17 days ago
We run Postgres and Redis with public TCP proxies and log every connection (log_connections, pg_stat_activity.client_addr). Every connection arrives from the proxy hop (100.64.0.x), never the caller's address, which staff confirmed in April is how the L4 proxy works. So, is there ANY way to see the source addresses of connections a TCP proxy accepted: proxy-side access logs, an API field, per-connection metadata, or an IP allowlist on the proxy?
3 Replies
17 days ago
The TCP proxy is a raw L4 relay that terminates the caller's connection and opens a new one to the container, so the original source address is not carried through. There is no PROXY protocol header, no proxy-side access log, no per-connection metadata API, and no IP allowlist on TCP proxies. Edge Rules do support source-IP filtering, but only for HTTP traffic on public domains, not for TCP proxy connections.
Status changed to Awaiting User Response Railway • 17 days ago
17 days ago
As the bot said, layer 4 by itself has no concept of IP, that lives on layer 3
Although it does sound like a good use case for a Tailscale Forwarder, Brody (Railway Employee) has a template for that here if you need it: https://railway.com/deploy/tailscale-forwarder
Otherwise you could maybe terminate TLS on the Postgres database since I believe Railway's TCP proxy has TLS passthrough and then only holders of the signed certificate could connect. Although I'd recommend the tailscale forwarder over that for sure
Status changed to Awaiting Railway Response Railway • 17 days ago
Status changed to Awaiting User Response Railway • 17 days ago
17 days ago
Alright thank you, will test it
Status changed to Awaiting Railway Response Railway • 17 days ago
Status changed to Solved leadity • 17 days ago