Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

stack: outbound HTTPS from Postgres (http, pg_net) fails certificate verification on native darwin-arm64

クローズ
#7,008 コメント 0 件 リアクション 0 件 担当者 1 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

@7ttp がすでに取り組んでいます。

2026年10月6日 から。

  • #7023 @7ttp による — オープン

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
32/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
macos, postgresql, typescript

調査の方向性

Start from how supabase start --runtime native launches the bundled darwin-arm64 Postgres (experimental stack) and which env vars it actually injects into that process. Trace OPENSSLDIR / CA lookup for the shipped OpenSSL dylib versus host /etc/ssl/cert.pem, and how http vs pg_net sessions pick up curl/OpenSSL options. Done when HTTPS http_get/pg_net succeed on native like Docker without a per-session CURLOPT_CAINFO workaround.

索引モデルが issue の本文から書いたものです。

説明

🐛 Bug supabase/cli
Affected area

Local development

Supabase CLI version

2.119.0

Operating system

macOS 26.3 (Apple silicon), Postgres artifact 17.11.0.002-r0 (darwin-arm64). Linux not tested.

Installation method

npm (supabase package)

Command
SUPABASE_EXPERIMENTAL_STACK=1 supabase start --runtime native
Actual output

Every HTTPS request made from inside Postgres fails. Plain HTTP works.

create extension http with schema extensions;
select status from extensions.http_get('https://example.com');
-- ERROR: SSL certificate OpenSSL verify result: unable to get local issuer certificate (20)

create extension pg_net;
select net.http_get('https://example.com');  -- id 1
select net.http_get('http://example.com');   -- id 2
select id, status_code, error_msg from net._http_response;
-- 1 | (null) | SSL peer certificate or SSH remote key was not OK
-- 2 | 200    |

Cause, as far as I can tell:

  • The bundled libcrypto.3.dylib has OPENSSLDIR compiled as /nix/store/5ffn4pdw6mvabzrrlss7k3gabnqw2f9g-openssl-3.6.0/etc/ssl, which does not exist on the host, so OpenSSL has no trust store.
  • SSL_CERT_FILE cannot fix it from outside: the Postgres process gets a fixed environment (DYLD_LIBRARY_PATH, HOME, LANG, NIX_PGLIBDIR, PATH, PGDATA, PGSODIUM_KEY_FILE, POSTGRES_*, PWD, SHLVL, TMPDIR). Exporting SSL_CERT_FILE=/etc/ssl/cert.pem before supabase start reaches the stack host process but not Postgres.

The only workaround I found is per session, and only for http:

select extensions.http_set_curlopt('CURLOPT_CAINFO', '/etc/ssl/cert.pem');

It does not help pg_cron jobs, triggers or pg_net, which run in their own sessions.

Expected behavior

HTTPS from http and pg_net works on native as it does on Docker. For example, the CLI could set SSL_CERT_FILE for Postgres to the host bundle (/etc/ssl/cert.pem on macOS), or the artifact could ship a CA bundle and point OPENSSLDIR at it.

Steps to reproduce
  1. mkdir repro && cd repro && supabase init
  2. SUPABASE_EXPERIMENTAL_STACK=1 supabase start --runtime native
  3. Run the SQL above against the DB URL from supabase status.

I investigated this with help from an AI coding assistant (Claude Code), which also drafted this text. The results above come from real runs.

主要言語
TypeScript
スター
2.4k
フォーク
533
平均マージ
1日 5時間
マージ済み PR(30日)
333

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

supabase/cli のほかの issue

supabase/cli の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。