Skip to content
CAI
Software that uses CAICheck a score

supabase/supavisor

55.6

Adequate · 22 September 2026

16.5k

lines of production code

Elixir

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Supavisor is a PostgreSQL proxy built in Elixir and Rust that manages database connections through pooling, tenant isolation, and multiple authentication methods including SCRAM and Just-In-Time access. It provides resilience features such as circuit breakers, read-replica support, and SSL/TLS enforcement, while offering a web API for cluster and tenant management alongside Prometheus metrics. The system supports distributed clustering via Postgres and is designed for high-concurrency deployments with hot-upgrade capabilities.

How it got here

2023 — Initial project scaffolding and core proxy implementation

25 changes.

This period established the foundational structure of the Supavisor project, including development tooling, configuration, and database schema migrations. It introduced the core PostgreSQL proxy logic with connection pooling, SCRAM authentication, and circuit breaker protection, alongside a Phoenix-based web API for cluster and tenant management. The work also included comprehensive test suites, native Rust parsing capabilities, and deployment configurations for Fly.io and systemd.

2024–2026 — JIT authentication and test infrastructure expansion

12 changes.

This period focused on implementing Just-In-Time (JIT) database authentication with PAM integration and establishing the necessary test infrastructure, including certificate generation and development setup scripts. Significant effort was also directed toward expanding test coverage across the protocol layer, client handlers, monitoring plugins, and prepared statement storage strategies to ensure robustness.

Features

Add JSON API view templates for cluster, tenant, and user resources

New view modules (ChangesetView, ClusterTenantsView, ClusterView, TenantView, UserView, ErrorView, ErrorHelpers) have been added to the web layer to handle JSON serialization for API responses. These views define how cluster, tenant, user, and network ban data is structured in JSON output, including support for error translation and specific endpoints like connection termination results.

_lib/supavisor\web/views · high confidence

Add Postgres-based clustering strategy

Introduces a new clustering strategy that uses Postgres LISTEN/NOTIFY to determine cluster topology. Nodes broadcast heartbeats to a shared channel, allowing other nodes to discover and connect to them. The strategy requires a database URL and supports optional configuration for heartbeat intervals and channel names.

lib/cluster · high confidence

Added Fail2ban filter for Supavisor logs

A new Fail2ban filter configuration file has been added to detect and ban clients based on Supavisor error logs, specifically targeting 'Exchange error' and 'User not found' messages.

contrib · high confidence

Added Nix package definition for Supavisor

A new Nix package definition (nix/package.nix) has been added to the project, enabling users to build and install Supavisor using the Nix package manager. The package configures the build environment to handle both Elixir dependencies (via mix) and native Rust components (via cargo), including specific build inputs for macOS systems such as libiconv and various Apple frameworks.

nix · high confidence

Added PostgreSQL setup scripts and authentication configurations for development

The development environment now includes a SQL setup script that initializes standard roles (anon, authenticated, service\_role) with appropriate schema permissions and creates the \_supavisor schema. Additionally, two PostgreSQL client authentication configuration files (pg\_hba.conf) are provided for MD5 and cleartext password authentication modes, allowing developers to configure local and external connection security policies for the database.

dev · high confidence

Added database seeding scripts for development and testing

The \priv/repo\ directory now includes \seeds.exs\, \seeds\_before\_migration.exs\, and \seeds\_after\_migration.exs\ to automate the population of the database. These scripts create a \\_supavisor\ schema and pre-configure multiple tenants with various user profiles, pool sizes, connection modes (transaction and session), and feature flags (such as named prepared statements), providing a standardized environment for local development and integration testing.

priv/repo · high confidence

Added deployment configurations for Fly.io and systemd

Users can now deploy the application using Fly.io or standard systemd services. A new Fly.io configuration file (fly.toml) defines the app as 'supavisor-staging', sets up HTTP/HTTPS listeners on ports 80 and 443, and exposes a TCP service on port 7654 with a concurrency limit of 16384 connections. Additionally, systemd support is provided via a service unit file (supavisor.service) and an environment variables template (service\_vars.ini), allowing the application to be managed as a system service with automatic restarts.

deploy · high confidence

Added release scripts for database migrations and server startup

The rel/overlays directory now includes shell and batch scripts (migrate, migrate.bat, server, server.bat) to facilitate running database migrations via the Supavisor.Release.migrate module and starting the application server with the PHX\_SERVER environment variable enabled.

