Agent skill

Supabase Incident Runbook

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute Supabase incident response: dashboard health checks, connection pool status, pgstatactivity queries, RLS debugging, Edge Function logs, storage health, and escalation.

MITAuto-check passedDevOps & Cloud

Install Supabase Incident Runbook

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-incident-runbook -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace supabase-incident-runbook --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/supabase-incident-runbook .claude/skills/supabase-incident-runbook && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
supabase-incident-runbook
GitHub stars
2.8k
Token cost
~2k tokens
SKILL.md length
686 words
Files
5 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute Supabase incident response: dashboard health checks, connection pool status, pgstatactivity queries, RLS debugging, Edge Function logs, storage health, and escalation.

  • Works in 3 steps: Triage — Platform vs. Application → Database Diagnostics with pg_stat_activity → RLS Debugging, Edge Functions, and Storage
  • Responding to Supabase outages
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls curl and jq; reaches status.supabase.com

What it does

Supabase Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Supabase incident response: dashboard health checks, connection pool status, pgstatactivity queries, RLS debugging, Edge Function logs, storage health, and escalation. Use when responding to Supabase outages, investigating production errors, debugging connection issues, or preparing evidence for Supabase support escalation. Trigger with "supabase incident", "supabase outage", "supabase down", "supabase on-call", "supabase emergency", "supabase broken", or "supabase connection issues".

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/diagnostics.md`, `references/errors.md` and `references/examples.md`). Compatibility notes: Designed for Claude Code

It sits in DevOps & Cloud, covering Incident response and Runbooks and postmortems. It works with Supabase. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Responding to Supabase outages
  • Investigating production errors
  • Debugging connection issues
  • Preparing evidence for Supabase support escalation

Example prompts

  • “supabase incident”
  • “supabase outage”
  • “supabase down”
  • “/supabase-incident-runbook”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Grep, Bash(npx supabase:*), Bash(supabase:*), Bash(curl:*), Bash(psql:*)

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Triage — Platform vs. Application
  2. Database Diagnostics with pg_stat_activity
  3. RLS Debugging, Edge Functions, and Storage

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Bash(npx supabase:*)
    • Bash(supabase:*)
    • Bash(curl:*)
    • Bash(psql:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • status.supabase.com

    Also links to:

    • supabase.com
    • postgresql.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Supabase Incident Runbook loads about 2k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 686 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 686 words, ~2,017 tokens.

Download SKILL.mdSave it as .claude/skills/supabase-incident-runbook/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
supabase-incident-runbook
description
Execute Supabase incident response: dashboard health checks, connection pool status, pg_stat_activity queries, RLS debugging, Edge Function logs, storage health, and escalation. Use when responding to Supabase outages, investigating production errors, debugging connection issues, or preparing evidence for Supabase support escalation. Trigger with "supabase incident", "supabase outage", "supabase down", "supabase on-call", "supabase emergency", "supabase broken", or "supabase connection issues".
allowed-tools
Read, Grep, Bash(npx supabase:*), Bash(supabase:*), Bash(curl:*), Bash(psql:*)
compatibility
Designed for Claude Code
version
1.54.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, supabase, incident-response, debugging, operations, runbook

Supabase Incident Runbook

Overview

A structured response for Supabase-backed application failures. Work three layers in order: triage platform vs. application, run pg_stat_activity database diagnostics, then debug RLS, Edge Functions, and storage — ending with an evidence bundle for support escalation.

When to use: Production errors involving Supabase, degraded API response times, connection pool exhaustion, silent data filtering from RLS, Edge Function cold start failures, or storage upload/download errors.

Each step below gives the workflow plus a first command. The complete copy-paste blocks for every step live in references/diagnostics.md.

Prerequisites

  • Supabase project with dashboard access at supabase.com/dashboard
  • @supabase/supabase-js v2+ installed in your project
  • Supabase CLI installed for Edge Function log access
  • Direct database connection string (for psql diagnostics)
  • Access to status.supabase.com for platform health

Instructions

Step 1: Triage — Platform vs. Application

Determine whether the issue is a Supabase platform incident or an application-level bug. Check the official status page first, then verify SDK client connectivity. Use Read to inspect the app's Supabase env config and Grep to scan application logs for HTTP error codes (401=auth, 429=rate limit, 500=server).

bash
# Check official status page — is this a platform-wide incident?
curl -sf https://status.supabase.com/api/v2/status.json | jq '.status'
# Expected: { "indicator": "none", "description": "All Systems Operational" }

If the status page is green, run the SDK healthCheck() (a select 1 against a small _health_check table) to measure latency and confirm connectivity. A green platform plus a failing health check points at your queries, RLS, or Edge Functions — the SDK block, incident-check query, and full decision tree are in references/diagnostics.md.

