惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

O
OpenAI News
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客
爱范儿
爱范儿
B
Blog
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园_首页
A
About on SuperTechFans
Engineering at Meta
Engineering at Meta
V
Visual Studio Blog
P
Proofpoint News Feed
小众软件
小众软件
Google DeepMind News
Google DeepMind News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
Y
Y Combinator Blog
Recorded Future
Recorded Future
博客园 - 聂微东
WordPress大学
WordPress大学
博客园 - 【当耐特】
腾讯CDC
T
Tailwind CSS Blog
The Register - Security
The Register - Security
V
V2EX
S
SegmentFault 最新的问题
IT之家
IT之家
D
Docker
I
InfoQ
大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
月光博客
月光博客
Stack Overflow Blog
Stack Overflow Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Jina AI
Jina AI
The Cloudflare Blog
量子位
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
美团技术团队
B
Blog RSS Feed

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Supabase Edge Functions Review: Deno on the Edge for Postgres Backends
pickuma · 2026-05-22 · via DEV Community

I deployed my first Supabase Edge Function in January 2026 — a webhook handler that received Stripe payment events, validated them against the Supabase auth system, and inserted records into a Postgres table with row-level security enforced at the database layer. I have since deployed twelve more functions handling authentication callbacks, file processing triggers, API endpoints for a mobile app, and a scheduled cleanup job. After five months of production use alongside Cloudflare Workers and AWS Lambda functions that serve the same application, I have a clear picture of where Supabase Edge Functions deliver unique value and where they fall short of the alternatives.

The Deno Runtime: TypeScript Without the Build Chain

Supabase's decision to use Deno as the Edge Functions runtime is the most consequential architectural choice in the product, and it took me about two weeks of use to understand why it matters. A Deno-based Edge Function is a single TypeScript file — no tsconfig.json, no bundler configuration, no node_modules, and no build step. You write a handler function that receives a Request and returns a Response, deploy it with supabase functions deploy, and it runs.

When I built the same Stripe webhook handler as a Cloudflare Worker, the workflow required installing wrangler, configuring a wrangler.toml file, writing the handler in a module syntax that esbuild could bundle, and managing a separate build step that produced the bundled output. With AWS Lambda and the Serverless Framework, the workflow required a serverless.yml configuration, a deployment package build step, and IAM role configuration that took three iterations to get right because the function needed both DynamoDB and SQS permissions. The Supabase Edge Function workflow eliminated all of that: I wrote a stripe-webhook/index.ts file, ran supabase functions deploy stripe-webhook, and the function was live at https://[project-ref].functions.supabase.co/stripe-webhook in approximately 40 seconds from deploy command to working endpoint.

The Deno standard library provides web-standard APIs that eliminate dependency overhead. Request and Response are native types, fetch is available without importing node-fetch, crypto.subtle handles JWT verification and HMAC signing without a library, and URLPattern provides route matching. My Stripe webhook handler — including Stripe signature verification, database writes, and error responses — is 94 lines of TypeScript with zero npm dependencies. The equivalent Node.js version with Express, the Stripe SDK, and a database client would require a package.json with 8 to 12 dependencies and a bundler configuration.

The Database and Auth Integration Is the Real Differentiator

The feature that sold me on Edge Functions — and the feature that has kept me using them for new endpoints — is the pre-wired integration with the Supabase platform. When an Edge Function receives a request, the Supabase client is available in the execution context with the project's API key, database URL, and authentication token already configured. If the request includes a Supabase auth token in its Authorization header, the client automatically validates it against GoTrue, identifies the user, and enforces Row Level Security (RLS) policies at the database layer.

I want to illustrate this with a concrete example. My application has an API endpoint that returns a user's order history. The endpoint requires that the user is authenticated and that the query only returns rows where user_id matches the authenticated user. On Supabase Edge Functions, the implementation is a database query that the RLS policy scopes automatically — the function does not need to extract the user ID from the token, validate it against the auth system, or add a WHERE clause to every query. On Cloudflare Workers, the same endpoint required 62 lines of TypeScript just for auth plumbing: extracting the JWT from the Authorization header, fetching the JWKS endpoint from GoTrue, verifying the token signature, extracting the user ID from the claims, and passing it as a parameter to every database query. The Workers version works, but it required maintaining authentication code that Supabase Edge Functions handle in zero lines.

Edge Functions share the same JWT secret as your Supabase project. When a function receives a request with a valid Supabase auth token, the Supabase client inside the function automatically inherits the user's identity and enforces Row Level Security policies. In my Stripe webhook handler, the function validates the webhook signature from Stripe, looks up the Supabase user by email in the Stripe event, and writes to a billing_events table — all without manually managing auth tokens or database permissions.

The integration extends to storage triggers. I configured an Edge Function to fire on every file upload to a Supabase storage bucket, which runs an image resizing pipeline through the sharp library (available via Deno's npm compatibility layer). The function receives the file metadata in the event payload, downloads the original from storage, generates three resized variants, and uploads them back to the same bucket. This pattern — serverless function triggered by a platform event, with direct access to the platform's storage and database — would require a queue, an event bus, and IAM role configuration on AWS. On Supabase, it is a configuration option and a handler function.

