locked
db-api unreachable
one schema, one service role, one scoped jwt
which role can touch which bucket
runs as supabase_admin. be careful.
supabase_admin
creates schema + role + kong consumer + signed jwt
for role