supabase/realtime
58.4
Adequate · 22 September 2026
36.7k
lines of production code
Elixir
primary language
6
measurements over time
What this system is
This system is a distributed, multi-tenant real-time event streaming service built on Elixir and Phoenix, designed to broadcast database changes, user presence, and custom messages to connected clients. It captures data modifications from PostgreSQL via logical replication and enforces Row Level Security to ensure tenants only receive authorized updates. The platform supports cross-region message routing, granular rate limiting, and comprehensive observability through Prometheus metrics and distributed tracing.
How it got here
2019–2022 — Realtime platform modernization and security hardening
37 changes.
This period focused on upgrading the core infrastructure to Phoenix 1.8 and Elixir 1.19, replacing legacy build tools with esbuild and Tailwind CSS, and implementing a runtime configuration model. It introduced comprehensive security measures, including strict JWT verification, AES-256-GCM encryption for credentials, and granular per-tenant rate limiting. The work also established a robust distributed monitoring system, added a new Postgres CDC RLS extension for change data capture, and rebuilt the developer-facing Inspector UI with LiveView.
2023–2025 — Realtime observability and tenant infrastructure
26 changes.
This period focused on building a comprehensive observability and tenant management infrastructure for the Realtime service, introducing detailed telemetry, PromEx monitoring, and a Live Dashboard for operational visibility. It established robust tenant authorization, Row Level Security enforcement, and a pluggable connection pipeline, while replacing the default PubSub with a GenRpc-based adapter for efficient cross-region routing. The work also included refactoring the core channel logic, implementing a Postgres logical replication adapter, and expanding test coverage to ensure reliability across distributed and region-aware operations.
2026 — distributed infrastructure and testing expansion
14 changes.
This period focused on establishing robust distributed primitives through the new Forum library and enhancing replication reliability with a Watchdog-based health monitoring system. Significant effort was dedicated to expanding test coverage across partitioned storage, channel authorization, and the Postgres CDC RLS extension, while also introducing comprehensive local development tooling and containerized environments.
Features
Add Realtime Extensions module for dynamic configuration retrieval
A new \Realtime.Extensions\ module has been introduced to manage extension settings. It provides a function to retrieve database-specific configuration (default values and required fields) by dynamically reading from the application environment, enabling the system to start extension supervisors based on these settings.
lib/extensions · high confidence
Add release scripts and example configuration for Realtime
The rel/overlays directory now includes shell and batch scripts (migrate, server) that invoke the 'realtime' executable, reflecting the project rename from Multiplayer to Realtime. An example configuration file (config.example.yml) is also added, defining default settings for the database connection (Postgres on localhost), cluster cookie, and service discovery (realtime-dns).
rel/overlays · high confidence
Added in-process caching for feature flags
An in-memory cache layer has been introduced for feature flags to reduce database load. This cache stores feature flag records and uses a sentinel value to handle 'not found' cases, preventing repeated database hits for missing flags. It also supports global updates and invalidations across cluster nodes to ensure consistency.
_lib/realtime/feature\flags · high confidence
Added static assets and relocated robots.txt
The application now includes a favicon (favicon.svg) and a Web Worker script (worker.js) in the static assets directory. The worker script listens for a 'start' event and sends periodic 'keepAlive' messages based on a provided interval. Additionally, the robots.txt file has been moved from the assets directory to the main priv/static directory, and its documentation link has been updated to the current HTTPS URL.
priv/static · high confidence
Initial devcontainer setup for local development
Developers can now open the project in VS Code Dev Containers to get an immediate, consistent development environment. The setup includes a Debian-based Dockerfile with Elixir/OTP, Node.js, and other tooling managed by mise, along with VS Code extensions for Elixir and Phoenix. It configures host networking for test database containers, uses named volumes for build artifacts to improve performance, and runs a post-create script to install dependencies and set up the workspace.
.devcontainer · high confidence
Inspector tool now supports connection configuration, event filtering, and message broadcasting
The Inspector tool has been rebuilt with a dedicated connection form that accepts host, project, channel, and token parameters, including support for JWT bearer tokens and user sign-in. Users can now filter and select specific database changes (schema, table, event types) and broadcast custom messages via a new message form. The event log component provides real-time visibility into transport, channel, and database events with pause/resume functionality, category filtering, and fuzzy search.
_lib/realtime\_web/live/inspector\live · high confidence
Introduce Forum library with Census and Muster primitives
The forum area now includes the Forum library, a distributed process-group toolkit for Elixir/OTP. It provides Forum.Census for eventually-consistent, low-overhead counting of group membership across the cluster, and Forum.Muster for precise, group-routed fan-out broadcast using consistent hashing to select a single router node per group. The library ships with a pluggable transport adapter (defaulting to Erlang distribution) and includes configuration, documentation, and formatter settings to support these capabilities.
forum · high confidence
Introduce GenCounter for efficient in-memory rate tracking
A new GenCounter module has been added to the realtime library to provide a lightweight, process-based counter backed by an ETS table. This component allows users to track rates and limits (such as channel join rates) using any Erlang term as a key, replacing the need for a separate GenServer process per counter. It supports atomic incrementing, retrieving current values, resetting counters, and deleting specific keys, offering a more efficient alternative to previous implementations that relied on heavier process-per-counter architectures.
