Volter World

Twins / Supabase / 1.0.4

@volter/twin-supabase

Supabase

volter-aiVolter maintainedSelected defaultv1.0.4

Local Postgres for apps using Supabase database connections. Supabase Auth, Storage, REST APIs and supabase-js are not supported by this release.

The example uses Supabase 1.0.3. Setup installs the selected 1.0.4 release; keep the example's own pins when following it.

Setup gives the current installation instructions for @volter/twin-supabase 1.0.4. Open the published README for credentials, seeds, supported operations and limits.

README shipped with @volter/twin-supabase 1.0.4

These instructions were published with this package. Their tool versions may differ from the current starter cohort. Use Setup to install this version.

A local Supabase project's Postgres database: in a World it is the World's own managed Postgres, and the twin hands the application its URL. A Protocol 3 derived pack (twin-world's architecture, "Protocol 3: the derived pack"); no real Supabase is contacted.

Use Node 22.6 or newer. Install the exact twin and World CLI in your app:

npm install --save-dev --save-exact @volter/world@3.0.147 @volter/twin-supabase@1.0.4

Follow Run a full stack to configure the World-owned Postgres and run your migrations and app inside the World. Keep your native Postgres client unchanged. This release does not implement Supabase's HTTP APIs or make supabase-js calls work.

The managed-database example supplies a complete SQL client and stop/resume workflow. It pins its own example releases; keep the selected release above when adopting this twin in your app.

For an operator calling the server directly:

bun run src/cli.ts serve --database <postgres url>   # without --database the project has no database to hand out (503)

For whom

RH2 (Volter's product), whose authority store is a Supabase project's Postgres, reached over the Postgres wire alone: "no PostgREST, no Supabase client library, no anon session" (journeys/demand.json). Its release migrates the database and its Worker queries it; both are answered by Postgres itself, the World's database (journeys/customer-life.json walks RH2's own statements on it).

What is served

  • The database. The runtime binds the twin to the World's managed Postgres (managedDatabase: serve --database <url>), and the application connects to that database with any Postgres client. Under the containerless backing its clock follows the World clock. Database-generated randomness belongs to the backing and is not pinned; use explicit stable fixture IDs when comparing fresh Worlds (twin-world architecture, SQL steps).
  • The door. POST /_twin/app-credentials (the descriptor's credentialDoor, called by the runtime at every boot): makes the World's project world the first time and answers { ref, database_url }, filling SUPABASE_DB_URL.
  • Not served (the gap): every operation of the Management API (api.supabase.com/v1), PostgREST (/rest/v1), Storage (/storage/v1) and Auth (/auth/v1), each answering its unit's own unknown-route error (journeys/decisions.json); Realtime and Edge Functions (their paths are not claimed, so the injector refuses them).

Units

Unit Spec Serves
supabase (src/) spec/openapi.json.gz, api.supabase.com's own document (170 operations) the door; the Management API is the gap
supabase/rest rest/spec/client-ops.json, the calls @supabase/postgrest-js makes the gap
supabase/storage storage/spec/openapi.json, storage-api's document as Supabase's docs publish it the gap
supabase/auth auth/spec/openapi.yaml, GoTrue v2.197.0's document the gap

Evidence

The vendor's documents and recordings are under each unit's spec/ (its SOURCE.md).

Set up this release

The example uses Supabase 1.0.3. Setup installs the selected 1.0.4 release; keep the example's own pins when following it.

For a complete example, follow Managed app database. It includes the application code and its own exact dependency pins.

Use Node 22.6 or newer. Install this exact starter cohort in your app folder:

npm install --save-dev --save-exact @volter/world@3.0.158 @volter/world-core@3.0.148 @volter/world-runtime@3.0.156 @volter/world-console@3.0.149 @volter/twin-supabase@1.0.4

In your app’s folder, initialize a World with this implementation:

./node_modules/.bin/volter world init --name my-app --twins supabase --source supabase=@volter/twin-supabase

Review the detected vendor and retain the generated bindings. The supabase service’s source must select this version:

{
  "source": {
    "package": "@volter/twin-supabase",
    "version": "1.0.4"
  }
}

This is the source field, not a complete config. Keep the installed version, lockfile and generated service source in agreement. Use the release README for throwaway SDK credentials, seeds and limits.

