PROXY protocol or source-IP visibility for TCP proxies?
leadity
PROOP

17 days ago

We run Postgres and Redis with public TCP proxies and log every connection (log_connections, pg_stat_activity.client_addr). Every connection arrives from the proxy hop (100.64.0.x), never the caller's address, which staff confirmed in April is how the L4 proxy works. So, is there ANY way to see the source addresses of connections a TCP proxy accepted: proxy-side access logs, an API field, per-connection metadata, or an IP allowlist on the proxy?

Solved

3 Replies

Railway
BOT

17 days ago

The TCP proxy is a raw L4 relay that terminates the caller's connection and opens a new one to the container, so the original source address is not carried through. There is no PROXY protocol header, no proxy-side access log, no per-connection metadata API, and no IP allowlist on TCP proxies. Edge Rules do support source-IP filtering, but only for HTTP traffic on public domains, not for TCP proxy connections.


Status changed to Awaiting User Response Railway • 17 days ago


17 days ago

As the bot said, layer 4 by itself has no concept of IP, that lives on layer 3

Although it does sound like a good use case for a Tailscale Forwarder, Brody (Railway Employee) has a template for that here if you need it: https://railway.com/deploy/tailscale-forwarder

Otherwise you could maybe terminate TLS on the Postgres database since I believe Railway's TCP proxy has TLS passthrough and then only holders of the signed certificate could connect. Although I'd recommend the tailscale forwarder over that for sure


Status changed to Awaiting Railway Response Railway • 17 days ago


Status changed to Awaiting User Response Railway • 17 days ago


leadity
PROOP

17 days ago

Alright thank you, will test it


Status changed to Awaiting Railway Response Railway • 17 days ago


Status changed to Solved leadity • 17 days ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...