_lib/realtime/gen\counter · high confidence
Introduce GenRpc-based PubSub adapter with regional broadcast routing
Added a new \Realtime.GenRpcPubSub\ adapter that replaces the default Phoenix.PubSub implementation, enabling cross-region message distribution via GenRpc. The adapter supports a feature-flagged \use\_muster\_broadcast\ mode that routes messages only to nodes holding specific tenant connections, reducing unnecessary network traffic compared to the previous region-wide flooding. It includes \RegionRings\ to maintain local copies of remote region membership for efficient routing decisions and \Worker\ processes to handle the actual message forwarding.
_lib/realtime/gen\rpc · high confidence
Introduce Postgres CDC RLS extension for database change subscriptions
This change adds the \lib/extensions/postgres\_cdc\_rls\ module, implementing a new Postgres Change Data Capture (CDC) extension that uses Row Level Security (RLS) to manage database change subscriptions. It introduces a \ReplicationPoller\ that polls the write-ahead log via temporary logical replication slots and a \SubscriptionManager\ that handles subscription lifecycle, OID changes, and region rebalancing. The extension integrates with the existing Realtime system by implementing the \Realtime.PostgresCdc\ behavior, allowing clients to subscribe to database events with filters, while ensuring proper cleanup of replication slots and handling distributed node coordination via GenRPC.
_lib/extensions/postgres\_cdc\rls · high confidence
Introduce Postgres logical replication adapter for real-time change data capture
Added a new Postgres adapter in lib/realtime/adapters that enables real-time replication of database changes via PostgreSQL's logical decoding (pgoutput) protocol. This includes a new protocol layer for parsing WAL messages (Write, KeepAlive), a decoder for logical replication messages (Begin, Commit, Insert, Update, Delete, Truncate, etc.), an OID database for mapping numeric type IDs to names, and structured change records (NewRecord, UpdatedRecord, DeletedRecord) that are JSON-encoded for downstream consumption.
lib/realtime/adapters · high confidence
Introduce Realtime API context and encryption infrastructure
This change introduces the \Realtime.Api\ context, providing CRUD operations for tenants (list, get, create, update, delete) with region-aware routing and cache invalidation. It also adds the \Realtime.Crypto\ module, which implements AES-256-GCM encryption for tenant database credentials (with a fallback to legacy AES-128-ECB) and a reconciler to migrate stored values to the stronger cipher. Additionally, it adds \Realtime.Database\ for handling tenant database connection setup and validation, \Realtime.FeatureFlags\ for managing per-tenant feature flags with rollout percentages, and \Realtime.Messages\ for persisting and replaying broadcast messages.
lib/realtime · high confidence
Introduce broadcast and presence authorization policy structures
Added new Elixir structs, BroadcastPolicies and PresencePolicies, to explicitly model authorization requirements for real-time message operations. BroadcastPolicies defines read, write, and persist permissions for topic-based broadcast messages, while PresencePolicies defines read and write permissions for presence tracking. These structures provide a standardized way to track whether specific authorization checks have been performed (indicated by nil values) for these distinct real-time communication types.
lib/realtime/tenants/authorization/policies · high confidence
Introduce dynamic RateCounter supervision with caching and idle shutdown
The realtime rate-limiting subsystem now uses a dedicated DynamicSupervisor to manage RateCounter processes, allowing them to be started on demand and automatically restarted if they become idle. Each counter caches its state via Cachex to persist across restarts and supports configurable idle shutdown timers (defaulting to 5 minutes, with support for :infinity) to prevent resource leaks. The implementation also integrates optional telemetry emission and configurable rate-limit logging, providing a more robust and observable foundation for tracking real-time event rates.
_lib/realtime/rate\counter · high confidence
Introduces strict linting, security scanning, and automated release tooling
This change adds configuration files that establish new development and operational standards for the project. It enables Credo in strict mode for Elixir code quality checks, configures SoboLow for security vulnerability scanning, and sets up .releaserc for automated semantic versioning and release notes via semantic-release. Additionally, it introduces a .dockerignore file to optimize Docker build contexts and a .dialyzer\_ignore.exs file to suppress known false positives from third-party type specs.
