Self-Hosting Supabase: The Ultimate Guide to a Complete Firebase Alternative on a Single VPS Using Docker Compose
Introduction: Why Self-Host Supabase?
For years, Google Firebase has been the go-to Backend-as-a-Service (BaaS) for developers looking to ship applications rapidly. It handles authentication, databases, and file storage seamlessly. However, as applications scale, vendors lock you in, and Firebase's proprietary NoSQL structure can become a bottleneck. Enter Supabase: the open-source Firebase alternative built on top of enterprise-grade, relational PostgreSQL.
While Supabase offers a fantastic managed cloud service, self-hosting Supabase on your own Virtual Private Server (VPS) grants you absolute control over your data, eliminates vendor lock-in, and drastically reduces infrastructure costs. By utilizing Docker Compose, you can deploy the entire Supabase ecosystem—including authentication, real-time databases, storage, and auto-generated APIs—onto a single, modest VPS. This guide will walk you through the entire process from server preparation to a fully operational production deployment.
Prerequisites and System Requirements
Before diving into the configuration, ensure your environment meets the minimum requirements to run the Supabase stack efficiently. Because Supabase is a microservices-based architecture running multiple Docker containers, resource allocation matters.
- Hardware: A minimum of 2 vCPUs and 4GB of RAM is highly recommended for stable operation. For production workloads with higher concurrent traffic, consider 4 vCPUs and 8GB of RAM.
- Operating System: A clean installation of a modern Linux distribution, preferably Ubuntu 22.04 LTS or Ubuntu 24.04 LTS.
- Domain Name: A registered domain name (e.g.,
supabase.yourdomain.com) with A records pointing to your VPS IP address. - Tools: Docker and Docker Compose plugin installed on the target machine.
Step 1: Preparing Your VPS Environment
First, connect to your VPS via SSH. Ensure your system packages are up to date and install the necessary dependencies for Docker.
sudo apt update && sudo apt upgrade -y
sudo apt install curl git coreutils -y
Next, install Docker and the Docker Compose plugin if you haven't already:
curl -fsSL [https://get.docker.com](https://get.docker.com) -o get-docker.sh
sudo sh get-docker.sh
Verify your installation by checking the versions:
docker --version
docker compose version
Step 2: Cloning the Supabase Docker Repository
Supabase provides an official, well-maintained Docker configuration repository that simplifies self-hosting. Clone this repository directly into your preferred deployment directory, usually /srv/supabase or your user's home directory.
git clone --depth 1 [https://github.com/supabase/supabase.git](https://github.com/supabase/supabase.git)
cd supabase/docker
Inside this directory, you will find the core docker-compose.yml file alongside configuration subdirectories for various services like the API gateway (Kong), authentication (GoTrue/Auth), and storage.
Step 3: Configuration and Environment Setup
Supabase relies heavily on environment variables to secure and connect its microservices. Copy the provided template to create your production environment file:
cp .env.example .env
Now, open the .env file using a text editor such as nano or vim. You must change the default credentials to secure your infrastructure. Specifically, generate strong, random strings for the following keys:
CRITICAL SECURITY NOTE: Never leave the default passwords or JWT secrets intact for a production server. If compromised, attackers can gain root access to your database.
POSTGRES_PASSWORD=your_ultra_secure_password
JWT_SECRET=your_long_random_jwt_secret_key
ANON_KEY=your_generated_anon_key
SERVICE_ROLE_KEY=your_generated_service_role_key
To generate secure JWT keys compliant with Supabase requirements, you can use a tool like openssl or visit a secure online JWT generator using the HS256 algorithm. Ensure your SITE_URL matches your domain name so that authentication redirects operate correctly.
Step 4: Launching the Stack via Docker Compose
With your environment variables safely locked down, it is time to initialize the containerized ecosystem. Run the following command from within the docker folder:
sudo docker compose up -d
Docker will now download the official images for all Supabase components, including:
- Kong: An API gateway acting as the reverse proxy orchestrating external requests.
- GoTrue: The authentication engine managing user sign-ups, JWT issues, and third-party logins.
- PostgREST: A standalone web server that turns your PostgreSQL database directly into a RESTful API.
- Realtime: A Elixir-based server enabling listeners to capture database changes over WebSockets.
- Storage: An S3-compatible service for managing files, avatars, and media assets.
- Studio: The elegant web dashboard UI to visually manage your databases and services.
Verify that all containers are running successfully by checking their statuses:
sudo docker compose ps
Step 5: Configuring Nginx Reverse Proxy and SSL (Certbot)
By default, the Supabase dashboard (Studio) exposes port 8000, and Kong exposes port 8000 for API traffic. Exposing these raw ports directly to the public web is highly discouraged. Instead, we route traffic through a secure reverse proxy like Nginx combined with Let's Encrypt SSL certificates.
Install Nginx and Certbot:
sudo apt install nginx certbot python3-certbot-nginx -y
Create a new Nginx configuration block for your Supabase instance at /etc/nginx/sites-available/supabase:
server {
server_name supabase.yourdomain.com;
location / {
proxy_pass http://localhost:8000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
Enable the site configuration and restart Nginx:
sudo ln -s /etc/nginx/sites-available/supabase /etc/nginx/sites-enabled/
sudo systemctl restart nginx
Finally, secure your domain with a free Let's Encrypt SSL certificate:
sudo certbot --nginx -d supabase.yourdomain.com
Follow the interactive prompts to complete the automated SSL provisioning. Certbot will automatically rewrite your Nginx configuration to handle HTTPS termination natively.
Step 6: Accessing the Supabase Dashboard
Open your web browser and navigate to [https://supabase.yourdomain.com](https://supabase.yourdomain.com). You will be greeted by the Supabase Studio interface. From here, you can create tables, write SQL queries, inspect users, create storage buckets, and monitor your system performance visually.
Because you are hosting this yourself, you have unrestricted access to the underlying PostgreSQL database on port 5432 (if exposed or accessed via SSH tunnel), allowing you to hook up external business intelligence tools or run raw migrations flawlessly.
Best Practices for Production Environments
Running a self-hosted instance requires a proactive approach to server maintenance. To ensure high availability and data integrity, implement the following best practices:
- Automated Backups: Set up a nightly cron job to back up your PostgreSQL data using
pg_dumpor Docker-native volume backup scripts, and ship them off-site to secure cloud storage like AWS S3 or Backblaze B2. - Monitoring Resources: Monitor disk IOPS, RAM consumption, and CPU usage. Tools like Prometheus, Grafana, or simple Netdata dashboards help predict scale requirements before outages occur.
- SMTP Configuration: By default, authentication emails use dummy settings. Edit your
.envfile with valid credentials from an email provider (such as SendGrid, Postmark, or Amazon SES) to guarantee production user invitations and password resets deliver smoothly.
Conclusion
Self-hosting Supabase on a single VPS via Docker Compose is an incredibly powerful option for startups, enterprise internal tools, and privacy-conscious developers. It gives you the seamless development workflow of a modern Backend-as-a-Service while keeping infrastructure costs predictable and completely under your own command. With your database, APIs, authentication, and file storage successfully deployed, you are now ready to build scalable, high-performance applications without boundaries.
