Outbound egress from Railway receives Cloudflare challenge while same application works from residential network
vndpmr-bot
HOBBYOP

2 hours ago

Title:

Outbound egress from Railway receives Cloudflare challenge while same application works from residential network

Hello Railway Support,

We are investigating a sudden outbound networking issue affecting our production service.

Our Python/Playwright application had been accessing a public website successfully for approximately 92 days. Around September 28-29, 2026, outbound requests from Railway began receiving a Cloudflare Challenge Page with HTTP 403.

The application logic and Playwright version did not change in the network request path. The same repository and Playwright 1.59.0 still receive HTTP 200 when run from a normal residential ISP connection.

Railway service details:

Project name: giving-embrace

Project ID: c8f7acc1-6a66-4da7-955f-fa431f48823a

Environment: production

Service name: web

Service ID: 8ba94e3b-34c3-42d3-8af7-fc4d95cc94ba

Current region: us-west2

Deployment ID:

8299d96b-3092-4627-be74-32a004188743

Current outbound IPv4:

13.52.31.100

IPv4 response from target:

HTTP/2 403

server: cloudflare

cf-mitigated: challenge

CF-Ray: a42d674e5b36f378-SJC

We also enabled Railway Outbound IPv6 for diagnostic purposes.

Current outbound IPv6:

2600:1f1c:1d1:8201:1182:1161:2b26:1b5c

IPv6 response from target:

HTTP/2 403

server: cloudflare

cf-mitigated: challenge

CF-Ray: a42d773e38a3ebe4-SJC

We previously tested another Railway region as well and observed the same Cloudflare challenge behavior.

The target website works normally from a residential connection using the same application code.

We are not requesting assistance bypassing the destination's security controls. We are trying to determine whether the Railway shared egress network, IP range, ASN, or routing changed around September 28-29.

Could you please help us clarify:

  1. Did our shared outbound egress IP pool or routing change around September 28-29, 2026, or as a result of a deployment?

  2. Were there any platform/network changes affecting outbound traffic in us-west2 during that period?

  3. Is our current shared egress traffic routed through the same ASN/network ranges for both IPv4 and IPv6?

  4. Is there any supported way to move this service to another shared egress pool without changing the application architecture?

  5. Would Railway Static Outbound IPs use a materially different egress pool or ASN from our current shared outbound routing?

  6. Can you confirm whether our current outbound IPs are shared with other Railway workloads?

  7. Are there any known reputation or Cloudflare-related issues affecting Railway outbound IP ranges?

This is production-impacting because our data synchronization pipeline is currently disabled to avoid repeatedly hitting the destination with unsuccessful requests.

Thank you.

$10 Bounty

0 Replies

Railway
BOT

2 hours ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • about 2 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...