Health check + all public routes fail with 502. service unavailable despite container starting cleanly
dors001
HOBBYOP

3 hours ago

My web service (Next.js 16, Docker deploy) consistently fails its own health check and returns 502 for every public route, despite the container starting up completely cleanly every time.

What I've confirmed:

  • Deploy logs show a clean startup every time: "Starting Container" → Next.js 16.3.0 boots → binds to the correct port (matches what's configured) → "Ready in 0ms". No errors, no crash.

  • The configured health check (path: /sign-in) fails every single attempt with "service unavailable" for the full 5-minute retry window, then the deployment fails.

  • Confirmed identically on both my custom domain (www.sheet-app.com, DNS verified, CNAME correctly pointing at the Railway-provided target) and the raw *.up.railway.app domain Railway assigns by default - same 502 on both.

  • The exact same Docker image runs and responds correctly when built and run locally (outside Railway) - confirmed with a real HTTP client, clean 307 redirects for the auth-gated routes, no errors.

  • I already deleted and fully recreated this service once, from scratch, it did not resolve it.

thank you for all the help

Awaiting User Response

1 Replies

Railway
BOT

3 hours ago

Your service's healthcheck is set to /sign-in. Since a security fix on 2026-08-28, the deploy healthcheck no longer follows redirects, so only a direct 2xx response passes. A 301/302/307/308 counts as a failure, and the build log still shows it as "service unavailable". With Clerk auth in front of your routes, that path may be answering with a redirect. You can check by requesting it without following redirects, for example curl -so /dev/null -w '%{http_code}' <your-url>/sign-in (no -L). If it returns a 3xx, point the healthcheck path in the service's settings at a route that returns 200 directly with no auth, such as a dedicated /api/health, or remove the healthcheck.

The 502 on both domains follows from the failed deploys. The healthcheck talks to the container directly and never goes through your domains or DNS, so once a deploy passes, the domains have a running container to serve.


Status changed to Awaiting User Response Railway • about 3 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...