IP
mikel-stolen
FREEOP

2 months ago

Hi Railway team,

I’m deploying an application on Railway and need to configure an IP allowlist on an external service that our application connects to.

We need to reliably determine which public outbound/egress IP address(es) or IP ranges our Railway service may use, so that we can whitelist only the required addresses in the external service’s firewall.

Could you please help us with the following?

  1. Which outbound/egress IP range(s) apply to our service/project?
  2. Are these outbound IPs static, or can they change over time?
  3. Is there a Railway configuration or service that provides a static/dedicated outbound IP?
  4. Do the applicable IP ranges depend on the deployment region?
  5. Is there an official Railway page or API where we can retrieve and monitor these ranges so we can keep our allowlist up to date?

We’d prefer to get the correct ranges directly from Railway rather than configuring IPs manually or guessing, as an incorrect allowlist could cause connectivity issues.

Thanks for your help!

Solved

3 Replies

Status changed to Awaiting Railway Response Railway • about 2 months ago


2 months ago

Static Outbound IP is only available on Pro Plan and above

https://docs.railway.com/networking/static-outbound-ips


Status changed to Solved Railway • about 2 months ago


dizzydes90
EMPLOYEE

2 months ago

Short version: the supported way to do this is our Static Outbound IPs feature, which is on the Pro plan. It's built for exactly your use case (allowlisting your service at an external firewall).

Specifics for your questions:

1 and 2. By default your service's outbound traffic comes from a shared pool of IPs that can change, and we don't publish those ranges to allowlist against, so that path isn't reliable for a firewall rule.

  1. With Static Outbound IPs enabled (per service, in the service's Settings under Networking), you get a small set of stable IPs (currently three, load-balanced) that you can whitelist. They appear in that Networking section once enabled.

  2. They're region-specific. If you move the service to a different region, the IPs change.

  3. Once enabled, the assigned IPs are shown in your service's Networking settings, and the reference is https://docs.railway.com/reference/static-outbound-ips. There's no separate list of shared ranges to monitor, since the static outbound IP is the intended way to get stable addresses.

One note: you're on the free trial right now, so you'd need to upgrade to Pro to turn this on.

The Railway Team


Status changed to Awaiting User Response Railway • about 2 months ago


dizzydes90

Short version: the supported way to do this is our Static Outbound IPs feature, which is on the Pro plan. It's built for exactly your use case (allowlisting your service at an external firewall). Specifics for your questions: 1 and 2. By default your service's outbound traffic comes from a shared pool of IPs that can change, and we don't publish those ranges to allowlist against, so that path isn't reliable for a firewall rule. 3. With Static Outbound IPs enabled (per service, in the service's Settings under Networking), you get a small set of stable IPs (currently three, load-balanced) that you can whitelist. They appear in that Networking section once enabled. 4. They're region-specific. If you move the service to a different region, the IPs change. 5. Once enabled, the assigned IPs are shown in your service's Networking settings, and the reference is https://docs.railway.com/reference/static-outbound-ips. There's no separate list of shared ranges to monitor, since the static outbound IP is the intended way to get stable addresses. One note: you're on the free trial right now, so you'd need to upgrade to Pro to turn this on. The Railway Team

mikel-stolen
FREEOP

2 months ago

Thank you very much for the detailed explanation and for clarifying how Static Outbound IPs work. This answers our questions and gives us exactly what we needed to know.

We really appreciate your help and the quick response. We'll take the Pro plan requirement into account and proceed from here.

Thanks again to the Railway team!


Status changed to Awaiting Railway Response Railway • about 2 months ago


Status changed to Solved Railway • about 2 months ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...