Pre-installed Extensions: pgcrypto, pgjwt, uuid-ossp, pgvector, pg_stat_statements.

2. API Gateway (supabase-kong)

  • Image: kong:2.8.1
  • Declarative Configuration: /var/lib/kong/kong.yml
  • Responsibilities:
    • Routes inbound HTTP paths (/auth/v1/, /rest/v1/, /storage/v1/, /functions/v1/) to their respective internal services.
    • Validates API keys (apikey query param or header) against SUPABASE_ANON_KEY and SUPABASE_SERVICE_ROLE_KEY.
    • Enforces CORS policies across all subdomains.

3. Authentication (supabase-auth / GoTrue)

  • Image: supabase/gotrue:v2.132.3
  • Internal Port: 9999
  • Database Schema: auth schema inside PostgreSQL.
  • Transactional Mailer: Integrated with Resend SMTP (smtp.resend.com:587) for verification codes, password resets, and magic link authentication.

4. RESTful Data API (supabase-postgrest)

  • Image: postgrest/postgrest:v11.2.0
  • Exposed Schemas: public, storage, graphql_public
  • Anonymous Role: anon (Subject to PostgreSQL Row Level Security policies).

5. Serverless Edge Runtime (supabase-edge-runtime)

  • Image: supabase/edge-runtime:v1.54.3
  • Functions Mount: ./supabase/functions mounted at /home/deno/functions.
  • Main Service: start --main-service /home/deno/functions/main.
  • Runtime Capabilities: Executes Deno/TypeScript serverless functions with direct access to Supabase DB, Gemini AI APIs, and third-party webhooks.

6. Admin Management Studio (supabase-studio)

  • Image: supabase/studio:2026.07.20-sha-74a0848
  • Accessible at: https://supabase-studio.planovi.app (protected by IP whitelist).
  • Backend Bridge: Connects to supabase-pg-meta (:8080) to provide interactive schema editing, SQL runners, table viewers, and user management.

🔄 Management & Inspection Commands

Terminal window
# Check status of all Supabase containers
docker compose ps | grep supabase
# Tail logs of the Supabase PostgreSQL database
docker logs -f --tail 100 supabase-db
# Tail logs of Deno Edge Functions
docker logs -f --tail 100 supabase-edge-runtime
# Restart Edge Runtime to reload new functions
docker restart supabase-edge-runtime