Where the Limits Start to Hurt

I need to be direct about the constraints, because the 10-second execution timeout and 256 MB memory limit have forced me to move workloads off Edge Functions twice in five months.

The first time was a batch processing job that needed to generate monthly invoice PDFs for approximately 1,200 users. The job required querying the database for each user's billing records, rendering an HTML template to PDF, and uploading the result to storage. Each PDF generation took approximately 2.5 seconds, and processing 1,200 users sequentially would exceed the 10-second timeout by two orders of magnitude. I attempted to parallelize by triggering one function invocation per user, but the function's memory limit prevented loading the HTML template library and a full user record simultaneously for the largest accounts. I moved the job to an AWS Lambda function with a 15-minute timeout and 1,024 MB of memory, where it completes in approximately 52 seconds for all 1,200 users. The Lambda function costs about $0.35 per monthly run and required IAM configuration, but the Supabase Edge Function could not complete the workload at all within its constraints.

The second time was a data export endpoint that needed to stream a CSV file of query results to the client. The function's memory limit prevented loading the full result set into memory — the largest export was approximately 180 MB of raw data — and the function has no streaming response capability. I ended up generating the export through a database function that wrote to a storage bucket and returning a signed URL, which worked but added complexity that a streaming response would have avoided.

The Deno ecosystem is also smaller than Node.js. When I needed to use the @stripe/stripe-js package for client-side Stripe integration — not the webhook handler, but a checkout session creation endpoint — the npm compatibility layer handled it, but the import took approximately 800 milliseconds of cold-start time to resolve the dependency graph. Hot starts (subsequent invocations within the same deployment) were faster at around 40 milliseconds, but the cold-start penalty for npm packages through the compatibility layer is worth measuring for latency-sensitive endpoints. For packages that have native Deno equivalents — std/http, std/crypto, std/encoding — the import is near-instant.

The Local Development Experience Saves Real Time

Supabase's local development environment is one of the platform's strongest selling points, and it works as advertised for Edge Functions. Running supabase start launches a complete local Supabase instance in Docker: Postgres, GoTrue for auth, a storage API compatible with the production storage service, and the Edge Functions runtime. My entire development workflow — writing function code, testing against the local database with RLS policies, simulating auth flows, and verifying storage triggers — runs on my laptop with no network dependency.

I timed my development cycle for a new function compared to Cloudflare Workers. On Supabase, writing the function, testing it locally, and deploying it took 23 minutes from first line of code to verified production endpoint. On Cloudflare Workers, the same function took 41 minutes — 18 minutes of which was spent configuring wrangler dev to proxy auth requests to the remote Supabase instance because Cloudflare's local runtime cannot replicate Supabase's auth integration.

The log and debug experience has improved since early 2026. The dashboard shows invocation counts, error rates, and execution durations per function. Real-time logs — streaming console output from deployed functions — became available on the Pro plan in March 2026 and display console.log, console.error, and unhandled exception traces with stack frames. When I need more detailed tracing, I add structured JSON logging to the function's console output and parse it through an external observability platform, which is not as integrated as AWS CloudWatch but works without additional infrastructure.

When I Choose Edge Functions Over Workers or Lambda

After five months and twelve production functions, my decision framework is straightforward. I choose Supabase Edge Functions when the function's primary job is to mediate between the client and the Supabase database or storage layer — CRUD endpoints, auth-protected API routes, webhook handlers that write to the database, and file processing triggers. The pre-wired integration saves development time and eliminates auth plumbing that would require writing and maintaining code on any other platform. For a function that queries the database, validates an auth token, and returns a JSON response, an Edge Function typically takes half to one-third the lines of code of an equivalent Cloudflare Worker or Lambda function.

I choose Cloudflare Workers when the function needs to run in multiple geographic regions for latency reasons and when the function does not primarily interact with Supabase — proxy endpoints, redirect logic, A/B testing middleware, and API gateways that route to multiple backends. Workers deploy to 300-plus locations globally, while Supabase Edge Functions deploy to a smaller set of regions that maps to Supabase's infrastructure footprint. For a function that needs to respond in under 50 milliseconds from anywhere in the world, Workers' physical footprint is the deciding factor.

I choose AWS Lambda when the function needs to run for more than 10 seconds, use more than 256 MB of memory, or access AWS services that are not available through Supabase — SQS, DynamoDB, EventBridge, or Step Functions. Lambda's 15-minute timeout and 10 GB memory ceiling make it the only option for batch processing, report generation, and CPU-intensive workloads. I use Lambda as the complement to Edge Functions, not as a replacement — Lambda handles the heavy lifting, and Edge Functions handle the request-response layer.


Originally published at pickuma.com. Subscribe to the RSS or follow @pickuma.bsky.social for new reviews.