6.11. Security, Auth, And Secrets Boundary¶
Supabase, Kong, service auth notes, API keys, local secrets, cloud keys, and intentionally unauthenticated local surfaces.
1. Diagram¶
2. Notes¶
Not every surface sits behind Supabase auth: Backend's /health, /ready, /metrics, and API-doc routes are intentionally public (no bearer token) — don't publish them beyond the intended network boundary. Kong's own Admin API (8001) is loopback-only, reachable via docker exec, never published. JupyterHub is explicitly operator-trusted, with direct database and service access rather than a policy gate.
3. Source Files¶
services/kong/service.ymlservices/supabase/service.ymlbootstrapper/generate_supabase_keys.py