(repo-wide) · high confidence
New Live Dashboard pages for operational visibility and management
The Realtime Live Dashboard now includes several new pages to help operators inspect and manage the system: a Feature Flags page to create, toggle, and delete global flags and override them per tenant; a Muster page to view cluster health and perform group lookups; a Node Info page showing region and replica routing details; a SQL Inspector for running read-only queries with sensitive data masking; a Tenant Info page for detailed tenant configuration and runtime status; a Tenant Migrations page to inspect and apply schema drift using pg-delta; a Process Dump page to download process trees; and a Recon Trace page for function call tracing.
_lib/realtime\web/dashboard · high confidence
New Mix tasks for local Realtime development and debugging
Added two new CLI commands to improve the local development experience: \mix realtime.export\_tenant\_schema\ automatically provisions a temporary database, runs tenant migrations, and exports a normalized schema artifact to \priv/repo/tenant\_schema/\ for drift detection, while \mix realtime.gen\_token\ generates signed JWTs for authenticating local clients or the Inspector without external tools.
lib/mix · high confidence
New PromEx monitoring plugins for Realtime infrastructure and tenant metrics
This change introduces a suite of new PromEx plugins in the \lib/realtime/monitoring/prom\_ex/plugins/\ directory to expose detailed observability data for the Realtime service. The new plugins cover distributed Erlang metrics (node queue size, send/receive bytes), GenRPC performance, OS monitoring (RAM, CPU, load averages), and Phoenix socket/channel lifecycle events (connection counts, join durations, serializer info). It also adds specific tenant-focused metrics, including per-tenant and global connection counts, payload sizes, replication poller query durations and error counters, tenant migration durations and exception counts, and broadcast fanout delivery statistics. These plugins enable users to monitor cluster health, tenant-specific performance, and replication reliability via Prometheus.
_lib/realtime/monitoring/prom\ex · high confidence
New REST API endpoints for tenant management, broadcasting, and metrics
This change introduces a new set of REST controllers in the Realtime application to expose core functionality via HTTP. The \TenantController\ provides CRUD operations for managing tenants (create, read, update, delete, health checks) with OpenAPI specifications. The \BroadcastController\ and \BroadcastSingleController\ allow clients to send batch or single broadcast messages to Realtime channels, supporting both JSON and binary payloads with optional persistence and private channel authorization. Additionally, a \MetricsController\ exposes Prometheus metrics for the entire cluster or specific regions, a \PingController\ provides a simple health check, and the \PageController\ now includes a dedicated healthcheck endpoint. A \FallbackController\ is also added to standardize error responses across these new endpoints.
_lib/realtime\web/controllers · high confidence
New development tooling for local setup, benchmarking, and load testing
The \dev\ directory now consolidates local development utilities, including scripts to configure PostgreSQL for local Supabase compatibility, generate tenant database dumps, and replay tenant migrations. It also introduces benchmarking scripts to compare GenCounter and region-set cache performance, and a load test for the Status LiveView to monitor mailbox and memory usage under simulated cluster traffic.
dev · high confidence
New distributed monitoring and observability infrastructure
This change introduces a comprehensive set of new modules to \lib/realtime/monitoring\ that enhance system observability. It adds \Realtime.DistributedMetrics\ and \Realtime.GenRpcMetrics\ to gather and accurately aggregate Erlang distribution and gen\_rpc TCP socket statistics (including monotonic counters that survive socket resets) across cluster nodes. A new \Realtime.Latency\ GenServer periodically pings cluster nodes via gen\_rpc to measure and broadcast inter-node latency. System health is improved with \Realtime.ErlSysMon\ for logging critical BEAM system monitor events and \Realtime.OsMetrics\ for exposing CPU and RAM usage. The metrics backend is modernized with \Realtime.PromEx\ and \Realtime.TenantPromEx\ configurations, utilizing custom \Peep.Storage\ implementations (\Partitioned\ and \PartitionedTables\) for high-performance ETS-based metric storage with tag-based routing, and a custom \Realtime.Monitoring.Prometheus\ exporter for formatting metrics.
lib/realtime/monitoring · high confidence
New public cluster health status page
A new LiveView-based status page has been added to monitor Realtime cluster health, displaying inter-node latency across regions. The page features a region latency matrix, a sortable and filterable node list, and a detailed drill-down view for selected nodes showing incoming and outgoing pair latencies. It also highlights 'problem pairs' (slow, unreachable, or stale connections) and uses background broadcasts to update the UI in near real-time.
_lib/realtime\_web/live/status\live · high confidence
New request processing plugs for tenant assignment, authentication, rate limiting, and content validation
This change introduces a suite of new Plug components in lib/realtime\_web/plugs to handle core request lifecycle stages. AssignTenant extracts the tenant from the host header, initializes rate counters, and returns a 401 if the tenant is not found. AuthTenant validates JWT tokens (supporting both secrets and JWKS) and API keys, assigning claims and roles to the connection. RateLimiter enforces tenant-specific event rate limits, returning a 429 status when thresholds are exceeded. ValidateBroadcastContentType ensures broadcast endpoints only accept application/json or application/octet-stream. Additionally, BaggageRequestId propagates request IDs from OpenTelemetry baggage, and OctetStream parser support allows binary bodies to be parsed into conn.body\_params.