rel/overlays · high confidence

Initial application configuration structure

The application now includes a standard set of configuration files (config.exs, dev.exs, prod.exs, runtime.exs, test.exs) to manage environment-specific settings. This structure introduces runtime configuration for cluster topology via libcluster (supporting DNSPoll, Epmd, and Postgres strategies), enables configurable metrics pushing to remote endpoints, and sets up SSL/TLS handling for upstream and downstream connections using environment variables for certificate paths. It also configures the Ecto repository, Phoenix endpoint, and logging metadata for development, production, and test environments.

config · high confidence

Initial project scaffolding and development tooling configuration

This change introduces the foundational configuration files for the Supavisor project, establishing the development environment and build standards. It includes the Elixir formatter settings, Credo linting rules, and Sobelow security scanner configuration. It also defines the specific toolchain versions for Erlang (27.3.4.16), Elixir (1.18.5), and Rust (1.84.1) via \.tool-versions\, alongside a Dockerfile and Makefile to standardize local development, testing, and containerized releases.

(repo-wide) · high confidence

Initial release of Supavisor core library and web interface

This change introduces the initial codebase for Supavisor, a PostgreSQL proxy. The \lib/supavisor.ex\ module establishes the core proxy logic, including connection pooling, tenant management, and support for transaction, session, and native modes. It also adds a \lib/supavisor\_web.ex\ entry point that configures the Phoenix-based web interface for controllers, views, routers, and channels.

lib · high confidence

Initial release of the native PostgreSQL parser library

The native/pgparser module has been introduced, providing a Rust-based library that exposes PostgreSQL query parsing capabilities to the host application via Rustler. This change adds a new \statement\_types\ NIF, allowing users to identify the types of SQL statements (e.g., SELECT, INSERT) within a given query string, effectively establishing the foundational parsing logic for the parser component.

native/pgparser · high confidence

Initial web interface and API specification

This change introduces the foundational web layer for Supavisor, establishing a Phoenix-based HTTP server with a structured API. It includes an OpenAPI specification (generated via OpenApiSpex) that documents Tenant and User schemas, along with a Swagger UI endpoint for interactive documentation. The router defines RESTful endpoints for managing tenants (CRUD, termination, credential updates, network bans) and clusters, as well as a metrics endpoint. Additionally, it implements a WebSocket proxy at /v2 to tunnel TCP traffic to the local database proxy, and configures telemetry for monitoring Phoenix, database, and VM metrics.

_lib/supavisor\web · high confidence

Introduce JIT authentication infrastructure with PAM integration and test services

This change adds the foundational components for Just-In-Time (JIT) database authentication. It introduces a PAM module (\pam\_jit\_pg.so\) built via a dedicated Dockerfile, configured to delegate authentication to a new Python-based API service (\jit\_api\_service\) via \pam.d/postgresql\. The PostgreSQL container is updated to enforce SSL connections using generated test certificates and utilizes PAM for authentication in \pg\_hba.conf\. Additionally, a mock API server is included to simulate authentication responses for testing purposes.

priv/jit · high confidence

New API endpoints for cluster management and metrics

The web API now includes controllers for managing database clusters and their associated tenants, as well as exposing Prometheus metrics. Users can create, read, update, and delete clusters via the new \ClusterController\, and manage cluster-tenant mappings via \ClusterTenantsController\. Additionally, a \MetricsController\ exposes cluster-wide and per-tenant metrics at \/metrics\ and \/metrics/:external\_id\, with configurable process tuning for the metrics handler.

_lib/supavisor\web/controllers · high confidence

New mix tasks for generating release upgrade artifacts

Added two new Mix tasks, \supavisor.gen.appup\ and \supavisor.gen.relup\, to the \lib/tasks\ directory. These tasks allow users to manually generate \appup\ and \relup\ files required for hot code upgrades by specifying source and target versions, supporting the generation of soft upgrade tarballs and manual appup workflows.

lib/tasks · high confidence

New scripts for test certificate generation, JIT development setup, and upgrade testing

Added three new shell scripts to the project: \scripts/gen-test-certs.sh\ generates test CA and server certificates (RSA and ECDSA) for local testing; \scripts/jit\_dev\_setup.sh\ automates the setup of a JIT development environment by generating certificates, starting Docker services, configuring downstream certs, and creating a test tenant; and \scripts/test\_upgrade.sh\ facilitates manual hot-upgrade testing between versions by building releases, starting the old version, and performing the upgrade to the current branch.

