SOURCE-AVAILABLE · LOCAL-FIRST · EXPLICIT COVERAGE

Back up the recoverable parts of a Supabase project

pgDumpster packages one hosted Supabase project into a portable bundle with checksums, terminal coverage outcomes and documented restore limits.

It is a local CLI, not a pgDumpster SaaS: pgDumpster does not operate an account, hosted backup copy or proxy for your project data. You choose the environment and destination - local storage or configured S3-compatible storage - then review a deterministic restore plan before a target changes.

pgDumpster / verified backupSTATUS: COVERAGE RECORDED

BACKUP RUN

discovering project resources

databaseaccounted for

storageaccounted for

edge functionsaccounted for

project configurationaccounted for


exporting applicable recoverable state

recording platform and manual limits

writing integrity and consistency evidence

result: complete, limits, or failed

POSTGRESQLSTORAGEAUTHEDGE FUNCTIONSVERIFY

WHAT IT IS

A database dump is not a project backup

PostgreSQL is only one part of a hosted Supabase project. Storage object bytes, Auth state, Edge Functions and applicable project configuration sit outside a conventional database dump.

pgDumpster captures the exportable project-scoped state it can reach, then reports what was captured, what was unavailable and what needs an operator procedure.

It never represents an unavailable value, a replacement credential or an external system as an identical automatic restore.

DATABASE-ONLY BACKUP

project
└── PostgreSQL

PGDUMPSTER

hosted project
├── PostgreSQL
├── file storage
├── exportable Auth / API state
├── deployable Edge source
├── applicable configuration
└── coverage + integrity evidence
 ↓
portable backup bundle

BACKUP COVERAGE

Know what the bundle contains - and what it cannot contain

Coverage is component-level, not a marketing label. pgDumpster records a terminal outcome for every registered component, including `not_exportable` and `failed`.

AreaWhat pgDumpster capturesRestore expectation
PostgreSQLLogical database state, roles, schema, data, migrations and supported extension state.Exact or semantic, per component
File StorageBucket configuration, object bytes and supported metadata.Bytes are checksum-verified
Auth and APIExportable Auth data/configuration, provider configuration and API-key definitions.Private material and replacements have limits
Edge FunctionsDeployable source trees, deployment metadata and a secret inventory.Source is deployable; secret values can be unavailable
Control planeApplicable project and service configuration, plus capability evidence.Restored only where a current documented write contract and handler exist
VerificationManifest, coverage, checksums and consistency evidence.Inspectable offline

A successful backup can still be complete_with_platform_limits. Read the coverage report before relying on it for recovery.

RECOVERY LIMITS

Deliberate recovery, not an identical-project promise

pgDumpster is designed to make limitations visible. These limits are part of a correct recovery decision, not hidden footnotes.

No atomic project snapshot

Supabase does not expose one transaction spanning PostgreSQL, Storage, Edge Functions and Management APIs. `verified` is pgDumpster's application-level stabilization mode, not a platform-wide atomic snapshot.

No silent completeness claim

Every registered component gets a terminal coverage outcome. A result can be `complete_with_platform_limits`; it is not an identical-project claim.

Private or platform-held material

Private Auth signing material, some Edge secret values and other values Supabase does not return stay explicit manual/platform actions.

Replacement rather than equality

When a target API generates a new secret, pgDumpster records the required protected rotation mapping. It does not call a different secret an identical restore.

External systems stay external

DNS, SMTP, OAuth-provider resources, source Git repositories, organization membership and billing are outside a single hosted-project backup.

Some platform surfaces are manual

Analytics/Iceberg data, read-only PgBouncer, backup schedules, custom/vanity domains, disk/autoscale, add-ons, read replicas, log drains, PrivateLink and JIT access remain explicit platform limits until a supported write contract and handler exist.

Read the generated restore plan, manual actions and parity report for the actual source bundle. Those artifacts are more specific than this overview.

BEFORE YOU INSTALL

Access and runtime requirements are real prerequisites

pgDumpster is intended for operators who control the source project and the backup destination. The CLI checks access, dependencies and project health with doctor, but a passing install alone is not a recovery drill.

Runtime

Node.js >=22.15.0 <23 or >=24 <25, Supabase CLI >=2.111.0 <3.0.0, and a reachable Docker-compatible daemon for the current database workflow.

Source access

A Supabase Management API access token, a linked workspace or database URL, and a privileged Storage credential that pgDumpster can prove suitable.

Destination

Local storage or configured S3-compatible storage. Cloudflare R2 has live interoperability evidence; do not assume every provider has identical evidence.

Encryption

The `age` executable plus a recipient for encrypted backups; an identity file is required to read an encrypted archive.

INTO - AND OUT OF - THE DUMPSTER

Discover. Back up. Verify. Plan. Apply deliberately.

01

Discover

Identify the project resources the authenticated operator can access.

02

Back up

Capture applicable exportable state, then produce coverage and integrity evidence.

03

Verify

Inspect coverage and validate the bundle offline before trusting it.

04

Restore

Create a deterministic plan first. `--apply` is required for mutation and blocked work does not modify a target.

The disposable source-to-clean-target recovery flow passed as a local live E2E and as protected exact-SHA release evidence for v0.1.2. CI runner setup is environment-specific; validate your normal local recovery path and any scheduler independently.

RESTORE SAFETY

A restore is a reviewed plan, not a one-click rollback.

Before mutation, pgDumpster verifies the bundle, builds a deterministic plan and rejects source=target. A blocked plan fails before target credential or resource discovery; an executable plan still requires explicit --apply. There is no automatic cross-service rollback, no automatic project deletion and no claim that manual/platform limits were restored.

PLANNED EXECUTABLE AND VERIFIED ACTIONSMANUAL PLATFORM OR EXTERNAL LIMITS

YOUR INFRASTRUCTURE

The backup stays on your side.

pgDumpster runs where you run it and writes to local storage or an S3-compatible destination you configure. MKP Digital does not receive a copy of your backup data through this tool or website.

SOURCE AVAILABLE

Source available, with explicit licensing boundaries

pgDumpster is distributed under the PolyForm Shield License 1.0.0. It is not OSI open source. The public license governs permitted use; competing hosted, managed, white-label or commercial backup services require a separate written commercial license.

Commercial terms and pricing are provided on request; the public repository's LICENSE and NOTICE files are authoritative.

TEST RECOVERY, NOT JUST BACKUP

Start with the CLI. Trust it after a recovery drill.

Install the public CLI, run doctor, create an encrypted verified backup, verify it offline, inspect its coverage and restore it to a fresh test target before relying on it for disaster recovery.