2 hours ago
Title:
Outbound egress from Railway receives Cloudflare challenge while same application works from residential network
Hello Railway Support,
We are investigating a sudden outbound networking issue affecting our production service.
Our Python/Playwright application had been accessing a public website successfully for approximately 92 days. Around September 28-29, 2026, outbound requests from Railway began receiving a Cloudflare Challenge Page with HTTP 403.
The application logic and Playwright version did not change in the network request path. The same repository and Playwright 1.59.0 still receive HTTP 200 when run from a normal residential ISP connection.
Railway service details:
Project name: giving-embrace
Project ID: c8f7acc1-6a66-4da7-955f-fa431f48823a
Environment: production
Service name: web
Service ID: 8ba94e3b-34c3-42d3-8af7-fc4d95cc94ba
Current region: us-west2
Deployment ID:
8299d96b-3092-4627-be74-32a004188743
Current outbound IPv4:
13.52.31.100
IPv4 response from target:
HTTP/2 403
server: cloudflare
cf-mitigated: challenge
CF-Ray: a42d674e5b36f378-SJC
We also enabled Railway Outbound IPv6 for diagnostic purposes.
Current outbound IPv6:
2600:1f1c:1d1:8201:1182:1161:2b26:1b5c
IPv6 response from target:
HTTP/2 403
server: cloudflare
cf-mitigated: challenge
CF-Ray: a42d773e38a3ebe4-SJC
We previously tested another Railway region as well and observed the same Cloudflare challenge behavior.
The target website works normally from a residential connection using the same application code.
We are not requesting assistance bypassing the destination's security controls. We are trying to determine whether the Railway shared egress network, IP range, ASN, or routing changed around September 28-29.
Could you please help us clarify:
-
Did our shared outbound egress IP pool or routing change around September 28-29, 2026, or as a result of a deployment?
-
Were there any platform/network changes affecting outbound traffic in us-west2 during that period?
-
Is our current shared egress traffic routed through the same ASN/network ranges for both IPv4 and IPv6?
-
Is there any supported way to move this service to another shared egress pool without changing the application architecture?
-
Would Railway Static Outbound IPs use a materially different egress pool or ASN from our current shared outbound routing?
-
Can you confirm whether our current outbound IPs are shared with other Railway workloads?
-
Are there any known reputation or Cloudflare-related issues affecting Railway outbound IP ranges?
This is production-impacting because our data synchronization pipeline is currently disabled to avoid repeatedly hitting the destination with unsuccessful requests.
Thank you.