a month ago
Project/Service: universal-receipt-checker (main API service)
Public domain: universal-receipt-checker-production.up.railway.app
Symptom: All external HTTPS requests to the public domain fail with:
SSL: SSLV3_ALERT_HANDSHAKE_FAILURE — sslv3 alert handshake failure
This happens at the TLS protocol level — not a certificate trust/expiry error. DNS resolves correctly and the TCP connection on port 443 succeeds, but the TLS handshake itself is rejected. Reproduced consistently from multiple independent networks (desktop, mobile data, and a third-party server), so it isn't specific to one client or network.
What I've already confirmed is healthy (so the problem isn't in my app or its config):
Container starts cleanly with no crash/restart loop — logs show a clean Uvicorn running on http://0.0.0.0:8080 every time.
PORT env var is 8080, matching exactly what the app binds to.
The app responds correctly to a request made from inside the container itself (curl/Python request to http://localhost:8080/healthz returns 200 OK).
Railway's own internal health-check probe reaches the container successfully (200 OK logged for every deploy).
What I've already tried, with no change in the error:
Redeployed the service.
Removed the public domain entirely and re-added it (same resulting hostname).
Given the container is fully healthy and reachable internally, but external TLS negotiation fails at the edge, this looks like an issue in Railway's edge/routing layer for this specific domain that isn't clearing through the normal redeploy/domain-reset self-service steps. Could someone take a look at the edge routing/SSL termination for this domain?
Thank you
Yonatan
2 Replies
a month ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 1 month ago
a month ago
Strange: I'm having no issues reaching it.
$ curl -vI https://universal-receipt-checker-production.up.railway.app
- Host universal-receipt-checker-production.up.railway.app:443 was resolved.
- IPv6: (none)
- IPv4: 69.46.46.54
- Trying 69.46.46.54:443...
- ALPN: curl offers h2,http/1.1
- TLSv1.3 (OUT), TLS handshake, Client hello (1):
- SSL Trust Anchors:
- CAfile: /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
- TLSv1.3 (IN), TLS handshake, Server hello (2):
- TLSv1.3 (IN), TLS change cipher, Change cipher spec (1):
- TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
- TLSv1.3 (IN), TLS handshake, Certificate (11):
- TLSv1.3 (IN), TLS handshake, CERT verify (15):
- TLSv1.3 (IN), TLS handshake, Finished (20):
- TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
- TLSv1.3 (OUT), TLS handshake, Finished (20):
- SSL connection using TLSv1.3 / TLS_AES_256_GCM_SHA384 / x25519 / id-ecPublicKey
- ALPN: server accepted h2
- Server certificate:
- subject: CN=*.up.railway.app
- start date: Jul 29 02:40:55 2026 GMT
- expire date: Oct 27 02:40:54 2026 GMT
- issuer: C=US; O=Let's Encrypt; CN=YE1
- Certificate level 0: Public key type EC/prime256v1 (256/128 Bits/secBits), signed using ecdsa-with-SHA384
- Certificate level 1: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
- Certificate level 2: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
- Certificate level 3: Public key type EC/secp384r1 (384/192 Bits/secBits), signed using ecdsa-with-SHA384
- subjectAltName: "universal-receipt-checker-production.up.railway.app" matches cert's "*.up.railway.app"
- SSL certificate verified via OpenSSL.
- Established connection to universal-receipt-checker-production.up.railway.app (69.46.46.54 port 443) from 10.0.0.179 port 39080
- using HTTP/2
- [HTTP/2] [1] OPENED stream for https://universal-receipt-checker-production.up.railway.app/
- [HTTP/2] [1] [:method: HEAD]
- [HTTP/2] [1] [:scheme: https]
- [HTTP/2] [1] [:authority: universal-receipt-checker-production.up.railway.app]
- [HTTP/2] [1] [:path: /]
- [HTTP/2] [1] [user-agent: curl/8.18.0]
- [HTTP/2] [1] [accept: /]
HEAD / HTTP/2
Host: universal-receipt-checker-production.up.railway.app
User-Agent: curl/8.18.0
Accept: /
- Request completely sent off
- TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
- TLSv1.3 (IN), TLS handshake, Newsession Ticket (4):
< HTTP/2 200
HTTP/2 200
< accept-ranges: bytes
accept-ranges: bytes
< content-type: text/html; charset=utf-8
content-type: text/html; charset=utf-8
< date: Mon, 31 Aug 2026 06:12:49 GMT
date: Mon, 31 Aug 2026 06:12:49 GMT
< etag: "701ab29145e82d79ddfe30b016ca5369"
etag: "701ab29145e82d79ddfe30b016ca5369"
< last-modified: Mon, 31 Aug 2026 05:25:43 GMT
last-modified: Mon, 31 Aug 2026 05:25:43 GMT
< server: railway-hikari
server: railway-hikari
< x-railway-request-id: qlV7wP63R42x1mgVEuroCg
x-railway-request-id: qlV7wP63R42x1mgVEuroCg
< x-request-id: 113c54ad-340c-4e53-8d2c-e8ed53df4c83
x-request-id: 113c54ad-340c-4e53-8d2c-e8ed53df4c83
< content-length: 70581
content-length: 70581
< x-hikari-trace: sin1.hs0s
x-hikari-trace: sin1.hs0s
< x-railway-edge: sin1
x-railway-edge: sin1
<
- Connection #0 to host universal-receipt-checker-production.up.railway.app:443 left intact
Attachments
Status changed to Open medim • about 1 month ago
Status changed to Solved medim • about 1 month ago
