• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

supabase / cli / 36758032458
67%
develop: 67%

Build:
Build:
LAST BUILD BRANCH: gh-readonly-queue/develop/pr-7032-6ebbac0402ac2edd62c9998de679d67c62e9c90c
DEFAULT BRANCH: develop
Ran 30 Sep 2026 06:23PM UTC
Jobs 1
Files 79
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Sep 2026 06:21PM UTC coverage: 66.737%. Remained the same
36758032458

push

github

web-flow
fix(stack): serve Storage S3 and resumable uploads behind the gateway (#6917)

## Summary

With the experimental stack, Storage behind the gateway at
`<API_URL>/storage/v1` was missing configuration that the legacy
`supabase start` path sets. This broke S3 clients, resumable (TUS)
uploads, and therefore Studio file uploads, on both the native and
Docker runtimes.

**Storage recipe (`packages/stack/src/services/Storage.ts`)**

- `S3_PROTOCOL_PREFIX=/storage/v1`: the gateway strips the prefix and
sends no `x-forwarded-prefix`, so Storage verified SigV4 signatures
against a different canonical path (`SignatureDoesNotMatch`).
- `S3_PROTOCOL_ACCESS_KEY_ID`, `S3_PROTOCOL_ACCESS_KEY_SECRET`,
`STORAGE_S3_REGION`: new optional `s3AccessKeyId`, `s3SecretAccessKey`,
`s3Region` config, defaulting to the package's local S3 defaults.
Access-key S3 auth was previously unavailable.
- `TUS_URL_PATH=/storage/v1/upload/resumable`: the TUS `Location` header
dropped `/storage/v1`.
- `NODE_ENV=development`: the Storage image sets `NODE_ENV=production`,
and storage-api then forces `https` into TUS upload URLs. Only the
Docker runtime was affected, because native processes don't inherit the
host's `NODE_ENV`.
- Legacy parity: `UPLOAD_FILE_SIZE_LIMIT_STANDARD` (5 GB) and
`SIGNED_UPLOAD_URL_EXPIRATION_TIME` (7200s, instead of storage-api's 60s
default). Image transformation now uses the preferred
`IMAGE_TRANSFORMATION_ENABLED` key.
- The `/storage/v1` prefix is now one exported constant, also used by
the gateway route in `host/Endpoints.ts`, so the route and the Storage
config can't drift.

**CLI**

- `stack-config.ts` passes the local S3 keys and region into the Storage
creation.
- Stack `status` shows the Storage S3 URL, access keys, and region when
the Storage member enables the S3 protocol. `--env` emits
`STORAGE_S3_URL`, `S3_PROTOCOL_ACCESS_KEY_ID`,
`S3_PROTOCOL_ACCESS_KEY_SECRET`, and `S3_PROTOCOL_REGION`, matching
legacy `status` names. The previously reserved but never... (continued)

4097 of 6139 relevant lines covered (66.74%)

7.37 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36758032458.1 30 Sep 2026 06:23PM UTC 79
66.74
GitHub Action Run
Source Files on build 36758032458
  • Tree
  • List 79
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #36758032458
  • 481cb3f4 on github
  • Prev Build on gh-readonly-queue/develop/pr-6921-37043833af5d913ee233d76cd9fa63760c43063c (#36752856923)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc