platform.engineering/supabaseofficialv0.1.0stableresource

Supabase resource plugin for formae

installation
$formae plugin install supabase
changelog as of v0.1.0 · structured per keep a changelog
unreleased
Changed
  • BREAKING: SUPABASE::Functions::Secret (one resource per secret name) is replaced by SUPABASE::Functions::Secrets — one bag resource per project holding a values name→value map, identified by $.projectRef. The Supabase API exposes only a bulk secrets endpoint with no per-secret operation; the old per-name model issued concurrent single-item writes that raced on the shared bag (read-modify-write, last writer wins) and silently dropped secrets during a multi-secret apply. The bag model makes every mutation a single atomic bulk call. Removing a key from values deletes that secret on reconcile.
v0.1.02026-05-26stableinstalled default
Added
  • SUPABASE::Platform::Project — async create / read / update / delete / list, polls until ACTIVE_HEALTHY.

  • SUPABASE::Platform::Branch — async create on existing project, polls until FUNCTIONS_DEPLOYED / MIGRATIONS_PASSED. Paid plan only.

  • SUPABASE::Platform::Organization — POST/GET only (API limit).

  • SUPABASE::Auth::APIKey — publishable + secret keys, JWT template support, ?reveal=true integration, APIKeyResolvable for same-plugin DAGs.

  • SUPABASE::Functions::EdgeFunction — inline JS/TS body deploy.

  • SUPABASE::Functions::Secret — bulk-endpoint bridge, one Forma resource per secret name.

  • SUPABASE::Config::AuthSettings — full Auth config singleton (/v1/projects/{ref}/config/auth).

  • SUPABASE::Config::APISettings — PostgREST singleton (/v1/projects/{ref}/postgrest).

  • SUPABASE::Config::DatabaseSettings — Postgres singleton (/v1/projects/{ref}/config/database/postgres, uses PUT).

  • SUPABASE::Config::NetworkRestriction — CIDR allowlist singleton.

  • Per-namespace subpackages (pkg/resources/{platform,auth,functions,config}), self-registration via init(), slim main dispatcher modelled on the K8s plugin.

  • Minimal HTTP transport (pkg/transport/supabase) — Bearer auth, rate-limit ready, error classification including the 406 Supabase returns on deleted API keys.

  • 41 unit tests (httptest-driven).

  • 23 conformance fixtures (testdata/*.pkl) — Create + Update + Replace variants per resource where applicable.

  • scripts/ci/clean-environment.sh — live cleanup hook for conformance test residue.

  • examples/basic/ — single Edge Function forma.

  • examples/k8s-supabase/ — cross-plugin demo running a real Next.js Supabase Starter Kit in a kind cluster, end-to-end verified against live Supabase Auth /settings.

type
resource
category
data
license
FSL-1.1-ALv2
originator
platform.engineering
namespace
SUPABASE
latest
v0.1.0 · stable
platforms
repo
github.com/platform-engineering-labs/formae-plugin-supabase
versions (1)
select a version to jump to its notes
v0.1.0stable
2026-06-19