New service cannot reach 10 of 11 existing services over private network
mkqiles
FREEOP

2 months ago

We are seeing a selective private-network routing failure inside one Railway production environment.

Scope

  • Project: baa4c45c-cf18-412c-a234-a7526a985713
  • Environment: 4fe4e2a4-f630-4f7f-a866-e8e5ebc848b9
  • Region: Southeast Asia (Singapore)
  • Private network: 03c23978-a574-4545-8224-fac8fdab571f
  • Affected service: Cassandra-v3-4 (223a8826-4301-4eb0-9f62-93c1e43121f8)
  • Runtime: V2

Reproduction

  1. Deploy a probe container in the same project, environment, region, and private network.
  2. Attempt TCP connections to the existing 11 Cassandra services on port 7000.
  3. The probe cannot complete the TCP handshake to 10 of 11 destinations.

Evidence

  • Probe A source 10.207.93.210: each failed flow contains only one outbound SYN (74 bytes), no response.
  • Independent Probe B source 10.168.230.195 reproduced the issue: 10 destinations show one SYN/74 bytes; only one destination shows a multi-packet exchange.
  • Probe timestamps were approximately 2026-08-19T15:05Z and 2026-08-19T15:14Z to 15:22Z.
  • Railway network flow records show flowState=partial, dropCause=null, peerKind=service, peerServiceId=null.
  • Existing Cassandra nodes are healthy and communicate with each other. Their current container IPv4 addresses match their advertised internode addresses.
  • DNS, cluster name, datacenter, rack, seeds, and port configuration were checked.
  • Recreating/redeploying an independent probe reproduced the same selective routing behavior.
  • Private-network status reports the same network ID, state=ready, addressFamily=IPv4 & IPv6.
  • We intentionally stopped before modifying database state or repeatedly restarting production nodes.

This appears below Cassandra: the TCP handshake itself does not complete. Could Railway please inspect/reconcile the private-network endpoints or WireGuard peer routes for this environment? Is there a self-service way to rebuild the private-network mesh without recreating the environment?

Related current community thread: same-environment Singapore private TCP path showing about 240ms on both IPv4 and IPv6:

https://station.railway.com/questions/220ms-tcp-connect-to-postgres-railway-in-3aa6a95f

Solved

1 Replies

Railway
BOT

2 months ago

The project and services you referenced cannot be reached from the account this thread is tied to, so we are unable to examine the private-network state or act on the resources from here. To allow us to investigate, please continue this request from the account or workspace that owns that project.


Status changed to Awaiting User Response Railway • about 2 months ago


Railway
BOT

a month ago

This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!

Status changed to Solved Railway • about 1 month ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...