The assessment records its own earlier tool versions under Measurements. This setup uses the current starter cohort.

Run your app’s own test command inside the World:

./node_modules/.bin/volter world up
./node_modules/.bin/volter world run -- npm test
./node_modules/.bin/volter world log
./node_modules/.bin/volter world down

down stops compute and retains state.

Versions and implementations

Package / versionPublisherStatusFirst use
@volter/twin-supabase1.0.4volter-aiSelected defaultPassed
@volter/twin-supabase1.0.3volter-ailiveNot measured

Evidence for 1.0.4

Installed first use · Passed
Installed first use
Passed
Fresh app installation
Verified
Workflow scope
Exact installed artifact; normal CLI initialization, unchanged SDK, result assertions and retained-state read-only resume where applicable
Customer SDK versions
pg@8.16.3
CLI, kernel and runtime versions
@volter/world@3.0.147 · @volter/world-core@3.0.147 · @volter/world-runtime@3.0.147
World clock
{"mode":"wall"}
Retained-state readback
Verified
Stopped compute
Verified
Customer journey failures
0
API coverage, replay and browser measurements

Counts describe the declared HTTP surface, not separate command tables or other protocols. Consult the release README for those workflows.

Assessment scope
packaged-customer-journey; in-process
Declared HTTP surface
0 served · 330 gaps · 330 declared operations
Exercised HTTP operation coverage
0 / 330 declared operations (0%)
Journey steps
182 answered / 184 steps
Replay
Equal across 2 runs
Journey failures
0
Browser target
Not measured
HTTP operations exercised through Chromium
Not measured
Chromium journey replay
Not measured
Browser response observation
Not recorded
Application-origin CORS coverage
Not measured
Native cookie-jar coverage
Not measured
DOM coverage
Not measured
Source code coverage
Not measured
State transition coverage
Not measured
Operations not exercised
  • supabase/auth:delete_admin_custom_providers_identifier
  • supabase/auth:delete_admin_oauth_clients_client_id
  • supabase/auth:delete_admin_sso_providers_ssoproviderid
  • supabase/auth:delete_admin_users_userid
  • supabase/auth:delete_admin_users_userid_factors_factorid
  • supabase/auth:delete_factors_factorid
  • supabase/auth:delete_user_identities_identityid
  • supabase/auth:delete_user_oauth_grants
  • supabase/auth:get_admin_audit
  • supabase/auth:get_admin_custom_providers
  • supabase/auth:get_admin_custom_providers_identifier
  • supabase/auth:get_admin_oauth_clients
  • supabase/auth:get_admin_oauth_clients_client_id
  • supabase/auth:get_admin_sso_providers
  • supabase/auth:get_admin_sso_providers_ssoproviderid
  • supabase/auth:get_admin_users
  • supabase/auth:get_admin_users_userid
  • supabase/auth:get_admin_users_userid_factors
  • supabase/auth:get_authorize
  • supabase/auth:get_callback
  • supabase/auth:get_health
  • supabase/auth:get_oauth_authorizations_authorization_id
  • supabase/auth:get_oauth_authorize
  • supabase/auth:get_saml_metadata
  • supabase/auth:get_settings
  • supabase/auth:get_user
  • supabase/auth:get_user_identities_authorize
  • supabase/auth:get_user_oauth_grants
  • supabase/auth:get_verify
  • supabase/auth:get_well_known_jwks_json
  • supabase/auth:post_admin_custom_providers
  • supabase/auth:post_admin_generate_link
  • supabase/auth:post_admin_oauth_clients
  • supabase/auth:post_admin_oauth_clients_client_id_regenerate_secret
  • supabase/auth:post_admin_sso_providers
  • supabase/auth:post_admin_users
  • supabase/auth:post_callback
  • supabase/auth:post_factors
  • supabase/auth:post_factors_factorid_challenge
