BE-M0-10 · Local stack settings in config.toml
ID BE-M0-10 · Level L0 · Pack Pack A · Local stack settings · Run order row 18
supabase/config.toml switches off self sign-up, sets the site URL for apps/web, points at the signing key file and switches off the services M0 doesn't use; the key file is git-ignored. Committed on the pack A branch.
Before
Section titled “Before”- Timeline rows 1 to 17 are Done: TL-M0-16 created config.toml with Supabase CLI 2.119.0. The local stack is stopped. You are in ~/opleet-v2/opleet.
1 · A branch for pack A
Section titled “1 · A branch for pack A”cd ~/opleet-v2/opleetgit switch main && git pullgit switch -c supabase/local-settings2 · Change the nine settings. The script changes only text it finds exactly once, and stops without writing anything if config.toml differs from what supabase init 2.119.0 wrote.
Section titled “2 · Change the nine settings. The script changes only text it finds exactly once, and stops without writing anything if config.toml differs from what supabase init 2.119.0 wrote.”python3 - <<'EOF'import pathlib, sys
p = pathlib.Path("supabase/config.toml")s = p.read_text()changes = [ ('[realtime]\nenabled = true\n', '[realtime]\n# Off in M0: nothing uses it yet. Realtime for the queue TV is OQ13.\nenabled = false\n'), ('# Image transformation API is available to Supabase Pro plan.\n# [storage.image_transformation]\n# enabled = true\n', '# Image transformation API is available to Supabase Pro plan. Off: v2 serves files as stored.\n[storage.image_transformation]\nenabled = false\n'), ('site_url = "http://127.0.0.1:3000"\n', 'site_url = "http://localhost:3000"\n'), ('additional_redirect_urls = ["https://127.0.0.1:3000"]\n', 'additional_redirect_urls = ["http://localhost:3000", "http://127.0.0.1:3000"]\n'), ('# signing_keys_path = "./signing_keys.json"\n', '# An ES256 key made on each machine by pnpm db:signing-key and git-ignored, so getClaims()\n# verifies tokens locally (D13, FE-R4).\nsigning_keys_path = "./signing_keys.json"\n'), ('# Allow/disallow new user signups to your project.\nenable_signup = true\n', '# Allow/disallow new user signups to your project.\n# Off: staff accounts are created by an admin, never by self sign-up (OQ2, proposed answer).\nenable_signup = false\n'), ('# Allow/disallow new user signups via email to your project.\nenable_signup = true\n', '# Allow/disallow new user signups via email to your project.\nenable_signup = false\n'), ('[edge_runtime]\nenabled = true\n', '[edge_runtime]\n# Off in M0: no Edge Functions yet.\nenabled = false\n'), ('[analytics]\nenabled = true\n', '[analytics]\n# Off: Logflare and Vector take memory the local stack needs (TL-M0-15).\nenabled = false\n'),]for old, new in changes: found = s.count(old) if found == 1: s = s.replace(old, new) else: sys.exit(f"Stopped, nothing written: expected this text once in {p}, found it {found} times:\n{old}")p.write_text(s)print(f"{p}: {len(changes)} settings changed")EOF3 · Keep the signing key file out of git
Section titled “3 · Keep the signing key file out of git”cat >> supabase/.gitignore <<'EOF'
# Local-only ES256 signing key, made by pnpm db:signing-key (D13). Never commit it.signing_keys.jsonEOF4 · Review the change, then commit
Section titled “4 · Review the change, then commit”git diff --statgit diffgit add supabase/config.toml supabase/.gitignoregit commit -m "build(supabase): local stack settings for M0"Expect
Section titled “Expect”- Block 1:
Switched to a new branch 'supabase/local-settings'. - Block 2:
supabase/config.toml: 9 settings changed. - Block 3 prints nothing.
- Block 4:
supabase/.gitignore | 3 +++,supabase/config.toml | 28 +++++++++++++++++-----------and2 files changed, 20 insertions(+), 11 deletions(-). The diff touches only realtime, storage.image_transformation, site_url, additional_redirect_urls, signing_keys_path, enable_signup (under [auth] and [auth.email]), edge_runtime and analytics, each with a short comment saying why. Lefthook skips Biome (no files it checks) and shows ✔️ commitlint, then the commit line.
python3 -c 'import tomllib; c = tomllib.load(open("supabase/config.toml","rb")); a = c["auth"]; print(a["enable_signup"], a["email"]["enable_signup"], a["site_url"], a["signing_keys_path"], c["realtime"]["enabled"], c["storage"]["image_transformation"]["enabled"], c["edge_runtime"]["enabled"], c["analytics"]["enabled"], c["db"]["major_version"])'git log --oneline -1Expect False False http://localhost:3000 ./signing_keys.json False False False False 17, then the commit “build(supabase): local stack settings for M0”.
If it fails
Section titled “If it fails”- Block 2 prints “Stopped, nothing written”: config.toml isn't what supabase init 2.119.0 writes. Paste the message, the output of
pnpm supabase --versionand ofgit log --oneline -3 -- supabase/config.toml. Don't edit config.toml by hand. - Block 4's numbers differ: don't commit; paste the output of
git diff. - The commit is refused: paste the output.
Nothing has been pushed:
git switch maingit branch -D supabase/local-settingsDone 2026-10-06 (zuki)