_lib/realtime\web/plugs · high confidence
New shared UI component library for LiveView
A new \RealtimeWeb.Components\ module has been introduced to provide a standardized set of reusable UI elements for the application's LiveViews. This includes semantic heading components (h1, h2, h3) with consistent branding, a versatile button component that supports primary/secondary/danger variants and can render as links or native buttons, and a modal dialog component with keyboard accessibility and customizable confirmation/cancellation actions. These components centralize styling and behavior, ensuring visual consistency across the interface.
_lib/realtime\web/live · high confidence
New telemetry logging infrastructure for Realtime
Added a new telemetry logging system in lib/realtime/telemetry that captures and logs key operational events. This includes logging tenant migration status (start, stop, exceptions, and reconciliation mismatches), HTTP request paths and response codes (including error details for 5xx and 4xx responses), and billing metrics. The implementation introduces a GenServer-based logger that subscribes to specific telemetry events and a helper module for dispatching telemetry data, enabling better observability into tenant migrations and API performance.
lib/realtime/telemetry · high confidence
New tenant authorization and broadcast infrastructure
The \lib/realtime/tenants\ directory now includes a complete authorization system (\Realtime.Tenants.Authorization\) that validates read and write access against RLS policies, supporting remote RPC calls for distributed nodes. A new \Realtime.Tenants.BatchBroadcast\ module handles message broadcasting with rate limiting, payload size validation, and policy checks for public and private channels. Tenant data is now cached locally and across nodes via \Realtime.Tenants.Cache\ using Cachex. Connection management is centralized in \Realtime.Tenants.Connect\, which handles database connections, region awareness, and migration execution. Replication is managed by \Realtime.Tenants.ReplicationConnection\ with a watchdog for health checks. Maintenance tasks like message cleanup and partition creation are handled by the \Realtime.Tenants.Janitor\. Database migrations are versioned and executed via \Realtime.Tenants.Migrations\. Additional modules include \Realtime.Tenants.EncryptionReconciler\ for migrating secrets to AES-256-GCM, \Realtime.Tenants.Rebalancer\ for region-aware node placement, and \Realtime.Tenants.Reconnector\ to ensure persistent connections for active tenants.
lib/realtime/tenants · high confidence
Realtime WebSocket authentication and channel infrastructure overhaul
The Realtime WebSocket connection flow has been restructured to enforce stricter authentication and rate limiting. \UserSocket\ now validates JWT tokens (including JWKS support) and API keys during the connect phase, rejecting connections with specific HTTP status codes (401, 403, 404, 429) for errors like expired tokens, suspended tenants, or rate limit breaches. A new \TenantRateLimiters\ module enforces per-tenant limits on concurrent users and join rates. Additionally, a new \RealtimeWeb.Presence\ module has been added to enable presence tracking capabilities within the Realtime channels.
_lib/realtime\web/channels · high confidence
Realtime subscription filtering and Row Level Security (RLS) enforcement
The \realtime\ schema now supports filtering database change notifications by specific column values and enforces Row Level Security (RLS) to ensure users only receive updates for records they are authorized to view. This is achieved through new database types (\realtime.equality\_op\, \realtime.user\_defined\_filter\, \realtime.wal\_column\) and functions (\realtime.apply\_rls\, \realtime.subscription\_check\_filters\) that validate filter syntax, check column privileges for the authenticated role, and apply RLS policies against the incoming WAL (Write-Ahead Log) data before broadcasting events to subscribers.
lib/realtime/tenants/repo · high confidence
ReplicationConnection health monitoring via Watchdog
A new Watchdog process has been introduced to monitor the health of ReplicationConnection instances. It performs periodic health checks; if the connection times out, the watchdog terminates it to trigger a restart. Additionally, it verifies that the replication slot is active and checks for excessive WAL lag (stopping the connection if lag exceeds 50% of the configured limit), ensuring that silent slot failures or high lag do not go unnoticed.
_lib/realtime/tenants/replication\connection · high confidence
Support for user broadcast metadata and binary payloads in Realtime V2
The Realtime V2 serializer now supports user broadcast messages that include optional metadata and binary payloads. A new \UserBroadcast\ struct defines the message format, allowing metadata to be passed as a JSON-encoded map alongside the payload. The \V2Serializer\ handles these messages by framing them into a specific binary protocol (distinguished by a new opcode) for efficient transmission, while maintaining backward compatibility with standard JSON broadcasts and replies. This enables clients to receive richer, structured data in user-initiated broadcast events.