  • supabase/auth:post_factors_factorid_verify
  • supabase/auth:post_invite
  • supabase/auth:post_logout
  • supabase/auth:post_magiclink
  • supabase/auth:post_oauth_authorizations_authorization_id_consent
  • supabase/auth:post_oauth_clients_register
  • supabase/auth:post_oauth_token
  • supabase/auth:post_otp
  • supabase/auth:post_reauthenticate
  • supabase/auth:post_recover
  • supabase/auth:post_resend
  • supabase/auth:post_saml_acs
  • supabase/auth:post_signup
  • supabase/auth:post_sso
  • supabase/auth:post_token
  • supabase/auth:post_verify
  • supabase/auth:put_admin_custom_providers_identifier
  • supabase/auth:put_admin_oauth_clients_client_id
  • supabase/auth:put_admin_sso_providers_ssoproviderid
  • supabase/auth:put_admin_users_userid
  • supabase/auth:put_admin_users_userid_factors_factorid
  • supabase/auth:put_user
  • supabase/rest:PostgrestClient.getOpenApiSpec
  • supabase/rest:PostgrestClient.rpc
  • supabase/rest:PostgrestClient.rpc_2
  • supabase/rest:PostgrestClient.rpc_3
  • supabase/rest:PostgrestQueryBuilder.delete
  • supabase/rest:PostgrestQueryBuilder.insert
  • supabase/rest:PostgrestQueryBuilder.select
  • supabase/rest:PostgrestQueryBuilder.select_2
  • supabase/rest:PostgrestQueryBuilder.update
  • supabase/storage:delete_bucket_bucketid
  • supabase/storage:delete_cdn_bucketname
  • supabase/storage:delete_iceberg_bucket_bucketname
  • supabase/storage:delete_iceberg_v1_prefix_namespaces_namespace
  • supabase/storage:delete_iceberg_v1_prefix_namespaces_namespace_tables_table
  • supabase/storage:delete_object_bucketname
  • supabase/storage:delete_s3_bucket
  • supabase/storage:delete_upload_resumable
  • supabase/storage:delete_upload_resumable_sign
  • supabase/storage:get_bucket
  • supabase/storage:get_bucket_bucketid
  • supabase/storage:get_health
  • supabase/storage:get_iceberg_bucket
  • supabase/storage:get_iceberg_v1_config
  • supabase/storage:get_iceberg_v1_prefix_namespaces
  • supabase/storage:get_iceberg_v1_prefix_namespaces_namespace
  • supabase/storage:get_iceberg_v1_prefix_namespaces_namespace_tables
  • supabase/storage:get_iceberg_v1_prefix_namespaces_namespace_tables_table
  • supabase/storage:get_object_authenticated_bucketname
  • supabase/storage:get_object_bucketname
  • supabase/storage:get_object_info_authenticated_bucketname
  • supabase/storage:get_object_info_bucketname
  • supabase/storage:get_object_info_public_bucketname
  • supabase/storage:get_object_public_bucketname
  • supabase/storage:get_object_sign_bucketname
  • supabase/storage:get_render_image_authenticated_bucketname
  • supabase/storage:get_render_image_public_bucketname
  • supabase/storage:get_render_image_sign_bucketname
  • supabase/storage:get_s3
  • supabase/storage:get_s3_bucket
  • supabase/storage:head_bucket
  • supabase/storage:head_bucket_bucketid
  • supabase/storage:head_health
  • supabase/storage:head_iceberg_bucket
  • supabase/storage:head_iceberg_v1_config
  • supabase/storage:head_iceberg_v1_prefix_namespaces
  • supabase/storage:head_iceberg_v1_prefix_namespaces_namespace
  • supabase/storage:head_iceberg_v1_prefix_namespaces_namespace_tables
  • supabase/storage:head_iceberg_v1_prefix_namespaces_namespace_tables_table
  • supabase/storage:head_object_authenticated_bucketname
  • supabase/storage:head_object_bucketname
  • supabase/storage:head_object_info_authenticated_bucketname
  • supabase/storage:head_object_info_bucketname
  • supabase/storage:head_object_public_bucketname
  • supabase/storage:head_object_sign_bucketname
  • supabase/storage:head_render_image_authenticated_bucketname
  • supabase/storage:head_render_image_public_bucketname