Step 2: Database Diagnostics with pg_stat_activity

Connect directly via psql (or the Supabase SQL Editor) to inspect connections, find stuck queries, and detect leaks.

sql
-- Current connections grouped by state — the first thing to run
SELECT state, count(*) AS connections,
       max(extract(epoch FROM age(now(), state_change)))::int AS max_idle_seconds
FROM pg_stat_activity
WHERE datname = current_database()
GROUP BY state ORDER BY connections DESC;
-- WARNING: If idle > 20 or idle_in_transaction > 0, you have a leak

From there, drill into long-running queries, connection-limit headroom (pct_used > 80% means enable Supavisor pooling), the pg_cancel_backend / pg_terminate_backend kill switches, and an app-side get_connection_stats() RPC — all in references/diagnostics.md.

Step 3: RLS Debugging, Edge Functions, and Storage

Debug silent data filtering from Row Level Security, inspect Edge Function execution, and verify storage. The classic RLS tell is an anon query returning fewer rows than the same query under the service role.

sql
-- List every RLS policy on the affected table
SELECT policyname, cmd, permissive,
       pg_get_expr(qual, polrelid) AS using_expression
FROM pg_policy
JOIN pg_class ON pg_class.oid = polrelid
WHERE relname = 'your_table_name';

Continue with JWT-claim simulation in the SQL Editor, the anon-vs-service-role SDK diff (debugRLS), Edge Function log tailing (npx supabase functions logs), cold-start detection, and a storage bucket upload/download check — full blocks in references/diagnostics.md.

Output

After running this incident runbook, you will have:

  • Platform status assessment — confirmed whether the issue is Supabase-side or application-side
  • SDK health check — latency measurement and connectivity verification via createClient
  • Connection pool analysis — pg_stat_activity showing active, idle, and leaked connections
  • Long-running query identification — stuck queries with PIDs ready for cancellation
  • RLS policy diagnosis — side-by-side comparison of anon vs. service role query results
  • Edge Function status — deployment status, cold start detection, and log inspection
  • Storage health report — bucket accessibility and upload/download verification
  • Evidence bundle — complete diagnostic data for Supabase support escalation
Show full SKILL.md (242 more words)Show less

Error Handling

ErrorCauseSolution
FetchError: request failedSupabase API unreachableCheck status.supabase.com; verify network/DNS
connection refused on port 5432Direct DB access blocked or wrong credentialsUse pooler URL (port 6543) or check dashboard connection strings
too many clients alreadyConnection pool exhaustedKill idle-in-transaction connections; enable Supavisor pooling
permission denied for tableRLS blocking or wrong roleCheck policies with pg_policy; verify JWT claims
WORKER_LIMIT in Edge FunctionMemory/CPU exceededReduce function payload size; optimize imports
JWT expiredToken not refreshingVerify autoRefreshToken: true in createClient options
storage/object-not-foundFile deleted or wrong pathCheck bucket policies; verify path with service role client
rate limit exceeded (429)Too many API requestsImplement exponential backoff; contact Supabase for limit increase

Examples

Example 1 — Quick triage script. A single async function that pings database, auth, storage, and realtime in sequence and prints an OK/ERROR line per service — the fastest "what's actually down?" check.

typescript
// One-line database probe (the first check in the full triage script)
const { error } = await supabase.from('_health_check').select('id').limit(1);
console.log('Database:', error ? `ERROR: ${error.message}` : 'OK');

Two more worked examples — a connection-leak detector SQL query that labels each connection LEAK/STALE/OK, and an escalation evidence-bundle builder that assembles diagnostics into JSON for Supabase support — are in references/examples.md.

