RLS is tied to Supabase
Policies call auth.uid(), auth.jwt() and auth.role(), which only exist in Supabase.
Early development · nothing works yet
Unvendor is an open source CLI that moves a Supabase project onto infrastructure you control, one piece at a time.
Policies call auth.uid(), auth.jwt() and auth.role(), which only exist in Supabase.
Your tables reference their IDs, so you can't just recreate accounts somewhere else.
The object store knows nothing about them, so copying files isn't enough.
Right now leaving means a dump, some one-off scripts and rewriting access control by hand. Unvendor turns that into something you can run and check.
Scans the project and lists what has to move.
Moves users, identities and bcrypt hashes and keeps the user IDs, so nobody has to reset a password.
Rewrites Supabase-specific policies into plain SQL using a small shim schema. Whatever it can't convert goes into the report.
Copies buckets and objects and translates the access rules.
Compares source and target: row counts, logins, and RLS checks that should be denied.
$ npx unvendor inventory --source "$SUPABASE_DB_URL"
$ npx unvendor migrate auth --target keycloak
$ npx unvendor verifyThat changes where Supabase runs, not what you depend on. You still run its services and stay on its schemas. Unvendor is for moving onto plain Postgres, your own identity provider and any S3 store, each replaceable on its own.
Open an issue and describe what broke. That's the most useful thing you can do right now.
Open an issue