  • supabase/storage:head_render_image_sign_bucketname
  • supabase/storage:head_s3_bucket
  • supabase/storage:head_upload_resumable
  • supabase/storage:head_upload_resumable_sign
  • supabase/storage:options_upload_resumable
  • supabase/storage:options_upload_resumable_sign
  • supabase/storage:patch_upload_resumable
  • supabase/storage:patch_upload_resumable_sign
  • supabase/storage:post_bucket
  • supabase/storage:post_bucket_bucketid_empty
  • supabase/storage:post_iceberg_bucket
  • supabase/storage:post_iceberg_v1_prefix_namespaces
  • supabase/storage:post_iceberg_v1_prefix_namespaces_namespace_tables
  • supabase/storage:post_iceberg_v1_prefix_namespaces_namespace_tables_table
  • supabase/storage:post_object_bucketname
  • supabase/storage:post_object_copy
  • supabase/storage:post_object_list_bucketname
  • supabase/storage:post_object_list_v2_bucketname
  • supabase/storage:post_object_move
  • supabase/storage:post_object_sign_bucketname
  • supabase/storage:post_object_upload_sign_bucketname
  • supabase/storage:post_s3_bucket
  • supabase/storage:post_upload_resumable
  • supabase/storage:post_upload_resumable_sign
  • supabase/storage:post_vector_createindex
  • supabase/storage:post_vector_createvectorbucket
  • supabase/storage:post_vector_deleteindex
  • supabase/storage:post_vector_deletevectorbucket
  • supabase/storage:post_vector_deletevectors
  • supabase/storage:post_vector_getindex
  • supabase/storage:post_vector_getvectorbucket
  • supabase/storage:post_vector_getvectors
  • supabase/storage:post_vector_listindexes
  • supabase/storage:post_vector_listvectorbuckets
  • supabase/storage:post_vector_listvectors
  • supabase/storage:post_vector_putvectors
  • supabase/storage:post_vector_queryvectors
  • supabase/storage:put_bucket_bucketid
  • supabase/storage:put_object_bucketname
  • supabase/storage:put_object_upload_sign_bucketname
  • supabase/storage:put_s3_bucket
  • supabase/storage:put_upload_resumable
  • supabase/storage:put_upload_resumable_sign
  • supabase:v1-Delete hostname config
  • supabase:v1-accept-invite-external-jit-access
  • supabase:v1-activate-custom-hostname
  • supabase:v1-activate-vanity-subdomain-config
  • supabase:v1-apply-a-migration
  • supabase:v1-apply-project-addon
  • supabase:v1-authorize-jit-access
  • supabase:v1-authorize-user
  • supabase:v1-bulk-create-secrets
  • supabase:v1-bulk-delete-secrets
  • supabase:v1-bulk-update-functions
  • supabase:v1-cancel-a-project-restoration
  • supabase:v1-check-vanity-subdomain-availability
  • supabase:v1-claim-project-for-organization
  • supabase:v1-count-action-runs
  • supabase:v1-create-a-branch
  • supabase:v1-create-a-function
  • supabase:v1-create-a-project
  • supabase:v1-create-a-sso-provider
  • supabase:v1-create-an-organization
  • supabase:v1-create-legacy-signing-key
  • supabase:v1-create-login-role
  • supabase:v1-create-project-api-key
  • supabase:v1-create-project-claim-token
  • supabase:v1-create-project-signing-key
  • supabase:v1-create-project-tpa-integration
  • supabase:v1-create-restore-point
  • supabase:v1-deactivate-vanity-subdomain-config
  • supabase:v1-delete-a-branch
  • supabase:v1-delete-a-function
  • supabase:v1-delete-a-project
  • supabase:v1-delete-a-sso-provider
  • supabase:v1-delete-invite-external-jit-access
  • supabase:v1-delete-jit-access
  • supabase:v1-delete-login-roles
  • supabase:v1-delete-network-bans
  • supabase:v1-delete-project-api-key
  • supabase:v1-delete-project-claim-token
  • supabase:v1-delete-project-tpa-integration
  • supabase:v1-deploy-a-function
  • supabase:v1-diff-a-branch
