a month ago
I have a Laravel API backend deployed on Railway (Dockerfile builder), paired with a Vue frontend on Netlify. For the past several hours, every single request to the backend, from the browser, from curl, from multiple different networks, gets:
HTTP/1.1 429 Too Many Requests
server: railway-hikari
x-railway-edge:
rate limited
This is coming straight from Railway's edge proxy, not my application.
What I've ruled out:
Not client/IP-specific. Reproduced identically from three separate networks: two different home connections and one mobile carrier on cellular data.
Not a billing/credit issue. I still have ~$4.99 of trial credit remaining.
Not an app problem. Deploy logs show a clean boot (migrations run, seeders complete, "Starting web server..."), and the service shows as Active in the dashboard. Hitting the same container directly in a local Docker environment (outside Railway) works perfectly with no rate limiting.
Both domains affected identically. The Railway-generated domain (*.up.railway.app) and my verified custom domain (api..com) both return the same 429.
Setup context: during initial deployment I did a lot of iteration, several redeploys, adding/removing/re-adding a custom domain while sorting out DNS, over the past few hours. I suspect this volume may have tripped some abuse-detection threshold on the service or account, but it's now blocking completely normal, legitimate traffic and hasn't let up.
A few x-hikari-trace IDs from blocked requests, in case they help locate this in your logs:
cdg1.e9jw
ams1.9qww
lhr1.mryf
ams1.aydy
Could someone take a look at whether this service/account got flagged, and clear it if so? Happy to provide the project ID or any other details needed. Thanks!
1 Replies
a month ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 26 days ago
a month ago
I figured it out, it is because I had Under Attack Mode enabled. After disabling it, the issue was fixed
Status changed to Solved kelo1 • 26 days ago