AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Edge_runtime.Secrets Are Not Propagated When Supabase Config Push Is Run

Secrets defined under edge_runtime.secrets (including remotes.<name>.edge_runtime.secrets) in config.toml are not pushed to the hosted Supabase project when running supabase config push. This leads to missing secrets in production, causing edge functions to fail or behave incorrectly. The behavior is not documented, causing confusion.

mediumConfidence 72%Supabase CLIAffected V2.90.0

Origin Analysis

The Supabase CLI's config push command does not include logic to sync the edge_runtime.secrets configuration to the platform's secrets storage. While local development reads these secrets from config.toml, the push implementation likely only handles auth, database, api, and other services, omitting edge function secrets entirely. The internal configuration loader may not pass the EdgeRuntime.Secrets map to the remote update API.
1. Define edge_runtime.secrets and remotes.production.edge_runtime.secrets in config.toml:\n [edge_runtime.secrets]\n FOO = "foo"\n [remotes.production.edge_runtime.secrets]\n FOO = "env(FOO)"\n2. Run supabase config push for the remote.\n3. Navigate to https://supabase.com/dashboard/project/_/functions/secrets and observe that the secrets were not added.

Fixing Code Block

// Add to internal/config/push.go (or equivalent push command file) import ( "context" "fmt" "os" "github.com/supabase/cli/internal/secrets" ) // pushEdgeRuntimeSecrets syncs the edge_runtime.secrets from config.toml to the remote project. func pushEdgeRuntimeSecrets(ctx context.Context, projectRef string, secretsMap map[string]string) error { if len(secretsMap) == 0 { return nil } for key, value := range secretsMap { // Resolve environment variables in the value (e.g., env(VAR)) resolvedValue := os.ExpandEnv(value) if err := secrets.Set(ctx, projectRef, key, resolvedValue); err != nil { return fmt.Errorf("failed to set secret %s: %w", key, err) } } return nil } // In the pushRemoteConfig function, after existing service pushes, add: if err := pushEdgeRuntimeSecrets(ctx, projectRef, remoteConf.EdgeRuntime.Secrets); err != nil { return err }
The fix adds a helper function that iterates over the EdgeRuntime.Secrets map for the target remote, expands any environment variable references, and calls the existing secrets.Set API to upload each secret. This integrates edge function secret propagation into the config push flow and ensures that both global and remote-specific secrets are handled.

Edge Case Audit

This change will overwrite existing secrets of the same name on the remote project. It also requires that the secrets.Set function properly handles special characters and escaping; if not, values with spaces or symbols may be corrupted. Environment variable expansion may unintentionally substitute variables not intended. Rollback: revert the patch and use the manual `supabase secrets set` command. Before deploying, test with a non-production remote and ensure secret values are correct, especially those containing `$` or spaces.

Ecosystem Topology