SkillByAIOpen interactive version →

Lesson 25 / 25

A Supabase Launch Checklist

Review before going live.

Questions to ask

Is RLS enabled on every exposed table, with policies tested as anon and authenticated users? Is the service key only on servers, and are security definer functions reviewed? Are auth settings, redirect URLs and CAPTCHA configured? Are migrations in Git and applied through CI, with types regenerated? Are indexes in place for filters and policies, and is pooling configured for serverless? Are backups, restores, spend caps and alerts in place?

The checklist

Use it in launch reviews.

# [ ] RLS on every public table; policies tested per role
# [ ] service_role / secret key only in server envs; bundle scanned
# [ ] security definer functions reviewed, search_path fixed
# [ ] auth: email confirm, redirect allow list, CAPTCHA, rate limits, MFA on dashboard
# [ ] private buckets by default; storage policies by user folder
# [ ] migrations in Git, applied via CI; types regenerated
# [ ] indexes for filters, joins and policy columns; explain analyze on hot queries
# [ ] Supavisor pooling for serverless; connection counts monitored
# [ ] backups + restore test; PITR if needed; spend caps and alerts
# [ ] Security and Performance Advisors clean

Re-run the advisors after every big migration

New tables and functions are where missing RLS and missing indexes appear, so make the advisor check part of each release.

Quick check: Which item belongs on a Supabase launch checklist?

  • Production schema is edited only in the dashboard
  • The service key is embedded in the mobile app
  • Every exposed table has RLS with tested policies
  • All buckets are public for simplicity
Answer

Every exposed table has RLS with tested policies — RLS and key hygiene come first.