Hosted Supabase, PostgreSQL 17.6.
We removed automatic anon/authenticated grants for future tables and views created by postgres in public, using ALTER DEFAULT PRIVILEGES ... ON TABLES.
The change was applied and verified:
service_role defaults and function/sequence defaults were preserved.postgres; our project administrator cannot assume supabase_admin.Default ACLs owned by the internal supabase_admin role still grant client privileges for future objects. The role documentation identifies it as an internal platform role, while the documented default-privilege procedure targets postgres.
Could the Supabase team confirm the intended hosted-platform boundary, ideally with a documentation reference?
public as supabase_admin?We are seeking clarification of the supported security posture, not a way to assume or modify a managed role.
Related discussion: https://github.com/orgs/supabase/discussions/48259
The user is seeking clarification on the security boundaries related to the supabase_admin role's default privileges on hosted Supabase. They have altered default privileges to remove automatic client grants and are concerned about potential security implications of platform-managed roles creating objects in the public schema. They request documentation or confirmation on the intended security posture.
If there are no docs to answer these questions then it's unlikely a team member will stumble upon this to answer these questions. I would file a ticket to Supabase support if you haven't yet