test: add hosted Supabase compatibility checks - #129
Conversation
Signed-off-by: Armand Parajon <armand@squareup.com>
Signed-off-by: Armand Parajon <armand@squareup.com>
Signed-off-by: Armand Parajon <armand@squareup.com>
Signed-off-by: Armand Parajon <armand@squareup.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The transaction-pooler assertion is nondeterministic, and CLI-created tables can escape cleanup on post-commit failures.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds an opt-in hosted Supabase regression suite covering CLI schema changes, Auth, RLS, Realtime continuity, TLS, and optional poolers.
Changes:
- Adds reusable hosted-project fixtures and cleanup.
- Exercises successful, refused, failed, and rollback paths.
- Documents setup, guarantees, limitations, and hosted results.
Fixture maintenance note: A separate update PR should evaluate Postgres 17.6.1.136→17.6.1.177, PostgREST 14.17→16.4 (major drift), Auth 2.196.0→2.197.0 (Auth schema additions), Realtime 2.134.10→2.138.3, and Supavisor 2.9.12→2.9.13 (pool throttling changes). Exact Postgres container-tag and digest verification remains incomplete.
| File | Description |
|---|---|
integration/supabase/README.md |
Links the hosted suite. |
integration/supabase/hosted/README.md |
Documents setup, scope, and evidence. |
integration/supabase/hosted/fixture_test.go |
Provides hosted users, tables, API access, and cleanup. |
integration/supabase/hosted/auth_test.go |
Tests Auth defaults, foreign keys, and index failures. |
integration/supabase/hosted/ddl_test.go |
Provides schema-change and refusal helpers. |
integration/supabase/hosted/lifecycle_test.go |
Tests CLI creation, export, columns, and indexes. |
integration/supabase/hosted/lifecycle_failure_test.go |
Tests refusal and failure preservation. |
integration/supabase/hosted/pooler_test.go |
Adds optional pooler checks. |
integration/supabase/hosted/realtime_test.go |
Implements authenticated Realtime streams. |
integration/supabase/hosted/realtime_lifecycle_test.go |
Verifies Realtime continuity across changes. |
integration/supabase/hosted/rls_test.go |
Tests declarative RLS behavior. |
integration/supabase/hosted/rls_rollback_test.go |
Tests atomic RLS cancellation. |
integration/supabase/hosted/tls_test.go |
Tests encryption and certificate rejection. |
docs/supabase.md |
Updates hosted compatibility guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
🤖 Review findings - created by Kiran's code review agent - for pg-sprite/pull/129, e770605. Verdict: 8 findings — 5 non-blocking (README/doc accuracy, weak refusal assertions), 3 suggestions. Non-blocking
General suggestions
The one thing that could have broken, verifiedThe RLS cancellation test depends on its tracer matching the exact live Verified correct
This review was generated by Claude Code (claude-opus-5). |
|
🤖 Addressed all eight findings in 1bbae42 and 0076f0f.
Focused hosted checks passed with race detection: cleanup, destructive refusal, and RLS creation/export/convergence. The no-opt-in package check and required lint/pre-push hooks also passed. The hosted session endpoint remains unconfigured and untested. — Codex (GPT-6) |

Why
The local Supabase suite cannot establish compatibility with the hosted service. We need repeatable checks against real Auth, Data API, Realtime, and database connections as pg-sprite evolves.
What
Add an opt-in Go test harness for a disposable hosted Supabase project, with setup instructions and an explicit account of what each result proves.
How
Realtime setup must establish reader readiness, authenticated subscriptions, and actual delivery before any schema change runs. Initialization failures fail the test. No writes are retried or connections restarted.
Risk
No production engine changes. Hosted tests skip unless explicitly enabled and require a disposable project because they create users, tables, and publication entries. Ordinary CI needs no hosted credentials.
Testing
Review fixes: hosted cleanup, destructive refusal, and RLS create/export/convergence passed with race detection. Without opt-in, the package skips hosted cases without Docker or database requests
go test -count=1 -timeout=10m -v ./integration/supabase/hosted: all 18 configured compatibility cases passed against hosted Supabase in 149 seconds. Pooler endpoints remain unconfiguredscripts/test-flaky.sh TestHostedRealtimeContinuity 10 ./integration/supabase/hosted: all ten race-enabled iterations passed, with no retries of failed runsAfter narrowing the scope,
go test -race -count=1 -timeout=3m -v ./integration/supabase/hosted -run '^TestHostedRealtimeContinuity$': all six phases passed in 53 secondsRead-only cleanup audit: zero remaining test tables or Auth users
Bigger picture
This establishes a hosted regression harness, not blanket Supabase support. Hosted session pooler validation remains a follow-up. Transaction-pooler refusal stays in the controlled local suite because hosted backend reuse makes that assertion nondeterministic. The harness verifies that pg-sprite preserves established Realtime delivery; Supabase startup investigation stays outside this PR.
Generated with Codex (GPT-6)