Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

stack: outbound HTTPS from Postgres (http, pg_net) fails certificate verification on native darwin-arm64

Abierto
#7,008 0 comentarios 0 reacciones 1 asignado Ver en GitHub

Los mantenedores suelen responder en 1 día

@7ttp ya está trabajando en esto.

Desde el 6/10/2026.

  • #7023 de @7ttp — abierto

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
32/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
macos, postgresql, typescript

Línea de trabajo

Start from how supabase start --runtime native launches the bundled darwin-arm64 Postgres (experimental stack) and which env vars it actually injects into that process. Trace OPENSSLDIR / CA lookup for the shipped OpenSSL dylib versus host /etc/ssl/cert.pem, and how http vs pg_net sessions pick up curl/OpenSSL options. Done when HTTPS http_get/pg_net succeed on native like Docker without a per-session CURLOPT_CAINFO workaround.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

🐛 Bug supabase/cli
Affected area

Local development

Supabase CLI version

2.119.0

Operating system

macOS 26.3 (Apple silicon), Postgres artifact 17.11.0.002-r0 (darwin-arm64). Linux not tested.

Installation method

npm (supabase package)

Command
SUPABASE_EXPERIMENTAL_STACK=1 supabase start --runtime native
Actual output

Every HTTPS request made from inside Postgres fails. Plain HTTP works.

create extension http with schema extensions;
select status from extensions.http_get('https://example.com');
-- ERROR: SSL certificate OpenSSL verify result: unable to get local issuer certificate (20)

create extension pg_net;
select net.http_get('https://example.com');  -- id 1
select net.http_get('http://example.com');   -- id 2
select id, status_code, error_msg from net._http_response;
-- 1 | (null) | SSL peer certificate or SSH remote key was not OK
-- 2 | 200    |

Cause, as far as I can tell:

  • The bundled libcrypto.3.dylib has OPENSSLDIR compiled as /nix/store/5ffn4pdw6mvabzrrlss7k3gabnqw2f9g-openssl-3.6.0/etc/ssl, which does not exist on the host, so OpenSSL has no trust store.
  • SSL_CERT_FILE cannot fix it from outside: the Postgres process gets a fixed environment (DYLD_LIBRARY_PATH, HOME, LANG, NIX_PGLIBDIR, PATH, PGDATA, PGSODIUM_KEY_FILE, POSTGRES_*, PWD, SHLVL, TMPDIR). Exporting SSL_CERT_FILE=/etc/ssl/cert.pem before supabase start reaches the stack host process but not Postgres.

The only workaround I found is per session, and only for http:

select extensions.http_set_curlopt('CURLOPT_CAINFO', '/etc/ssl/cert.pem');

It does not help pg_cron jobs, triggers or pg_net, which run in their own sessions.

Expected behavior

HTTPS from http and pg_net works on native as it does on Docker. For example, the CLI could set SSL_CERT_FILE for Postgres to the host bundle (/etc/ssl/cert.pem on macOS), or the artifact could ship a CA bundle and point OPENSSLDIR at it.

Steps to reproduce
  1. mkdir repro && cd repro && supabase init
  2. SUPABASE_EXPERIMENTAL_STACK=1 supabase start --runtime native
  3. Run the SQL above against the DB URL from supabase status.

I investigated this with help from an AI coding assistant (Claude Code), which also drafted this text. The results above come from real runs.

Lenguaje dominante
TypeScript
Estrellas
2.4k
Forks
531
Merge medio
1 d 2 h
PR fusionados (30 d)
347

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de supabase/cli

Todos los issues de supabase/cli

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.