_lib/realtime\web/socket · high confidence
Removals
Removal of default Phoenix welcome page template
The default Phoenix application welcome page template (lib/realtime\_web/templates/page/index.html.eex) has been removed. This action eliminates the standard landing page that previously displayed framework resources, documentation links, and community help information, indicating a shift away from the initial scaffolding content.
_lib/realtime\web/templates/page · high confidence
Architecture
RealtimeChannel refactored into modular components
The RealtimeChannel implementation has been restructured into distinct modules to improve maintainability and performance. A new \Assigns\ module centralizes socket state, while \BroadcastHandler\, \PresenceHandler\, and \MessageDispatcher\ now handle their respective features with dedicated logic. The \MessageDispatcher\ introduces a caching mechanism for encoded messages to optimize fan-out, and the \Logging\ module adds structured error codes and telemetry. Additionally, a \Tracker\ module monitors open channels to automatically clean up idle transport processes.
_lib/realtime\_web/channels/realtime\channel · high confidence
Refactor tenant connection logic into a pluggable pipeline
The tenant connection process has been restructured into a modular pipeline using a new \Piper\ behavior. This change introduces distinct steps for retrieving tenant data (\GetTenant\), validating database connectivity (\CheckConnection\), reconciling migration states (\ReconcileMigrations\), and registering the connection process (\RegisterProcess\). This architecture allows for more resilient and observable connection handling, including specific logic to handle migration counter discrepancies and DB connection monitoring.
lib/realtime/tenants/connect · high confidence
Behavioural changes
Assets build system migrated to Tailwind and esbuild with new inspector capabilities
The assets pipeline has been refactored to replace the legacy Webpack and Babel setup with Tailwind CSS for styling and esbuild for JavaScript bundling. This change introduces a new fuzzy-search filter for the Realtime Inspector's event log, allowing users to quickly locate specific messages. It also adds a topbar loading indicator for better visual feedback during network activity and implements automatic redaction of sensitive credentials (API keys and JWTs) in inspector logs to improve security. Additionally, the configuration now includes dedicated formatters (oxfmt, oxlint) and a comprehensive Tailwind theme with custom brand colors and Heroicons support.
assets · high confidence
New JWT verification and channel authorization logic
The channel authorization flow now uses dedicated modules (\RealtimeWeb.ChannelsAuthorization\ and \RealtimeWeb.JwtVerification\) to validate JWTs. This implementation enforces the presence of \role\ and \exp\ claims, explicitly validates that \exp\ and \iat\ are numeric (rounding decimals to integers to prevent type errors), and supports signature verification via HS256/384/512, RS256/384/512, ES256/384/512, and EdDSA (RFC 8037) algorithms using JWKs or a shared secret. Expired tokens now return a specific error tuple with a message indicating how many seconds ago the token expired.
_lib/realtime\web/channels/auth · high confidence
Realtime API schema and configuration overhaul
The Realtime API data models have been restructured to support granular tenant configuration, new extension settings, and message persistence. The Tenant schema now includes explicit rate-limiting fields (max\_joins\_per\_second, max\_bytes\_per\_second, max\_channels\_per\_client) and a broadcast\_adapter enum defaulting to gen\_rpc. A new Extensions schema allows per-tenant configuration storage with encrypted settings, while a FeatureFlag schema introduces global flags with rollout percentages and bucket-based targeting. The Message schema has been updated to use UUIDs, support binary payloads, and distinguish between broadcast, presence, and persistence extensions.
lib/realtime/api · high confidence
Realtime Web layer upgraded to Phoenix 1.7 with OpenAPI specs and enhanced WebSocket handling
The \lib/realtime\_web\ module has been refactored to support Phoenix 1.7, introducing a new \RealtimeWeb.Socket\ macro that manages heap sizes, traffic telemetry, and error handling for WebSocket connections. Long-polling is now enabled alongside WebSockets, and the endpoint configures specific serializers (V1 and V2 JSON) and performance tuning (active\_n, fullsweep\_after). An OpenAPI specification (\RealtimeWeb.ApiSpec\) and detailed schemas (\RealtimeWeb.OpenApiSchemas\) have been added to document the API, including tenant and broadcast parameters. The router has been restructured with dedicated pipelines for API authentication, tenant assignment, rate limiting, and CORS, exposing new endpoints for health checks, metrics, and broadcast operations. Additionally, the \Gettext\ module was updated to use the \Gettext.Backend\ macro, and the \Endpoint\ now includes a \BaggageRequestId\ plug and conditional healthcheck logging.
_lib/realtime\web · high confidence
Realtime tenant schema exported as auto-generated SQL files
The \priv/repo/tenant\_schema\ directory now contains the complete Realtime tenant schema as a set of auto-generated SQL files (schema, tables, types, and functions), managed by the \mix realtime.export\_tenant\_schema\ task. This includes the \realtime\ schema, the \messages\ and \subscription\ tables, custom types like \equality\_op\ and \user\_defined\_filter\, and functions such as \apply\_rls\ and \broadcast\_changes\. A \.pgdelta-export.json\ manifest defines the load order and scope, ensuring the schema is consistently versioned and applied.
