Overview of RDS Supabase Applications
What Is Supabase?
Supabase is an open-source alternative to Firebase (108k+ GitHub Stars, Apache-2.0 license). Built on PostgreSQL, it is a full-stack Backend-as-a-Service (BaaS) platform that provides complete backend capabilities, including PostgreSQL databases, user authentication, auto-generated RESTful and GraphQL APIs, real-time data subscriptions, object storage, and vector search. It enables developers to quickly build backend logic for web and AI applications without spending weeks setting up complex backends, databases, and servers. Unlike Firebase, which uses a NoSQL document database, Supabase leverages the power of the enterprise-grade relational database PostgreSQL. It combines the advanced features of relational databases with the flexibility of an open-source ecosystem, providing an open-source solution to avoid commercial BaaS vendor lock-in.
RDS Supabase applications are currently free during beta testing. After they become commercially available, this feature will be billed.
Supabase Capabilities
Supabase integrates various mature, best-in-class open-source tools into a unified development platform, providing core capabilities out of the box, such as data APIs, user authentication, object storage, and real-time communication. Developers can rapidly build high-performance, scalable applications without building backend infrastructure from scratch. Core capabilities include:
- PostgreSQL database
- A fully managed, independent PostgreSQL database that provides complete SQL capabilities, rather than a simplified edition.
- Supports JSONB, full-text search, views, stored procedures, triggers, and visual SQL management.
- Auto-generated data APIs
- When database tables are created, Supabase automatically generates secure, ready-to-use RESTful and GraphQL APIs based on the database schema.
- Auto-generated RESTful APIs cover database CRUD functions, allowing you to perform operations such as query, insert, update, and delete efficiently without writing backend code.
- Authentication
- Provides out-of-the-box registration, login, and session management, and supports email login and authentication, as well as JWT-based fine-grained access control.
- By deeply binding user roles with PostgreSQL row-level security (RLS) policies, the system natively implements multi-tenant data security isolation, ensuring that users access only their own data.
- Realtime
- Listens for database changes through WebSockets, allowing you to easily build collaborative applications, chat applications, dashboards, and other real-time features.
- Supports INSERT, UPDATE, and DELETE events, as well as Presence (online status) and Broadcast (message broadcasting).
- Storage
- Interconnects with Huawei Cloud Object Storage Service (OBS) to store and serve large files such as videos and images.
- Provides file-level access control based on RLS and supports resumable transfer of large files.
- Provides image transformation and resizing with built-in CDN support.
- Vector and AI (Vecs/pgvector)
- Includes the built-in pgvector extension for storing and querying vector embeddings directly in PostgreSQL.
- Eliminates the need for an additional vector database, simplifying AI application architecture.
RDS Supabase Architecture
RDS Supabase uses a layered, decoupled architecture for higher scalability and flexibility. Figure 1 shows the overall architecture.
- Application access layer (ACCESS)
The unified user entry point that provides multiple ways to access and manage the platform. This layer shields backend complexity to achieve single integration for multi-terminal use.
- ManageAPI is used for automated project management and orchestration.
- OpenAPI exposes RESTful APIs for programs to call.
- SDK provides multi-language development kits.
- WebConsole serves as the visualized management console.
- MCP supports AI Agent access.
- RDS service layer (SERVICE)
The core service layer that is built on Supabase, responsible for routing, authentication, data access, and O&M capabilities.
- Kong is used for traffic control and routing.
- Auth is used for security authentication and user management.
- PostgREST is used to automatically convert APIs into SQL statements.
- Realtime is used to push database table changes.
- Storage and Imgproxy are used to process large files and images.
- Studio provides visualized O&M.
- Supavisor handles high concurrency through connection pooling.
- Logflare is used for structured log analysis.
- Newly added components include Meta (metadata management), Vector (vector search), and DBS Agent (management agent service). They extend the platform with metadata governance, AI vector retrieval, and control-plane interaction capabilities.
- RDS workload data layer (DATA)
The workload data storage and processing layer that is built on PostgreSQL. It uses a primary/standby architecture (primary node for read and write operations, standby node for read-only operations), offering high availability, reliability, and scalability. Relying on RLS policies, Auth schema, pgvector vector storage, and pggraph graph queries, it ensures data security and multi-modal query execution.
- Cloud storage layer (STORAGE)
The underlying storage powered by Huawei Cloud. Huawei Cloud OBS provides S3-compatible object storage to host large files securely, while cloud disks provide persistence for workload data backups. The service layer accesses object storage through the S3 protocol and performs backup and recovery operations using backup protocols. The data layer communicates with the cloud storage layer through backup-and-recovery data flows, enabling secure data archiving and rapid recovery.
RDS Supabase Application Scenarios
- Rapid MVP Validation and Agile Delivery
RDS Supabase enables products to move from prototype to production with minimal effort. After data modeling, backend capabilities are automatically generated from table schema definitions, eliminating the need to build services from scratch. Authentication, real-time messaging, and other common modules are available out of the box, allowing developers to focus on core business logic and significantly shorten delivery cycles.