  • supabase:v1-disable-preview-branching
  • supabase:v1-disable-readonly-mode-temporarily
  • supabase:v1-enable-database-webhook
  • supabase:v1-exchange-oauth-token
  • supabase:v1-generate-typescript-types
  • supabase:v1-get-a-branch
  • supabase:v1-get-a-branch-config
  • supabase:v1-get-a-function
  • supabase:v1-get-a-function-body
  • supabase:v1-get-a-migration
  • supabase:v1-get-a-snippet
  • supabase:v1-get-a-sso-provider
  • supabase:v1-get-action-run
  • supabase:v1-get-action-run-logs
  • supabase:v1-get-all-projects-for-organization
  • supabase:v1-get-an-organization
  • supabase:v1-get-auth-service-config
  • supabase:v1-get-available-regions
  • supabase:v1-get-backup-schedule
  • supabase:v1-get-database-disk
  • supabase:v1-get-database-metadata
  • supabase:v1-get-database-openapi
  • supabase:v1-get-disk-utilization
  • supabase:v1-get-hostname-config
  • supabase:v1-get-jit-access
  • supabase:v1-get-jit-access-config
  • supabase:v1-get-legacy-signing-key
  • supabase:v1-get-network-restrictions
  • supabase:v1-get-organization-entitlements
  • supabase:v1-get-organization-project-claim
  • supabase:v1-get-performance-advisors
  • supabase:v1-get-pgsodium-config
  • supabase:v1-get-pooler-config
  • supabase:v1-get-postgres-config
  • supabase:v1-get-postgres-upgrade-eligibility
  • supabase:v1-get-postgres-upgrade-status
  • supabase:v1-get-postgrest-service-config
  • supabase:v1-get-profile
  • supabase:v1-get-project
  • supabase:v1-get-project-api-key
  • supabase:v1-get-project-api-keys
  • supabase:v1-get-project-claim-token
  • supabase:v1-get-project-disk-autoscale-config
  • supabase:v1-get-project-function-combined-stats
  • supabase:v1-get-project-legacy-api-keys
  • supabase:v1-get-project-logs
  • supabase:v1-get-project-logs-all
  • supabase:v1-get-project-pgbouncer-config
  • supabase:v1-get-project-signing-key
  • supabase:v1-get-project-signing-keys
  • supabase:v1-get-project-tpa-integration
  • supabase:v1-get-project-usage-api-count
  • supabase:v1-get-project-usage-request-count
  • supabase:v1-get-readonly-mode-status
  • supabase:v1-get-realtime-config
  • supabase:v1-get-restore-point
  • supabase:v1-get-security-advisors
  • supabase:v1-get-services-health
  • supabase:v1-get-ssl-enforcement-config
  • supabase:v1-get-storage-config
  • supabase:v1-get-vanity-subdomain-config
  • supabase:v1-invite-external-jit-access
  • supabase:v1-list-action-runs
  • supabase:v1-list-all-backups
  • supabase:v1-list-all-branches
  • supabase:v1-list-all-buckets
  • supabase:v1-list-all-functions
  • supabase:v1-list-all-network-bans
  • supabase:v1-list-all-network-bans-enriched
  • supabase:v1-list-all-organizations
  • supabase:v1-list-all-projects
  • supabase:v1-list-all-secrets
  • supabase:v1-list-all-snippets
  • supabase:v1-list-all-sso-provider
  • supabase:v1-list-available-restore-versions
  • supabase:v1-list-jit-access
  • supabase:v1-list-migration-history
  • supabase:v1-list-organization-members
  • supabase:v1-list-project-addons
  • supabase:v1-list-project-tpa-integrations
  • supabase:v1-merge-a-branch
  • supabase:v1-modify-database-disk
  • supabase:v1-oauth-authorize-project-claim
  • supabase:v1-patch-a-migration
  • supabase:v1-patch-network-restrictions
  • supabase:v1-pause-a-project
  • supabase:v1-push-a-branch
  • supabase:v1-read-only-query
  • supabase:v1-remove-a-read-replica
  • supabase:v1-remove-project-addon
  • supabase:v1-remove-project-signing-key
  • supabase:v1-reset-a-branch
  • supabase:v1-restart-a-project
  • supabase:v1-restore-a-branch
  • supabase:v1-restore-a-project