_priv/repo/tenant\schema · high confidence
Redesigned UI with dark mode support and Supabase branding
The layout templates have been completely rewritten to replace the default Phoenix scaffolding with a custom Supabase Realtime interface. The new design features the Supabase logo, a navigation bar with links to the Inspector, Status, and documentation, and a footer displaying the application version, node ID, and region. A key behavioral change is the addition of dark mode support, which respects the user's system preference and includes a toggle button in the header. The layout now uses Tailwind CSS classes for styling and integrates with LiveView for dynamic content rendering.
_lib/realtime\web/templates/layout · high confidence
Refactored tenant seeding and added Postgres 17 support
The seeding process for the realtime tenant has been restructured to improve reliability and environment handling. The main seed script now explicitly deletes and recreates the tenant to ensure a clean state, supports overriding the tenant name via the SELF\_HOST\_TENANT\_NAME environment variable, and enforces SSL settings based on DB\_SSL. A new dev\_seeds.exs script provides a safer, idempotent setup for development environments that preserves existing data. Additionally, the repository now includes a pgdelta\_profile.json to manage database schema changes and grants, and adds a pre-migration seed script to create the realtime schema. Tenant database dumps are now provided for both Postgres 15 and 17, ensuring compatibility with newer database versions.
priv/repo · high confidence
Runtime configuration migration and expanded environment variable support
The application has migrated from static compile-time configuration files to a runtime configuration model via a new \config/runtime.exs\, replacing the previous \config/prod.secret.exs\ and \config/prod.exs\ patterns. This change allows sensitive settings and environment-specific values to be loaded at startup, significantly expanding the number of configurable environment variables for database connections (including SSL, replicas, and IP version), logging (Logflare backend, metadata fields), metrics (PromEx, pusher settings), and Realtime-specific behaviors (presence, janitor tasks, gen-rpc, and muster shutdown). Additionally, the logger metadata has been enriched with fields like \:project\, \:external\_id\, and \:error\_code\ across all environments, and the build tooling has switched from Webpack to esbuild and Tailwind CSS.
config · high confidence
Tenant schema evolution and rate-limit defaults update
The tenant database schema has been significantly expanded to support granular rate limiting, new authentication methods, and feature flagging. New columns include \max\_bytes\_per\_second\, \max\_channels\_per\_client\, \max\_joins\_per\_second\, \max\_presence\_events\_per\_second\, and \max\_client\_presence\_events\_per\_window\ to control traffic, alongside \presence\_enabled\, \private\_only\, and \suspend\ flags for tenant management. Authentication is now supported via \jwt\_jwks\ (JWKS) in addition to the existing \jwt\_secret\, with a constraint ensuring one is present. The default broadcast adapter has shifted from \phoenix\ to \gen\_rpc\, and the default \max\_events\_per\_second\ has been lowered from 10,000 to 1,000. Additionally, a new \feature\_flags\ table and a \feature\_flags\ map on tenants enable per-tenant feature toggles with rollout percentages.
priv/repo/migrations · high confidence
Upgrade to Phoenix 1.8 compatibility and modernize web stack
The library has been updated to support Phoenix 1.8, replacing the deprecated \:namespace\ option in controllers with explicit \formats\ and \layouts\ configurations. This change introduces support for Phoenix LiveView and LiveComponents, adding dedicated macros to integrate these features into the application. Additionally, the web module now includes verified routes for static assets (such as \worker.js\ and fonts), and channel logging for joins and message handling is explicitly disabled by default to reduce log noise.
lib · high confidence
Fixes
Add tenant view with password sanitization and improve error handling
This change introduces a new TenantView to expose tenant details via JSON, specifically stripping the 'db\_password' from extension settings in the 'show' response to prevent sensitive data leakage. It also adds a ChangesetView to standardize changeset error translation for API responses. Additionally, the error handling is refined by updating error helpers to use Bootstrap-compatible 'invalid-feedback' classes for form validation and simplifying the ErrorView to return custom error messages in JSON format.
_lib/realtime\web/views · high confidence
Enhanced node discovery and memory management for distributed deployments
The release environment scripts now automatically detect the node's IP address and name for Fly.io, AWS ECS Fargate, and Kubernetes environments, ensuring reliable clustering without manual configuration. Additionally, the VM arguments have been updated to increase the distribution buffer busy limit to 100,000 kilobytes and disable busy wait, while setting a process heap limit to improve stability under load.
rel · high confidence
Structured validation for Realtime channel join payloads
The join payload handling now uses dedicated Ecto schemas to strictly validate and normalize client input. A new FlexibleBoolean type ensures boolean fields (such as ack, self, replication\_ready, private, and wait) correctly accept both native booleans and string representations like "true"/"false". The Config schema normalizes nil postgres\_changes arrays into empty lists and validates nested structures for Broadcast (including replay limits), Presence, and PostgresChangesOptions (including wait timeouts). This ensures that malformed or inconsistent join parameters are rejected early with clear error messages before reaching the channel logic.