- Backendless Web and Mobile Application Development
Traditionally, building a complete application requires both frontend and backend systems. RDS Supabase adopts a "Database-as-an-API" model, exposing the data layer directly as callable APIs, significantly reducing backend coding and server O&M operations. Frontend engineers can deliver production-ready web and mobile applications without relying on server-side technology stacks (like Node.js) or worrying about deployment and scaling. This model is ideal for small teams and full-stack frontend engineers.
- One-Stop Foundation for AI Applications As AI becomes a standard product feature, integrating underlying data and model services becomes a major challenge. RDS Supabase is deeply integrated with PostgreSQL to provide end-to-end development support for AI applications.
- Vectorized multi-modal storage: RDS Supabase relies on the pgvector capabilities of RDS for PostgreSQL to store vector data and perform similarity searches, providing the foundation for semantic matching. RAG applications do not require an additional vector database.
- Unified APIs: RDS Supabase acts as the API layer between applications and data, shielding underlying complexity.
- Scenario-driven capabilities: Common AI requirements, such as RAG retrieval and streaming WebSocket interactions, can be implemented using RDS for PostgreSQL and Supabase ecosystem capabilities. These capabilities support scenarios like intelligent customer service, smart Q&A, and semantic search, helping AI businesses build MVPs, validate market fit, and acquire early users with significantly lower effort.
- AI knowledge base: By storing business data and AI vector data in the same database, RDS Supabase eliminates the need to maintain multiple heterogeneous systems. This avoids cross-system data synchronization challenges and significantly reduces the development and O&M costs of AI applications.
- SaaS Multi-Tenancy and Fine-Grained Access Control
For SaaS providers and enterprises undergoing digital transformation, data and permission isolation is a foundational requirement. RDS Supabase provides an Auth mechanism supporting multiple authentication methods and combines it with RLS policies to deliver fine-grained control over data access. This ensures strict tenant-level isolation in multi-tenant scenarios while supporting role- and dimension-based privilege division within organizations, enabling security governance to extend across the entire lifecycle of the application.
- Enterprise-Built Internal BaaS Platform
- It standardizes the enterprise's backend architecture, eliminates redundant development, and ensures full data sovereignty.
- Its visualized management console simplifies platform operations, enables isolation across multiple projects, and mitigates data silo challenges within the enterprise.
- Real-Time Collaborative Applications
Real-time performance is core to user experience of collaborative products. Realtime of RDS Supabase provides capabilities such as data change listening (Postgres Change), message broadcasting (Broadcast), and online status tracking (Presence), covering key collaboration scenarios. Developers can efficiently build applications based on these capabilities and extend them to enterprise-grade application scenarios, including online multi-use document editing, real-time updates of project management dashboards, and message and status synchronization in instant messaging systems.
Advantages of the RDS Supabase Development Model
Traditional application architectures are typically multi-layered and tightly coupled, with frontend services, backend services, and databases closely bound together. Each component needs to be independently developed, deployed, and maintained. Supabase breaks this bottleneck by offering integrated services.
| Comparison Item | Traditional Development Model | Supabase Development Model |
|---|---|---|
| Backend services | A self-built API layer results in tight coupling between the frontend and backend. | Auto-generated Data APIs, eliminating duplicate labor Adding a table creates an API without writing backend code. Based on the PostgREST framework, the system automatically maps database tables to RESTful APIs. Creating a table generates full CRUD endpoints. There is no need to write DAO layer code. Developers focus solely on business logic. |
| User authentication | Manual integration of OAuth/JWT requires several weeks of development effort. | Multiple authentication methods available out of the box for fast access Auth provides complete user registration, login, and session management capabilities. It supports email/password login and authentication and JWT-based fine-grained access control. Each authenticated user is bound to PostgreSQL's RLS policies through roles to achieve secure data isolation across users. For example, in a task management application, you can configure policies so that users are restricted to viewing only the tasks they created. |
| File storage | A self-built file system plus CDN introduces heavy operational overhead. | S3-compatible OBS object storage, plug-and-play Storage provides S3-compatible object storage services, supporting high-performance uploads and downloads for large files. It works with Auth's RLS policies to implement fine-grained file access control to explicitly specify who can view, upload, and delete files. |
| Real-time push | Polling or self-built WebSocket leads to high complexity. | CDC real-time subscriptions (push upon change, zero-latency response) with no configuration to access Based on PostgreSQL logical replication's CDC mechanism, all data writes are captured in real time and pushed to online clients within seconds, eliminating the need for polling and ensuring instant delivery of changes. Instant messaging, multi-user co-editing, and real-time data dashboards require only a few lines of code to integrate. |
| Data governance | Relying on third-party platforms results in data lock-in. | By adopting an open-source, self-hosted deployment model, you retain full data sovereignty: Data stays within jurisdictional boundaries and never flows to third parties, meeting compliance requirements in sectors such as finance and government. |
| Development cycle | Measured in months | Measured in days |
| Cost | High | Significantly reduced |
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
