External HTTPS requests fail with TLS handshake error, despite healthy container
wyoni72
FREEOP

a month ago

Project/Service: universal-receipt-checker (main API service)

Public domain: universal-receipt-checker-production.up.railway.app

Symptom: All external HTTPS requests to the public domain fail with:

SSL: SSLV3_ALERT_HANDSHAKE_FAILURE — sslv3 alert handshake failure

This happens at the TLS protocol level — not a certificate trust/expiry error. DNS resolves correctly and the TCP connection on port 443 succeeds, but the TLS handshake itself is rejected. Reproduced consistently from multiple independent networks (desktop, mobile data, and a third-party server), so it isn't specific to one client or network.

What I've already confirmed is healthy (so the problem isn't in my app or its config):

Container starts cleanly with no crash/restart loop — logs show a clean Uvicorn running on http://0.0.0.0:8080 every time.

PORT env var is 8080, matching exactly what the app binds to.

The app responds correctly to a request made from inside the container itself (curl/Python request to http://localhost:8080/healthz returns 200 OK).

Railway's own internal health-check probe reaches the container successfully (200 OK logged for every deploy).

What I've already tried, with no change in the error:

Redeployed the service.

Removed the public domain entirely and re-added it (same resulting hostname).

Given the container is fully healthy and reachable internally, but external TLS negotiation fails at the edge, this looks like an issue in Railway's edge/routing layer for this specific domain that isn't clearing through the normal redeploy/domain-reset self-service steps. Could someone take a look at the edge routing/SSL termination for this domain?

Thank you

Yonatan

Solved$10 Bounty

2 Replies

Railway
BOT

a month ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • about 1 month ago


lineup-events
HOBBY

a month ago

Strange: I'm having no issues reaching it.

image.png

$ curl -vI https://universal-receipt-checker-production.up.railway.app

  • Host universal-receipt-checker-production.up.railway.app:443 was resolved.
  • IPv6: (none)
  • IPv4: 69.46.46.54
  • Trying 69.46.46.54:443...
  • ALPN: curl offers h2,http/1.1
  • TLSv1.3 (OUT), TLS handshake, Client hello (1):
  • SSL Trust Anchors:
  • CAfile: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
  • TLSv1.3 (IN), TLS handshake, Server hello (2):
  • TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
  • TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
  • TLSv1.3 (IN), TLS handshake, Certificate (11):
  • TLSv1.3 (IN), TLS handshake, CERT verify (15):
  • TLSv1.3 (IN), TLS handshake, Finished (20):
  • TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
  • TLSv1.3 (OUT), TLS handshake, Finished (20):
  • SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / x25519 / id-ecPublicKey
  • ALPN: server accepted h2
  • Server certificate:
  • subject: CN=*.up.railway.app
  • start date: Jul 29 02:40:55 2026 GMT
  • expire date: Oct 27 02:40:54 2026 GMT
  • issuer: C=US; O=Let's Encrypt; CN=YE1
  • Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA384
  • Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
  • Certificate level 2: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
  • Certificate level 3: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
  • subjectAltName: "universal-receipt-checker-production.up.railway.app" matches cert's "*.up.railway.app"
  • SSL certificate verified via OpenSSL.
  • Established connection to universal-receipt-checker-production.up.railway.app (69.46.46.54 port 443) from 10.0.0.179 port 39080
  • using HTTP/2
  • [HTTP/2] [1] OPENED stream for https://universal-receipt-checker-production.up.railway.app/
  • [HTTP/2] [1] [:method: HEAD]
  • [HTTP/2] [1] [:scheme: https]
  • [HTTP/2] [1] [:authority: universal-receipt-checker-production.up.railway.app]
  • [HTTP/2] [1] [:path: /]
  • [HTTP/2] [1] [user-agent: curl/8.18.0]
  • [HTTP/2] [1] [accept: /]

HEAD / HTTP/2

Host: universal-receipt-checker-production.up.railway.app

User-Agent: curl/8.18.0

Accept: /

  • Request completely sent off
  • TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
  • TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):

< HTTP/2 200

HTTP/2 200

< accept-ranges: bytes

accept-ranges: bytes

< content-type: text/html; charset=utf-8

content-type: text/html; charset=utf-8

< date: Mon, 31 Aug 2026 06:12:49 GMT

date: Mon, 31 Aug 2026 06:12:49 GMT

< etag: "701ab29145e82d79ddfe30b016ca5369"

etag: "701ab29145e82d79ddfe30b016ca5369"

< last-modified: Mon, 31 Aug 2026 05:25:43 GMT

last-modified: Mon, 31 Aug 2026 05:25:43 GMT

< server: railway-hikari

server: railway-hikari

< x-railway-request-id: qlV7wP63R42x1mgVEuroCg

x-railway-request-id: qlV7wP63R42x1mgVEuroCg

< x-request-id: 113c54ad-340c-4e53-8d2c-e8ed53df4c83

x-request-id: 113c54ad-340c-4e53-8d2c-e8ed53df4c83

< content-length: 70581

content-length: 70581

< x-hikari-trace: sin1.hs0s

x-hikari-trace: sin1.hs0s

< x-railway-edge: sin1

x-railway-edge: sin1

<

  • Connection #0 to host universal-receipt-checker-production.up.railway.app:443 left intact

Attachments


wyoni72
FREEOP

a month ago

Thank you for your verification , i found that it's internal issue.


Status changed to Open medim • about 1 month ago


Status changed to Solved medim • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...