3 hours ago
Hello Railway Support,
I'm configuring a secure backup process for an existing PostgreSQL 17 deployment using Railway's postgres-ssl template.
Before enabling the backup worker, I need to establish independently authenticated trust for the PostgreSQL server certificate, so that clients can connect using sslmode=verify-full.
Could you please advise on the following?
Is there an authenticated Railway control-plane or dashboard method to obtain or verify the deployment-specific PostgreSQL CA certificate and its SHA-256 fingerprint, bound to the correct project, environment and service?
If the supported retrieval mechanism uses Railway SSH/SFTP, is there an independently authenticated source for the ssh.railway.com gateway's SSH host-key fingerprint and its rotation policy, so that strict host-key verification can be established without trust-on-first-use?
Does the postgres-ssl template guarantee that the existing server certificate includes the assigned RAILWAY_PRIVATE_DOMAIN in its Subject Alternative Names, or must this be checked for each deployment?
What is the recommended process for distributing updated CA certificates to clients when the template renews or regenerates its CA and server certificates?
We are not requesting access to private keys, database credentials or any changes to the running deployment. We only need a secure procedure for authenticating the existing public certificate material and maintaining trust through rotation.
Thank you.
1 Replies
Status changed to Awaiting Railway Response Railway • about 3 hours ago
2 hours ago
We don't offer a dashboard or API method that returns the PostgreSQL CA certificate or its fingerprint for a specific project, environment and service. The template creates its own certificates and renews them before they expire, and it doesn't guarantee that the private domain is included in the Subject Alternative Names, so please check the SANs on each deployment before you rely on verify-full.
For ssh.railway.com, we don't publish host-key fingerprints, an SSHFP record or a known_hosts list. Host keys can change at any time without notice, so we can't provide an independent source for pinning them.
We also have no Railway-side process for distributing updated CA certificates to your clients, so keeping trust in place through rotation has to be handled in your own setup.
Status changed to Awaiting User Response mykal • about 2 hours ago