Back to articles
Technology Insight

Mastering Self-Hosted Supabase with Cloudflare Tunnels: The Ultimate Guide to Secure, IP-Hidden Backend Infrastructure

June 5, 2026

Introduction: The Evolution of Self-Hosted Backend-as-a-Service

In the modern development landscape, Supabase has emerged as the premier open-source alternative to Firebase. While the Supabase Cloud offering is exceptional, many enterprises and privacy-conscious developers are turning toward self-hosting to maintain absolute data sovereignty and reduce long-term costs. However, self-hosting brings a critical challenge: security. Exposing a database and authentication server directly to the public internet via open ports is a significant risk.

This is where the combination of Supabase Self-Hosted and Cloudflare Tunnels becomes a game-changer. By utilizing Cloudflare’s Argo Tunnel technology, you can expose your local Supabase services to the web without opening a single inbound port on your firewall. This architecture creates a 'black hole' for attackers, as your server's public IP address remains entirely hidden, effectively neutralizing DDoS attacks and unauthorized port scanning at the edge.

Why Choose Supabase Self-Hosted?

Before diving into the technical implementation, it is vital to understand the strategic advantages of hosting your own BaaS (Backend-as-a-Service):

  • Data Residency: Comply with strict GDPR, CCPA, or local data protection laws by keeping data within specific geographic boundaries.
  • Cost Predictability: Avoid the 'success tax' of managed platforms by leveraging existing hardware or fixed-price VPS instances.
  • Full Extension Support: Gain the ability to install any PostgreSQL extension without waiting for platform-wide support.
  • Deep Integration: Connect Supabase directly to other local microservices within a private network with zero latency.

The Security Powerhouse: Cloudflare Tunnels (Cloudflared)

Cloudflare Tunnels function by running a small daemon (cloudflared) on your server. This daemon establishes outbound-only connections to the Cloudflare edge. When a user requests your API, Cloudflare routes that traffic through these established tunnels. The benefits are three-fold:

  1. Zero Inbound Ports: You can close ports 80, 443, and 5432 on your router or cloud security group.
  2. WAF Protection: All traffic is filtered by Cloudflare’s Web Application Firewall before it ever reaches your infrastructure.
  3. Automatic SSL/TLS: Cloudflare handles certificate management, ensuring encrypted transit from the user to the edge.

Prerequisites for Deployment

To follow this guide, ensure you have the following components ready:

  • A Linux server (Ubuntu 22.04 LTS recommended) with at least 4GB of RAM and 2 CPUs.
  • Docker and Docker Compose installed.
  • A registered domain name managed via Cloudflare.
  • A Cloudflare account with a Zero Trust dashboard enabled.

Step 1: Preparing the Supabase Environment

Supabase provides a Docker-based configuration that orchestrates multiple services including GoTrue (Auth), PostgREST (API), Realtime, and Kong (API Gateway). First, we must clone the official repository and configure the environment variables.

Note: Never use the default passwords in a production environment. Use a secure password manager to generate 128-character strings for your JWT secrets and Postgres passwords.

Start by executing the following commands on your server:

git clone --depth 1 [https://github.com/supabase/supabase.git](https://github.com/supabase/supabase.git)
cd supabase/docker
cp .env.example .env

Inside the .env file, you must update the SITE_URL to your intended domain (e.g., [https://api.yourdomain.com](https://api.yourdomain.com)) and ensure all secret keys are unique.

Step 2: Launching Supabase with Docker Compose

Once the environment variables are configured, pull the images and start the services. In the supabase/docker directory, run:

docker compose pull
docker compose up -d

At this stage, Supabase is running locally on your server, typically listening on port 8000 via the Kong gateway. Crucially, do not open port 8000 in your firewall. We will use Cloudflare to bridge the gap.

Step 3: Configuring Cloudflare Tunnels

Navigate to the Cloudflare Zero Trust Dashboard. Under the 'Networks' tab, select 'Tunnels' and create a new tunnel. Give it a descriptive name like 'Supabase-Production'.

Cloudflare will provide a command to install and run the cloudflared connector. It is highly recommended to run this as a Docker container alongside your Supabase stack to ensure it restarts automatically with the system. Your docker-compose.yml for the tunnel should look like this:

tunnel:
  image: cloudflare/cloudflared:latest
  command: tunnel --no-autoupdate run --token YOUR_TOKEN_HERE
  restart: always

Step 4: Mapping Services to Public Hostnames

Within the Cloudflare Tunnel settings, add a Public Hostname. Map your subdomain (e.g., api.yourdomain.com) to the internal service URL. Since the tunnel container is in the same Docker network as Supabase, you can use the service name:

  • Service Type: HTTP
  • URL: http://kong:8000

Cloudflare will now automatically manage the DNS records. Any request to your subdomain will be securely routed to your local Kong container.

Step 5: Hardening and Optimization

With the tunnel established, you should perform additional hardening steps:

1. Configure CORS

In your Supabase .env file, restrict the ADDITIONAL_REDIRECT_URLS and CORS settings to only allow your frontend's domain. This prevents unauthorized websites from making requests to your API.

2. Implement Rate Limiting

Leverage Cloudflare’s 'WAF' rules to apply rate limiting on the /auth/v1/ endpoints. This prevents brute-force attacks on your user login and registration flows.

3. Monitor Logs

Use Docker logs to monitor the health of your services. Monitoring the cloudflared logs is particularly important to ensure the connection to the edge remains stable.

Conclusion

By deploying Supabase Self-Hosted behind a Cloudflare Tunnel, you achieve an enterprise-grade backend infrastructure that is both flexible and incredibly secure. You have successfully decoupled your server's physical identity from its digital presence, ensuring that your IP remains hidden while providing a seamless, high-performance experience for your users.

This setup represents the pinnacle of modern self-hosting: the power of a full-scale Backend-as-a-Service, the privacy of local hosting, and the world-class security of Cloudflare’s edge network. Whether you are building a small startup or an enterprise application, this architecture provides a scalable foundation for the future.