Skip to content

Bump PostgREST for v16.4 - #2529

Open
laurenceisla wants to merge 3 commits into
developfrom
laurence/pgrst-16-4
Open

laurenceisla wants to merge 3 commits into
developfrom
laurence/pgrst-16-4

Conversation

@laurenceisla

Copy link
Copy Markdown
Contributor

What kind of change does this PR introduce?

Updates PostgREST to latest v16.4

What is the current behavior?

We're currently in v14.18, a major and some minor versions behind.

@laurenceisla
laurenceisla requested review from a team as code owners October 6, 2026 03:02
@laurenceisla laurenceisla changed the title Laurence/pgrst 16 4 Bump PostgREST for v16.4 Oct 6, 2026
Comment thread ansible/vars.yml Outdated
Comment on lines +10 to +12
postgresorioledb-17: "17.11.0.005-orioledb-pgrst-16-4"
postgres17: "17.11.0.005-pgrst-16-4"
postgres15: "15.19.0.005-pgrst-16-4"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please remove suffix before merge to develop.

@brainrake brainrake left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PostgREST 14.18 to 16.4 changelog review. 16.0 is a major with breaking changes.

Verified

  • PG13 dropped in 16.0. We ship 15 and 17 only.
  • Embedded table filters with an alias are deprecated, not removed. Default keeps old behavior.
  • Graceful shutdown: salt drains via Envoy before stopping postgrest@<slot>. No unit change needed.
  • Admin server and /live on 3001/3003 unchanged.
  • ARM binary is pulled from S3, not the GitHub asset in ansible/vars.yml.
  • 16.1, 16.3, 16.4 are JWT and config fixes only.
  • Worker buildConfig() emits role-claim-key = ".role" and db-schema. Both legacy names still parse in 16.4. Old role claim syntax works via the 16.2 shim with a warning.
  • role_claim_key is not user-editable. Default .role only.
  • db-use-legacy-gucs was removed in v12 and is already ignored.

Unknown

  • Projects with db_schema containing pg_catalog or information_schema. 16.0 fails at startup. The API and DB do not validate this field. A bad value crash-loops with no start limit.
  • S3 arm64.tar.xz build. 16.x aarch64 is now static, not Ubuntu-based. Not tested.
  • Clients sending Prefer: timezone with handling=lenient. Invalid timezones now always error.
  • Vary header added to responses. Not checked against Kong or CDN caching.

Follow-up

  • Check db_schema in middleware db:
    select project_ref, db_schema
    from public.postgrest_config
    where db_schema ~* '(^|,)\s*(pg_catalog|information_schema)\s*(,|$)';```
  • Worker should emit jwt-role-claim-key = "$.role" to stop the deprecation warning.

@laurenceisla

laurenceisla commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor Author

Thanks for the review!

Unknown

  • Projects with db_schema containing pg_catalog or information_schema. 16.0 fails at startup. The API and DB do not validate this field. A bad value crash-loops with no start limit.

The replica keeps disallowing this, will come back to it later.

  • S3 arm64.tar.xz build. 16.x aarch64 is now static, not Ubuntu-based. Not tested.

Manually tested AMI in staging (see pic) and also Supadev Smoke tests are passing/running (Oct. 6 ones).

image

We used to have PostgREST tests when opening a PR, but they don't seem to be running right now?

https://github.com/supabase/postgres/blob/develop/testinfra/test_ami_nix.py#L462-L467

  • Clients sending Prefer: timezone with handling=lenient. Invalid timezones now always error.

There's an internal conversation about this. IIUC, the consensus was to allow it.

  • Vary header added to responses. Not checked against Kong or CDN caching.

Not sure about this, will verify.

Follow-up

  • Check db_schema in middleware db:
    select project_ref, db_schema
    from public.postgrest_config
    where db_schema ~* '(^|,)\s*(pg_catalog|information_schema)\s*(,|$)';```

Replica problem as mentioned above.

  • Worker should emit jwt-role-claim-key = "$.role" to stop the deprecation warning.

Planned, but not a blocker for now: the deprecation warning only shows on startup / schema reload.

cc. @steve-chavez For confirmation on these

@brainrake

Copy link
Copy Markdown
Collaborator

We used to have PostgREST tests when opening a PR, but they don't seem to be running right now?

They run in the amis / build jobs (testinfra-ami-build.yml), all green on this PR. They use a fixed base.conf, so they don't cover db-schema or the S3 path for salt hosts.

@laurenceisla

Copy link
Copy Markdown
Contributor Author

Thanks for the info. A follow up of the pending reviews:

  • Check db_schema in middleware db:
    select project_ref, db_schema
    from public.postgrest_config
    where db_schema ~* '(^|,)\s*(pg_catalog|information_schema)\s*(,|$)';```

Replica problem as mentioned above.

Solved it by checking the table directly and only one active project is using that configuration. So this shouldn't be a blocker IMO.

  • Vary header added to responses. Not checked against Kong or CDN caching.

Not sure about this, will verify.

AFAICS we're not allowing caching in PostgREST, or more specifically it's blocked for JSON responses. So this won't affect that, but it'll be useful for when caching is finally enabled.

... and also Supadev Smoke tests are passing/running (Oct. 6 ones).

All Supadev Smoke Tests steps are passing correctly except for the Upgrade ones. I get the following error: https://github.com/supabase/supadev/actions/runs/37714933457/job/113465267934#step:24:1546. I asked the team what the issue might be.

@brainrake

brainrake commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Open:

  • Remediate project that will crash loop
  • Verify handling of Vary header
  • Run Upgrade smoke test
  • Verify blast radius of Prefer: timezone error

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants