AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Supavisor Session Pooler Authentication Failure After PostgreSQL Password Rotation

After rotating the database password in the Supabase Dashboard, connections through the Supavisor Session Pooler begin failing with 'password authentication failed for user "postgres"' despite using the correct new password. The issue is likely caused by Supavisor's secret synchronization not updating its cached credentials, as indicated by the repeated 'SecretChecker not started, using a one-off auth query connection' log message.

highConfidence 65%Supavisor

Origin Analysis

Supavisor's SecretChecker process is not running, causing it to use one-off auth query connections that rely on cached credentials stored in its configuration. When the database password is rotated via the Supabase Dashboard, the cached credential for the 'postgres' user in Supavisor is not updated, leading to authentication failures for clients presenting the new password.
1. Rotate the PostgreSQL database password via Supabase Dashboard. 2. Connect through Supavisor Session Pooler using username 'postgres.<project-ref>' and the new password. 3. Observe first connection may succeed, but subsequent attempts fail with 'password authentication failed for user "postgres"'. 4. Check Supavisor logs: repeated 'SecretChecker not started, using a one-off auth query connection' and 'ClientHandler: Exchange error: password authentication failed for user "postgres"'.

Fixing Code Block

Edge Case Audit

This hotfix is conceptual and untested. It may introduce race conditions if multiple retries occur concurrently, cause performance overhead due to secret reloads, or fail if the secret backend does not support synchronous refresh. Recommend thorough testing in a staging environment, monitoring for increased latency, and having a rollback plan (e.g., feature flag to disable the retry). Do not deploy to production without validation.

Ecosystem Topology