2 months ago
Hi Railway team,
I’m deploying an application on Railway and need to configure an IP allowlist on an external service that our application connects to.
We need to reliably determine which public outbound/egress IP address(es) or IP ranges our Railway service may use, so that we can whitelist only the required addresses in the external service’s firewall.
Could you please help us with the following?
- Which outbound/egress IP range(s) apply to our service/project?
- Are these outbound IPs static, or can they change over time?
- Is there a Railway configuration or service that provides a static/dedicated outbound IP?
- Do the applicable IP ranges depend on the deployment region?
- Is there an official Railway page or API where we can retrieve and monitor these ranges so we can keep our allowlist up to date?
We’d prefer to get the correct ranges directly from Railway rather than configuring IPs manually or guessing, as an incorrect allowlist could cause connectivity issues.
Thanks for your help!
3 Replies
Status changed to Awaiting Railway Response Railway • about 2 months ago
2 months ago
Static Outbound IP is only available on Pro Plan and above
Status changed to Solved Railway • about 2 months ago
2 months ago
Short version: the supported way to do this is our Static Outbound IPs feature, which is on the Pro plan. It's built for exactly your use case (allowlisting your service at an external firewall).
Specifics for your questions:
1 and 2. By default your service's outbound traffic comes from a shared pool of IPs that can change, and we don't publish those ranges to allowlist against, so that path isn't reliable for a firewall rule.
-
With Static Outbound IPs enabled (per service, in the service's Settings under Networking), you get a small set of stable IPs (currently three, load-balanced) that you can whitelist. They appear in that Networking section once enabled.
-
They're region-specific. If you move the service to a different region, the IPs change.
-
Once enabled, the assigned IPs are shown in your service's Networking settings, and the reference is https://docs.railway.com/reference/static-outbound-ips. There's no separate list of shared ranges to monitor, since the static outbound IP is the intended way to get stable addresses.
One note: you're on the free trial right now, so you'd need to upgrade to Pro to turn this on.
The Railway Team
Status changed to Awaiting User Response Railway • about 2 months ago
dizzydes90
Short version: the supported way to do this is our Static Outbound IPs feature, which is on the Pro plan. It's built for exactly your use case (allowlisting your service at an external firewall). Specifics for your questions: 1 and 2. By default your service's outbound traffic comes from a shared pool of IPs that can change, and we don't publish those ranges to allowlist against, so that path isn't reliable for a firewall rule. 3. With Static Outbound IPs enabled (per service, in the service's Settings under Networking), you get a small set of stable IPs (currently three, load-balanced) that you can whitelist. They appear in that Networking section once enabled. 4. They're region-specific. If you move the service to a different region, the IPs change. 5. Once enabled, the assigned IPs are shown in your service's Networking settings, and the reference is https://docs.railway.com/reference/static-outbound-ips. There's no separate list of shared ranges to monitor, since the static outbound IP is the intended way to get stable addresses. One note: you're on the free trial right now, so you'd need to upgrade to Pro to turn this on. The Railway Team
2 months ago
Thank you very much for the detailed explanation and for clarifying how Static Outbound IPs work. This answers our questions and gives us exactly what we needed to know.
We really appreciate your help and the quick response. We'll take the Pro plan requirement into account and proceed from here.
Thanks again to the Railway team!
Status changed to Awaiting Railway Response Railway • about 2 months ago
Status changed to Solved Railway • about 2 months ago