Operate a managed platform
Review a stack, follow its operations, change its configuration and restore a separate copy.
Neon and Supabase contain several services. Hakopod groups each stack under one platform record with a project, environment, revision and operation history. Vitess is in the managed database catalog and uses the database workflow.
The current published release keeps Neon and Supabase unavailable. This guide explains the implemented workflow and the operator setup required before a qualified release can enable it. Check the Neon and Supabase guides for the current acceptance boundary.
Check what your installation can run#
Open Managed platforms, select the project and environment, then choose Create platform. The guided pages collect the stack, resources, placement and settings before a final review. The catalog supplies allowed nodes and immutable secret references for that scope. Secret values do not appear in the form. Creating, changing, backing up or restoring a platform requires deployment permission for that project.
The CLI reads the same API:
hakopod platform catalog --project demo --environment development
hakopod platform list --project demo --environment development
hakopod platform review --file supabase.toml --project demo --environment development
Review every component's compute request, persistent storage and placement. These values reserve capacity; they are not measurements of current use. A blocked review explains which requirement is missing. Adding more replicas does not create more physical hosts or approve another storage class.
Follow the operation#
An accepted request creates a durable operation. It does not mean the stack is ready. The detail page separates the overview, component information and operation history so you can inspect a failure without losing the platform's scope.
hakopod platform apply --file supabase.toml --project demo --environment development
hakopod platform operations PLATFORM_ID
hakopod platform operation OPERATION_ID
Replace the uppercase IDs with values returned by your API. Before changing an external resource, Hakopod records its creation intent and verifies its observed identity. A worker retry must find that same operation and resource. A matching Kubernetes name alone does not prove ownership.
Change settings and credentials#
Choose Configure from the platform detail. The review uses the loaded platform's project, environment and current revision. If someone updates the platform while your form is open, review the new revision before applying your change. Entered values stay in the form after a request fails.
Neon configuration has two steps: Resources and Review. You can change component CPU and memory. Storage size, placement, member counts, version and secret references stay fixed. An allocation change can restart services and interrupt connections. To change storage or topology, restore into a separate compatible platform and inspect it before moving the application.
For Supabase, database password rotation moves the role bootstrap and all database clients together. Old secret snapshots are removed only after the new revision is observed. JWT expiry is a separate setting. Signing keys and keys that encrypt stored data have different retirement requirements; unsupported rotations are rejected.
The security guide explains why applications receive scoped credentials and public trust material, without Kubernetes credentials or the server's private CA key.
Inspect the certificates your clients use#
New platform specifications use managed TLS. Hakopod creates a separate certificate authority for each platform after claiming its namespace. You still supply versioned references for passwords, application keys and object storage credentials. Existing platforms with operator-supplied certificates keep that ownership mode.
Open Security to see the last verified issuer, endpoint certificates and expiry dates. The verification time matters: an earlier successful check does not describe a newer revision. A pending or failed renewal stays visible alongside the last certificate observation.
Choose Download public CA, or read the same public certificate through the CLI:
hakopod platform trust PLATFORM_ID
The command returns JSON with a certificate_pem field. Configure the client to trust that CA and verify the hostname it connects to. These private certificates are not automatically trusted by a browser or operating system. A certificate containing a public hostname does not create a public endpoint.
Leaf certificates last 30 days and enter renewal with fewer than seven days remaining. Maintenance has its own durable lease, waits for lifecycle and recovery work, and checks the certificates actually served after rollout. It can continue after the original creator's deployment key is revoked because the platform's maintenance authority is separate from that key. Missing ownership, changed runtime approval or insufficient approved capacity still stops the work.
A restored Supabase target keeps its application services isolated for inspection. Maintenance preserves that isolation until you review and apply a new platform revision. Each target has its own issuer; a restore does not copy the source's TLS private keys.
Restore the stack, then inspect it#
The Supabase recovery candidate captures database rows, roles, encryption files, uploaded objects, function files and Studio snippets. The Neon recovery candidate preserves the tenant, timeline and storage identities needed to read its data. Both remain unavailable until their native qualification passes. Choose a backup destination and retention policy that cover the whole platform.
Restore uses a separate empty compatible target. Review the source, artifact, target and revisions, then confirm the target's exact name. The target stays isolated while recovery runs. Check the restored data and an application path before planning a connection change. New writes to the source are not copied into an older backup.
hakopod platform recovery-review --file recovery.toml
hakopod platform recovery-apply --file recovery.toml --idempotency-key platform-backup-001
hakopod platform recovery-operation OPERATION_ID
hakopod platform recovery-cancel OPERATION_ID
For a backup, the recovery TOML needs the source platform and revision plus the encrypted destination and its revision. For a restore, it needs the source and revision, completed artifact, separate target and revision, and the target's exact current name in confirm_target_name. Use the source operation guide for complete examples. Choose a new idempotency key for a new operation and preserve it while retrying the same request.
Cancellation requests cleanup. It cannot undo every completed write. The worker keeps its cleanup lease while restoring paused source services or removing temporary resources it owns. Inspect the final operation result before treating cancellation as finished.
Why operator setup matters#
A release qualifies specific runtime images. The installation operator still needs to approve storage, resource identities and network access for the actual cluster. The runtime binds that approval to the cluster UID and the StorageClass UID, provisioner and parameters. Naming a class “encrypted” does not establish encryption at rest; that requires evidence from the storage provider.
Cloud also checks the current workspace capacity grant. A runtime configuration file cannot override it. Planning and execution verify node identity, operating system and architecture. Backup and restore recheck the runtime approval before new mutations. If the approval changes, new work stops while cleanup can finish under its existing lease.
Read the architecture guide to follow the API and worker path, and the recovery guide to plan inspection and application cutover.