BE-M0-32 · The local signing key out of git, and a new one
ID BE-M0-32 · Level L0 · Pack Pack A · Local stack settings · Run order row 18a · Issue #69
supabase/signing_keys.json is git-ignored and no longer tracked, and the local stack signs with a new key made on this Mac. Pull request #6 committed the file, a private ES256 key, and supabase/.gitignore never got its line, so every clone shared one key (D13, FE-R4). The key only signed tokens for local stacks, so nothing is rewritten in git history; the old key is never used again.
Before
Section titled “Before”- Pack A is Done. Nothing else has to come first: this step can run before pack B.
- You are in ~/opleet-v2/opleet,
git status --shortprints nothing, and Docker Desktop is running.
1 · Note the current key's ID, which isn't secret, to compare at the end
Section titled “1 · Note the current key's ID, which isn't secret, to compare at the end”cd ~/opleet-v2/opleetgit switch main && git pullpython3 -c 'import json; print(json.load(open("supabase/signing_keys.json"))[0]["kid"])'2 · A branch; ignore the key file and stop tracking it (the file stays on disk for now)
Section titled “2 · A branch; ignore the key file and stop tracking it (the file stays on disk for now)”git switch -c supabase/untrack-signing-keycat >> supabase/.gitignore <<'EOF'
# Local-only ES256 signing key, made by pnpm db:signing-key (D13). Never commit it.signing_keys.jsonEOFgit rm --cached supabase/signing_keys.jsongit check-ignore -v supabase/signing_keys.jsongit status --short3 · Commit, push and open the pull request
Section titled “3 · Commit, push and open the pull request”git add supabase/.gitignoregit commit -m "build(supabase): stop tracking the local signing key"git push -u origin supabase/untrack-signing-keygh pr create --title "build(supabase): stop tracking the local signing key" --body "BE-M0-32. #6 committed supabase/signing_keys.json; it is now ignored and untracked. Closes #69."gh pr checks --watch4 · Merge, then pull. The pull deletes the old key from disk, because main no longer tracks it
Section titled “4 · Merge, then pull. The pull deletes the old key from disk, because main no longer tracks it”gh pr merge --squash --delete-branchgit switch maingit pullls supabase/signing_keys.json5 · Make a new key, restart the stack, and read the key it publishes
Section titled “5 · Make a new key, restart the stack, and read the key it publishes”Signing in again is needed afterwards: tokens signed with the old key no longer verify.
pnpm db:signing-keypnpm supabase stoppnpm supabase startpython3 -c 'import json; print(json.load(open("supabase/signing_keys.json"))[0]["kid"])'eval "$(pnpm supabase status -o env)"curl -s "$API_URL/auth/v1/.well-known/jwks.json" -H "apikey: $PUBLISHABLE_KEY" | python3 -c 'import json, sys; k = json.load(sys.stdin)["keys"]; print(len(k), k[0]["kid"], k[0]["alg"], "d" in k[0])'Expect
Section titled “Expect”- Block 1: “Already on 'main'”, then one key ID (a UUID-like string). Keep it for block 5.
- Block 2: “Switched to a new branch 'supabase/untrack-signing-key'”, then
rm 'supabase/signing_keys.json', thensupabase/.gitignore:11:signing_keys.json supabase/signing_keys.json(the line number may differ), thenM supabase/.gitignoreandD supabase/signing_keys.json. - Block 3: ✔️ commitlint, then the commit line with 2 files changed; the pull request's URL; checks and pr-title pass.
- Block 4: “✓ Squashed and merged pull request #…”, the pull lists
supabase/signing_keys.jsonas deleted, and ls prints “No such file or directory”. - Block 5:
JWT signing key appended to: supabase/signing_keys.json (now contains 1 keys); the stack stops and starts; then a key ID different from block 1's; then1 <that ID> ES256 False.
git ls-files supabase/signing_keys.jsongit check-ignore -q supabase/signing_keys.json && echo ignoredgit status --shortgit log --oneline -1Nothing, then “ignored”, then nothing, then “build(supabase): stop tracking the local signing key (#…)” on main.
If it fails
Section titled “If it fails”- Block 2's
git rm --cachedsays “did not match any files”: the key isn't tracked on your main. Stop and paste the output ofgit log --oneline -3 -- supabase/signing_keys.json. - Block 2's check-ignore prints nothing: the ignore line didn't land. Paste the output of
tail -5 supabase/.gitignore. Don't commit. - Block 4's ls still shows the file: paste the output of
git log --oneline -2andgit status --short. Don't make a new key until the file is gone or ignored. - Block 5's start fails to read the signing keys: run
pnpm db:signing-keyagain, thenpnpm supabase start. - The key ID in block 5 matches block 1's: the old file was kept. Stop and paste both lines.
Before merging: gh pr close --delete-branch, then git switch main. The key file is still on disk and the stack is unchanged. After merging there is nothing to undo: keep the new key, and never put the old one back.
Not run yet. Log each run as a comment on #69.