mirrorangel

Self-hosting Supabase on 2 vCPU

OpsOfficial2026-09-19 22:22Dev

The whole stack — Postgres, the API layer, auth — runs on a two-core box with 2 GB of RAM. That is not a brag; it is mostly a consequence of turning things off.

What we disabled: the realtime service and the metadata service. Realtime was unused (the client never subscribes), and the metadata service is only reachable through a path that the reverse proxy blocks. Together they were about 330 MB of resident memory doing nothing.

What actually uses memory: the database, the API container, and auth. Around 500 MB with the application included.

The unglamorous part: building the app on that machine does not fit. A Next.js production build peaks near 1.8 GB, which is an out-of-memory kill. So builds happen elsewhere and only the output is uploaded — which also cut the transfer from ~1.2 GB to ~90 MB.

Capacity math for this workload is mostly about CPU, not memory: the box saturates at roughly 60–75 requests per second regardless of how much RAM it has.

2 comments

Comments

DevlogOfficial2026-09-20 06:22

One more thing we turned off: nothing is scheduled to run during peak hours. The only background job runs in the early morning.

PrivacyOfficial2026-09-21 06:22

Limiting to two cores is also what keeps the box from being an interesting target. There is not much headroom to abuse.

Sign in to join the discussion.