_lib/realtime\web/channels/payloads · high confidence
Test coverage
Added WALRUS regression test suite for Postgres Changes; Added comment to LayoutView test file; Added comprehensive test coverage for Realtime core components; Added comprehensive test coverage for Realtime tenant subsystems; Added comprehensive test suite for Postgres CDC RLS extension; Added integration tests for Realtime channel authorization, billing, and connectivity; Added test coverage for PromEx monitoring plugins; Added test coverage for RealtimeChannel broadcast, logging, and presence handlers; Added test coverage for realtime monitoring components; Added test coverage for realtime web plugs; Added test coverage for the admin dashboard feature flags, muster, tenant info, and tenant migrations pages; Added tests for API JWT secret rotation and updated test infrastructure; Added tests for GenCounter module; Added tests for Inspector and Status LiveView components; Added tests for PartitionedTables and Partitioned storage backends; Added tests for Realtime channel replication readiness and socket error handling; Added tests for RealtimeWeb endpoint logging, socket telemetry, and tenant broadcaster; Added tests for RegionRings and Worker components in GenRpcPubSub; Added tests for ReplicationConnection watchdog health checks and slot lag monitoring; Added tests for channel authorization and JWT verification; Added tests for join payload validation and flexible boolean casting; Added tests for tenant connect components; Added tests for the Realtime Janitor maintenance task; Added tests for the Realtime Telemetry Logger; Added tests for the V2 serializer and user broadcast metadata handling; Added unit tests for the Realtime RateCounter module; Comprehensive test infrastructure overhaul for reliability and isolation; Expanded integration test coverage for distributed Realtime and region-aware operations; New Bun-based Realtime E2E test CLI with parallel execution and OpenTelemetry tracing; Refactored test tenant database infrastructure with Docker and external backends.
Dependencies
Introduces the Forum sub-application and upgrades core dependencies
This change adds a new \forum\ sub-application (defined in \forum/mix.exs\) to the project, establishing it as a dependency for the main Realtime application. It also performs a major dependency upgrade across the Elixir and JavaScript stacks: the main application is upgraded to Elixir 1.19 and Phoenix 1.8 (via a custom fork), while the assets directory switches from a Webpack/Babel build to \oxlint\/\oxfmt\ and updates \@supabase/realtime-js\ to v2.114.0. Additionally, the main \mix.exs\ configures a 7-day Hex dependency cooldown and adds several new libraries including \prom\_ex\, \opentelemetry\, and \gen\_rpc\.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 63 → 58 (-4.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 87 → 66 (-20.2)
- Architecture 97 → 80 (-17.6)
- Maturity 70 → 76 (+6.2)
- Readiness 57 → 57 (-0.1)
- Security 58 → 60 (+2.0)
- Accessibility 55 (new)
Resolved (36)
- Boundary-crossing change coupling: runtime.exs ↔ gen_rpc.ex (config/runtime.exs)
- Change coupling clique: authorization.ex, broadcast_policies.ex, presence_policies.ex (lib/realtime/tenants/authorization.ex)
- Change coupling: message.ex ↔ migrations.ex (lib/realtime/api/message.ex)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (12 lines × 2) (lib/realtime_web/live/inspector_live/conn_component.ex)
- Duplicated block (13 lines × 2) (lib/realtime/tenants/authorization.ex)
- Duplicated block (13 lines × 2) (lib/realtime_web/channels/realtime_channel.ex)
- Duplicated block (15 lines × 2) (lib/realtime/adapters/postgres/oid_database.ex)
- Duplicated block (16 lines × 2) (lib/realtime/adapters/postgres/oid_database.ex)
- Duplicated block (19 lines × 2) (forum/lib/forum/muster/shard.ex)
- Duplicated block (19 lines × 2) (lib/realtime/monitoring/peep/partitioned.ex)
- Duplicated block (43 lines × 2) (lib/realtime/tenants/repo/migrations/20260707120000_restrict_realtime_schema.ex)
- Duplicated block (5 lines × 2) (lib/realtime/monitoring/prom_ex/plugins/distributed.ex)
- Further sole-owners (lower concentration)
- High IaC: DS-0002 (Dockerfile)