Resources

Next Steps

  • For GDPR compliance and data handling, see supabase-data-handling
  • For performance tuning and query optimization, see supabase-performance-tuning
  • For observability and monitoring setup, see supabase-observability
  • For common error patterns and fixes, see supabase-common-errors

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/.curated/supabase-incident-runbook of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/diagnostics.md
  • references/errors.md
  • references/examples.md
  • references/immediate-actions-by-error-type.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Supabase Incident Runbook next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Supabase Incident Runbook compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Supabase Incident Runbook this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Oncallpigweed-project/pigweed548—~963Automated safety check: PassApache-2.0
Activation Governance Chaos RolloutAli-Marandi/DataSense107—~1.9kAutomated safety check: PassMIT
Incident Response686f6c61/alfred-dev117—~1.1kAutomated safety check: PassMIT
Superset Incident Triagesuperset-sh/superset15k—~1kAutomated safety check: PassCustom licence
Post-Incident DebriefVeryGoodOpenSource/vgv-wingspan109—~1.9kAutomated safety check: PassMIT

Similar skills

  • Oncall

    pigweed-project/pigweed

    Pigweed oncall rotation runbooks and maintenance workflows (such as rolling CIPD client tools for b/315378787).

    548 GitHub stars~963 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Design, validate, and govern fail-closed customer-activation automations that use an Outbox/worker pattern.

    107 GitHub stars~1.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    686f6c61/alfred-dev

    Protocolo de respuesta ante incidentes en produccion: triaje, mitigacion, causa raiz y postmortem.

    117 GitHub stars~1.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Superset Incident Triage

    superset-sh/superset

    Does a read-only first pass on a possible production incident: gathers deploy, Sentry and health-check signals, proposes a severity and status message, then stops for human approval.

    15k GitHub stars~1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Post-Incident Debrief

    VeryGoodOpenSource/vgv-wingspan

    Produces a blameless post-incident debrief with timeline, root cause and follow-up actions after an outage, failed release or significant bug, while details are fresh.

    109 GitHub stars~1.9k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • SRE Engineer

    Jeffallan/claude-skills

    Defines SLIs, SLOs and error budgets, and sets up golden-signal monitoring, blameless postmortems, toil automation and chaos experiments for production systems.

    12k GitHub stars~1.7k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Supabase Incident Runbook

What does Supabase Incident Runbook do?

Execute Supabase incident response: dashboard health checks, connection pool status, pgstatactivity queries, RLS debugging, Edge Function logs, storage health, and escalation. Supabase Incident Runbook is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Supabase incident response: dashboard health checks, connection pool status, pgstatactivity queries, RLS debugging, Edge Function logs, storage health, and escalation.

When should I use Supabase Incident Runbook?

Supabase Incident Runbook fits situations like: responding to Supabase outages; investigating production errors; debugging connection issues; preparing evidence for Supabase support escalation.

How do I install Supabase Incident Runbook in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-incident-runbook -a claude-code`. Or copy the skill folder (skills/.curated/supabase-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/supabase-incident-runbook in your project. Claude Code loads it when a task matches its description.

How do I install Supabase Incident Runbook in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-incident-runbook -a codex`. Or copy the skill folder (skills/.curated/supabase-incident-runbook in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/supabase-incident-runbook in your project. Codex loads it when a task matches its description.

Can I use Supabase Incident Runbook in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill supabase-incident-runbook -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/supabase-incident-runbook, .gemini/skills/supabase-incident-runbook, .github/skills/supabase-incident-runbook and .opencode/skills/supabase-incident-runbook in your project.

What does Supabase Incident Runbook need to run?

Going by SKILL.md and its folder, Supabase Incident Runbook needs the command-line tools its instructions call (curl and jq). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Grep, Bash(npx supabase:*), Bash(supabase:*), Bash(curl:*), Bash(psql:*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Supabase Incident Runbook access the network?

SKILL.md names 3 domains. In commands or code: status.supabase.com; the agent is likely to contact it when it follows the instructions. As links in the text: supabase.com and postgresql.org. This is read from the text; nothing was executed.

Is Supabase Incident Runbook safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Supabase Incident Runbook use?

Supabase Incident Runbook is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Supabase Incident Runbook use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.7k tokens, read only when the agent opens those files.

What are the alternatives to Supabase Incident Runbook?

Skills that share tags, products or a category with Supabase Incident Runbook: Oncall (pigweed-project/pigweed, 548 stars), Activation Governance Chaos Rollout (Ali-Marandi/DataSense, 107 stars), Incident Response (686f6c61/alfred-dev, 117 stars) and Superset Incident Triage (superset-sh/superset, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Supabase Incident Runbook?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.