  • supabase:v1-restore-physical-backup
  • supabase:v1-restore-pitr-backup
  • supabase:v1-revoke-token
  • supabase:v1-rollback-migrations
  • supabase:v1-run-a-query
  • supabase:v1-scrape-project-metrics
  • supabase:v1-setup-a-read-replica
  • supabase:v1-shutdown-realtime
  • supabase:v1-undo
  • supabase:v1-update-a-branch-config
  • supabase:v1-update-a-function
  • supabase:v1-update-a-project
  • supabase:v1-update-a-sso-provider
  • supabase:v1-update-action-run-status
  • supabase:v1-update-auth-service-config
  • supabase:v1-update-backup-schedule
  • supabase:v1-update-database-password
  • supabase:v1-update-hostname-config
  • supabase:v1-update-jit-access
  • supabase:v1-update-jit-access-config
  • supabase:v1-update-network-restrictions
  • supabase:v1-update-pgsodium-config
  • supabase:v1-update-pooler-config
  • supabase:v1-update-postgres-config
  • supabase:v1-update-postgrest-service-config
  • supabase:v1-update-project-api-key
  • supabase:v1-update-project-legacy-api-keys
  • supabase:v1-update-project-signing-key
  • supabase:v1-update-realtime-config
  • supabase:v1-update-ssl-enforcement-config
  • supabase:v1-update-storage-config
  • supabase:v1-upgrade-postgres-version
  • supabase:v1-upsert-a-migration
  • supabase:v1-verify-dns-config
Conformance results
  • decided: 0 failures · every served operation is decided with its demand; every demanded and every refreshed operation is served
  • published: 0 failures · what a release publishes holds every unit: its manifest, its spec and its journeys
  • cited: 0 failures · every vendor fact cited is recorded as a page that answered, each quote found on it
  • refresh: 0 failures · every stored resource of a vendor-backed unit declares how it is read back, and a unit that sends events ingests the vendor's
  • registered: 0 failures · a vendor-backed unit, lane or not, reaches the registered pack's state system
  • allowance: 0 failures · a rate budget above the fallback rests on the vendor's documented allowance, cited in its manifest
  • client: 0 failures · driven by the vendor's own client (its official SDK), served as a World runs it, the vendor's documented behaviour holds · supabase owes no client case: The demand's application uses node-postgres over the project's native Postgres connection, not a Supabase SDK (journeys/demand.json). The customer life drives that wire; recognized Supabase SDK dependencies do not establish support for Management, Auth, Storage or PostgREST, which remain explicit gaps.
  • life: 0 failures · the life walked over HTTP against the pack served as a World runs it, with its scenario: every check held
  • standalone: 0 failures · served by its server.ts as a World runs it, the pack answers HTTP and the boot probe, and each declared socket upgrades
Publisher, admission and provenance
Source commit
aa8fdf214742cc2bd955d7a5d9d297a995726258
Catalog record commit
674f488979d7a2c9b8427e39ec259a4eb5beb1ad
Package integrity
sha512-nABAOt9JIS+e5KsG0HtcgdQiKx3BLkD1vp3v3OdsiPC9aCHRCJGf+FX92YWeCWj/hJISmBQkZtRu+Iw2Hmks4A==
Admission mode
Trusted internal publisher · maintainer merge
Catalog assessment
Bundled report checksum verified
Assessed at
Not recorded
Assessment input head
6b50a8e6367de273865e4b6d201c1698c9432190

Read the catalog snapshot

Catalog snapshot · @volter/twin-catalog@0.2.62
Source commit
2d891e44624083a0ee54c058f1a566f050f38f1e
Catalog digest
72cc7d129522aaa089c84552b9d0839ab4cb0924ee7bd56ab359f827cddaa258
Installer integrity
sha512-MelxBw6h8W8k67EMu7SlYXOPwg8Z0QVcpDNKEcMzB8gH4v0JfYK2vuL7WdXNY1epjPZqxyK/5pEvDCiRqU0nAA==

Snapshot identity and measurements