scripts · high confidence

Supavisor proxy core with SCRAM authentication and circuit breaker protection

The lib/supavisor directory now contains the core proxy implementation, including the Application supervisor, ClientHandler for managing incoming PostgreSQL connections, and a dedicated AuthQuery module for fetching user secrets from upstream databases. Authentication is handled via a new ClientAuthentication system that supports SCRAM-SHA-256, cleartext password, and Just-In-Time (JIT) access methods, with secrets cached in Cachex and rate-limited refreshes. To improve resilience, a CircuitBreaker module with an atomic sliding-window counter and a Janitor process protects pool operations from cascading failures by temporarily blocking connections when thresholds are exceeded.

lib/supavisor · high confidence

Behavioural changes

Added hot-upgrade instructions for Supavisor v2.9.5, v2.9.6, and v2.9.7

This change adds the necessary \appup\ files to support seamless hot-upgrades from version 2.9.0 (and rc.4) to versions 2.9.5, 2.9.6, and 2.9.7. These upgrade scripts define the module loading, purging, and state migration steps required to safely transition the system, including handling changes to the \DbHandler\, \ClientHandler\, and \SecretChecker\ modules, as well as the introduction of \ConnectBackoff\ and \PromEx\ plugins.

relups · high confidence

Configured release environment for Fly.io and distributed Erlang performance

The release environment scripts (rel/env.sh.eex, rel/env.bat.eex) and VM arguments (rel/vm.args.eex) have been added to support deployment on Fly.io and optimize distributed node communication. The shell script automatically detects the Fly.io local 6pn IP address or falls back to the hostname, sets the node name based on environment variables, and enables JPperf symbols on Linux. The VM arguments configure the Erlang VM with increased process limits (1,000,000), expanded ETS name table size, and specific distribution port ranges (20000-21000) with tuned socket buffers and nodelay settings for improved network performance.

rel · high confidence

Database schema evolution for Supavisor management tables

The internal database schema for the Supavisor management system has been updated to support advanced connection management, security, and operational features. New migrations introduce read-replica support via the \clusters\ and \cluster\_tenants\ tables, enforce SSL/TLS configuration with \upstream\_ssl\ and \enforce\_ssl\ fields, and enable Just-In-Time (JIT) access through \use\_jit\ and \jit\_api\_url\. Operational controls now include tenant banning (\banned\_at\, \ban\_reason\), IP allow-listing (\allow\_list\), availability zone tracking, and configurable pool strategies (\fifo\/\lifo\) and idle timeouts. The \users\ table has been extended with connection limits (\max\_clients\), checkout timeouts, and performance indexes to support these capabilities.

priv/repo/migrations · high confidence

Test coverage

Added JavaScript integration tests for Postgres.js, Prisma, and Neon Serverless; Added benchmarking scripts for protocol and circuit breaker performance; Added test certificates for ECDSA and EdDSA key types; Added test coverage for client handler validation, proxying, and telemetry; Added test coverage for metrics and tenant controllers; Added test coverage for monitoring plugins; Added test fixtures and helpers for tenant and connection testing; Added tests for LogflareFormatter JSON output structure; Added tests for OpenAPI endpoints and WebSocket proxy password filtering; Added tests for backend prepared statement storage strategies; Added unit tests for the protocol layer; Expanded integration test coverage for proxy reliability and security; Expanded test coverage for core Supavisor components; Initial Elixir test suite and integration scaffolding; New test support modules for assertions, clustering, and integration testing.

Dependencies

Initial dependency configuration for Supavisor

This change introduces the foundational dependency manifests for the Supavisor project, establishing the build environment across Elixir, Rust, and JavaScript. The Elixir \mix.exs\ defines the core application stack, including Phoenix 1.7.2, Ecto 3.10, Postgrex (pinned to a specific Git commit), and Rustler 0.36.1 for native extensions, alongside a custom Supabase fork of Poolboy. The Rust \Cargo.toml\ sets up the \pgparser\ crate using Rustler and \pg\_query\ 6.1.0. Additionally, JavaScript integration test dependencies are added, specifying Prisma 5.22.0, the Neon serverless driver, and the \postgres\ client.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 56 (+0.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 95 → 97 (+1.3)
  • Architecture 92 → 90 (-2.8)
  • Maturity 67 → 67 (+0.0)
  • Readiness 41 → 44 (+2.4)
  • Security 57 → 54 (-2.8)

Resolved (42)

