Database

Setting Up Your Database on Self-Hosted Supabase

Supabase’s open-source stack on a server you run, from a kit we give you. One script makes its secrets, one command starts it, and it sets up and updates its own database.

5 min read

The kit is the open-source Supabase self-hosting bundle, pinned to a known version, with a small Pental overlay. It runs the portal’s database on a server of yours: a virtual machine in your Azure, Google Cloud or AWS account, or your own hardware. Your data never leaves it.

Pros and cons

Pros

  • Everything runs on your own server, in your Azure, Google Cloud or AWS account or on your own hardware.
  • It sets itself up: on first start the stack builds the portal’s database, with no SQL to copy anywhere.
  • Updates apply themselves every day, only when Pental has signed them, and one command takes an update straight away.
  • The same open-source Supabase software, Studio dashboard included.

Cons

  • You run the server: the operating system, Docker, disk space, monitoring and backups are yours to look after.
  • It needs a Linux server with Docker, a DNS name pointed at it and ports 80 and 443 open to the internet.
  • It is one server, so the portal is up when that server is.

What you need

  • A Linux server with Docker Engine 24 or later and Docker Compose 2.24.4 or later (docker compose version says which). Two CPUs, 4 GB of memory and 40 GB of disk suit a small firm.
  • A DNS name for it, such as db.yourfirm.com, and the right to add a record for it. The setup offers one on your firm’s own domain.
  • Ports 80 and 443 open to the internet. Port 80 is only used to get the certificate and to redirect to 443.
  • The server able to reach the internet over https: Docker Hub for the images, Let’s Encrypt for the certificate and pental.io for schema updates.
  • Your portal’s address, such as https://yourfirm.pental.io.

Point the name at the server

At your DNS provider, add an A record for the name with the server’s public IP address, then check it has arrived:

dig +short db.yourfirm.com

Install the kit and make its secrets

Download the kit from the Database step (Download the kit), copy it to the server, with scp for example, and run these there. The setup shows them with your own name and portal address already in.

unzip pental-self-hosted-kit-*.zip
cd pental-self-hosted-kit
./pental-setup.sh db.yourfirm.com https://yourfirm.pental.io

pental-setup.sh writes .env with every secret newly generated (never the example keys the whole internet knows), turns on the settings the portal needs, and prints the two things you paste on pental.io: the address and the publishable key. It is safe to run again: it keeps what it made.

Start it

docker compose up -d

The first start downloads the images. Then, on their own, Caddy fetches a TLS certificate for your name from Let’s Encrypt and the Pental updater sets up the portal’s database with Pental’s current schema. Nobody copies SQL anywhere. To check both have happened:

RunYou should see
docker compose psEvery service running or healthy
docker compose logs pental-updaterSet up the portal schema (version …)
curl -I https://db.yourfirm.comAn answer over https, not an error

Connect it on pental.io

On the Database step choose Self-hosted Supabase and paste what pental-setup.sh printed, whole: the address and the key are taken from it and the box empties itself. The setup asks your stack straight away and watches until its database is set up. Then press Check and connect: Pental checks every service the portal uses (tables, sign-in, files and live updates), plants Pental’s public keys in your stack’s vault and connects your portal.

The publishable key is the stack’s ANON_KEY, which reads nothing the security policies do not allow. Pental never asks for the service key in the same file; only a move uses it, from your own browser.

Keeping it updated

The database updates itself. When Pental publishes a new schema, the updater applies it at its daily run, 03:00 UTC unless you move it. It only applies SQL Pental has signed, checked against the key the setup planted in your own vault (before you connect, the key its first setup was checked with); anything else is refused and logged. It never applies an older version over a newer one, and an update that fails leaves the database exactly as it was.

RunWhat it does
./pental-update.sh --checkSays whether an update is waiting
./pental-update.shApplies it now
docker compose logs pental-updaterShows what the updater did, and when

In .env, PENTAL_UPDATE_HOUR_UTC (0 to 23) moves the daily run and PENTAL_AUTO_UPDATE=false turns it off. The kit itself updates the way it installs: download the newer kit, unzip it over the folder (your .env and your data stay as they are) and run docker compose up -d --build.

Keeping it safe

  • Keep the server’s firewall to ports 80 and 443.
  • .env holds every secret. Keep a copy somewhere safe: without it, the database’s sealed secrets cannot be opened.
  • Studio, Supabase’s dashboard, is at your address behind the DASHBOARD_USERNAME and DASHBOARD_PASSWORD in .env.
  • Back the database up regularly. Nightly, for example:
docker compose exec -T db pg_dumpall -U postgres | gzip > backup-$(date +%F).sql.gz

If something is not right

What you seeWhat to do
No certificate; the browser warnsThe name does not point at the server yet, or port 80 is closed. Fix it, then run docker compose restart caddy.
pental.io says the portal schema is missingdocker compose logs pental-updater says why, and ./pental-update.sh tries again now.
pental.io says the database is on an older setup SQL./pental-update.sh takes the update now. Then press Check and connect again.
The updater cannot reach pental.ioThe server needs outbound https. It tries again by itself.
docker compose complains about !overrideDocker Compose is older than 2.24.4. Update Docker.

Moving later

Move it to Supabase Cloud or PostgreSQL in your cloud whenever you like, with everything in it. The move uses the stack’s service key, which grep ^SERVICE_ROLE_KEY= .env prints in the kit’s folder.


Set It Up in the Trial

The Database step fills your server’s name into these commands and checks your stack from your browser as it starts.


Also Worth Reading

Setup guide

Prefer to watch it?

The whole setup recorded, with chapters you can jump to: registering, your own domain, your own database, your own mail server, branding, the first sign-in, and keeping the database updated.

  • 0:00 · Registering, signing in, and the free trial
  • 0:51 · Your name and your firm’s name
  • 0:57 · Custom domain
  • +5 more