- High IaC: DS-0029 (Dockerfile)
- Hotspot: test/e2e/realtime-check.ts (test/e2e/realtime-check.ts)
- LLM evaluation failed
- Leaked secret: high-entropy-secret (bench/secrets.exs)
- …and 16 more
New (107)
- Change coupling: metrics_controller.ex ↔ router.ex (lib/realtime_web/controllers/metrics_controller.ex)
- Change coupling: tenants.ex ↔ rpc.ex (lib/realtime/monitoring/prom_ex/plugins/tenants.ex)
- Change-coupling hub: mix.exs → dev.exs, prod.exs, runtime.exs, test.exs, message.ex, gen_rpc.ex, pub_sub.ex, helpers.ex, metrics_cleaner.ex, latency.ex, tenant.ex, tenants.ex, repo.ex, rpc.ex, batch_broadcast.ex, cache.ex, connect.ex, janitor.ex, migrations.ex, replication_connection.ex, channels_authorization.ex, broadcast_handler.ex, logging.ex, message_dispatcher.ex, presence_handler.ex, broadcast_controller.ex, fallback_controller.ex, open_api_schemas.ex, assign_tenant.ex, auth_tenant.ex, tenant_broadcaster.ex, seeds.exs (mix.exs)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (13 lines × 2) (lib/realtime/tenants/authorization.ex)
- Duplicated block (15 lines × 2) (lib/realtime/adapters/postgres/oid_database.ex)
- Duplicated block (18–19 lines × 2) (forum/lib/forum/census.ex)
- Duplicated block (19 lines × 2) (lib/realtime_web/channels/realtime_channel.ex)
- Duplicated block (24–25 lines × 2) (lib/realtime/monitoring/peep/partitioned.ex)
- Duplicated block (29–38 lines × 2) (forum/lib/forum/muster/shard.ex)
- Duplicated block (43 lines × 2) (lib/realtime/tenants/repo/migrations/20260707120000_restrict_realtime_schema.ex)
- Duplicated block (5 lines × 2) (lib/realtime/feature_flags/cache.ex)
- Duplicated block (5 lines × 2) (lib/realtime/monitoring/prom_ex/plugins/distributed.ex)
- Duplicated block (5 lines × 2) (lib/realtime/monitoring/prom_ex/plugins/distributed.ex)
- Duplicated block (5 lines × 2) (lib/realtime_web/channels/auth/jwt_verification.ex)
- Duplicated block (90 lines × 3) (lib/realtime/tenants/repo/migrations/20241030150047_messages_partitioning.ex)
- Edited copy of a member (10 corresponding lines) (lib/realtime/monitoring/prom_ex/plugins/distributed.ex)
- FixmeComment (test/integration/tests.ts)
- High IaC: DS-0029 (Dockerfile)
- High IaC: DS-0029 (Dockerfile)
- …and 87 more
Changes since last survey
- 215 commits — 139 feature/other, 76 fixes
By area
- (root) — 116 commits
- lib/realtime — 22 commits
- lib/realtime_web — 15 commits
- test/realtime — 12 commits
- .github/workflows — 9 commits
- test/e2e — 8 commits
- test/integration — 8 commits
- priv/repo — 5 commits
- test/support — 4 commits
- .github/dependabot.yml — 2 commits
- .github/scripts — 2 commits
- forum/lib — 2 commits
- lib/extensions — 2 commits
- test/realtime_web — 2 commits
- assets/js — 1 commit
- config/dev.exs — 1 commit
- config/test.exs — 1 commit
- dev/bench — 1 commit
- test/extensions — 1 commit
- test/walrus — 1 commit
Notable commits
- fix: # chore: fix flaky bad_tcp test (#2125)
- fix: Fix: snabkaffex inclusion in root mix.lock (#2107)
- fix: chore(lint): Switch to credo strict mode, fix violations (#2200)
- fix: chore(tests): Attempt to fix flaky Node regions test (#2199)
- fix: chore(tests): Fix some more flakies (#2227)
- fix: chore: Fix metrics pusher flaky test (#2137)
- fix: chore: Fix tenant controller flaky spec (#2124)
- fix: chore: add regression test for column restriction (#2074)
- fix: chore: fix flaky integration presence test (#2180)
- fix: chore: fix flaky jwt test (#2138)
- fix: chore: fix flaky test distribution (#2256)
- fix: chore: fix flaky tests (#2102)
- fix: chore: fix flaky user counter tests (#2182)
- fix: chore: fix flaky wal bloat test (#2127)
- fix: ci: fix nix portable build (#2171)
- fix: fix(auth): accept the RFC 8037 EdDSA alg for OKP keys (#2060)
- fix: fix(auth): return 401 on a malformed authorization header (#2245)
- fix: fix(dashboard): close tenant version connection (#2242)
- fix: fix(deps): bump gettext from 0.26.2 to 1.0.2 (#2147)
- fix: fix(deps): bump joken from 2.6.2 to 2.7.0 (#2205)
- …and 195 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
supabase/realtime was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 8c7a4da065982be9938e01844dac845f7226e718 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.