Skip to content

Supabase and CNPG

Assembly owns self-hosted Supabase component topology and operations. Backend owns SQL migrations, schema, constraints, functions, RLS, grants, and migration replay.

One central Supabase API plane uses the managed CloudNativePG cluster. Projects receive scoped schemas or assets, not per-project databases. Component images require immutable digests before release. Secrets remain OpenBao references. Backup, restore, upgrade, rollback, and health evidence are recorded against assembly pins.

The deployment mechanism and version-specific traps are recorded in Supabase on Kubernetes. The Helm chart stays upstream-owned; CNPG, External Secrets, object storage, and ingress remain separate native platform responsibilities.