  • Change coupling: client_handler.ex ↔ client.ex (lib/supavisor/client_handler.ex)
  • Change coupling: client_handler.ex ↔ handler_helpers.ex (lib/supavisor/client_handler.ex)
  • Change coupling: client_handler.ex ↔ tenant.ex (lib/supavisor/client_handler.ex)
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (12 lines × 2) (lib/supavisor/client_handler/auth_methods/jit.ex)
  • Duplicated block (6 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • Duplicated block (8 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • Duplicated block (9 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • FileTooLong: supavisor/tenants.ex (lib/supavisor/tenants.ex)
  • High CVE: [GHSA redacted] (mix.lock)
  • High IaC: DS-0029 (Dockerfile)
  • Medium CVE: [CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • Medium CVE: EEF-[CVE redacted] (mix.lock)
  • …and 22 more

New (84)

  • Boundary-crossing change coupling: config.exs ↔ application.ex (config/config.exs)
  • Boundary-crossing change coupling: config.exs ↔ client_handler.ex (config/config.exs)
  • Change coupling: runtime.exs ↔ test.exs (config/runtime.exs)
  • Change-coupling hub: client_handler.ex → handler_helpers.ex, client.ex, tenant_supervisor.ex, tenant.ex (lib/supavisor/client_handler.ex)
  • Dependency advisory scan runs only on code events
  • Documentation: written for insiders (docs/development/docs.md)
  • Duplicated block (10 lines × 2) (lib/supavisor_web/controllers/cluster_controller.ex)
  • Duplicated block (11 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • Duplicated block (11 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • Duplicated block (14 lines × 2) (lib/supavisor/client_handler/auth_methods/jit.ex)
  • Duplicated block (14 lines × 2) (lib/supavisor_web/controllers/cluster_json.ex)
  • Duplicated block (5 lines × 2) (lib/supavisor/monitoring/net_stat.ex)
  • Duplicated block (6 lines × 2) (lib/supavisor/monitoring/net_stat.ex)
  • Duplicated block (7 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • Duplicated block (7 lines × 2) (lib/supavisor/monitoring/prom_ex.ex)
  • HackComment (lib/supavisor/monitoring/prom_ex.ex)
  • High IaC: DS-0029 (Dockerfile)
  • High IaC: DS-0029 (Dockerfile)
  • High IaC: WD-DOCKER-0001 (Dockerfile)
  • High: security finding (details withheld)
  • …and 64 more

Changes since last survey

  • 65 commits — 43 feature/other, 22 fixes

By area

  • lib/supavisor — 24 commits
  • (repo) — 22 commits
  • (root) — 6 commits
  • .github/workflows — 6 commits
  • docs/monitoring — 3 commits
  • test/supavisor — 2 commits
  • priv/repo — 1 commit
  • test/integration — 1 commit

Notable commits

  • fix: Merge pull request #1177 from supabase/fix/forward-port-enotfound-delay
  • fix: Merge pull request #1178 from supabase/fix/forward-port-handshake-timeouts
  • fix: Merge pull request #1186 from supabase/fix/sec-964-forward-client-ip-jit
  • fix: Merge pull request #1196 from supabase/jv/dockerfile-debian-version-fix
  • fix: chore: bump req to 0.6.3 (fix decompression bomb DoS)
  • fix: fix(monitoring): drop tenant label from state duration metric (#1168)
  • fix: fix: add 5s timeout on the handshake state (#1162)
  • fix: fix: add project metadata to syn conflict resolution logs
  • fix: fix: alias nested PromEx plugin modules in prom_ex_test.exs
  • fix: fix: bound client TLS handshake with a timeout (#1153)
  • fix: fix: bump DEBIAN_VERSION to a snapshot published for otp 27.3.4.16
  • fix: fix: bypass :inet_gethost_native for literal IP addresses (#1160) (#1167)
  • fix: fix: correct gzip assertion in MetricsPusher test
  • fix: fix: forward client_ip internal pooling
  • fix: fix: increase ENOTFOUND response delay to 2.5s (#1159)
  • fix: fix: poll node IPv6 address instead of computing it once
  • fix: fix: remove dead cache invalidation in SecretChecker.do_update_credentials (#1151)
  • fix: fix: remove stale Sync handler (#1176)
  • fix: fix: replace dynamic atom interpolation in config_key/2 with static clauses
  • fix: fix: replay parse before named statement describe (#1185)
  • …and 45 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

supabase/supavisor was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e5247779767612793852de1cd9affd5345310e2c — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.