15 days ago
railway sandbox ssh fails with "kex_exchange_identification: read: Connection reset by peer" from ssh.railway.com:18765.
TCP connects (nc -zv ssh.railway.com 18765 succeeds), but the relay sends no SSH banner and resets the connection immediately.
Same result:
- with direct ssh (sbx::@ssh.railway.com)
- with -4 (IPv4 only)
- after railway logout / railway login
- from inside a Railway sandbox towards the same relay (tested via /dev/tcp)
Sandboxes in europe-west4 and us-west2, created via CLI and SDK. SSH key is registered on the account (CLI shows "Using SSH key from agent"). railway sandbox exec and the web console work fine.
macOS, OpenSSH 10.3, CLI 5.58.0, Hobby plan.
Is the sandbox SSH relay operational? I need SSH (with agent forwarding) rather than exec.
4 Replies
Status changed to Awaiting Railway Response Railway • 15 days ago
15 days ago
Sandbox SSH connects to ssh.railway.com on the default SSH port (22), not port 18765. Port 18765 is not a port the SSH relay listens on, which explains the immediate connection reset before any SSH banner. If you have an SSH config entry for ssh.railway.com that sets a non-default port, that would override the CLI's connection as well. Check ~/.ssh/config for any Host block matching ssh.railway.com and remove or correct the Port directive, then retry railway sandbox ssh.
Note that sandboxes are currently in beta and behavior may change between releases.
Status changed to Awaiting User Response sam-a • 15 days ago
15 days ago
Thanks, that was it — a Host *.nl *.com block in my ssh config set Port 18765. Fixed, railway sandbox ssh works now.
Follow-up: does the sandbox SSH relay support SSH agent forwarding (ssh -A)? Inside the sandbox ssh-add -l says "Could not open a connection to your authentication agent", and remote unix-socket forwarding (-R /tmp/agent.sock:$SSH_AUTH_SOCK) doesn't arrive either. I want to use my local 1Password SSH agent from inside the sandbox without copying any private key into it. Is that supported or planned?
Status changed to Awaiting Railway Response Railway • 15 days ago
15 days ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 15 days ago
15 days ago
The port issue is resolved (my ssh config). The open question is agent forwarding: ssh -A sends "Requesting agent forwarding" but inside the sandbox SSH_AUTH_SOCK is empty. Does the sandbox relay support agent forwarding? That's what I need.
emre-aydemir
The port issue is resolved (my ssh config). The open question is agent forwarding: `ssh -A` sends "Requesting agent forwarding" but inside the sandbox SSH_AUTH_SOCK is empty. Does the sandbox relay support agent forwarding? That's what I need.
14 days ago
I had a look through the current sandbox SSH implementation and I don't think agent forwarding is supported by the sandbox relay right now.
sandbox ssh is using your local OpenSSH client through ssh.railway.com, but the Railway side still has to support the SSH agent forwarding channel for -A to work.
That seems to match what you're seeing: your client is requesting agent forwarding, but no SSH_AUTH_SOCK is being created inside the sandbox.
I also couldn't find any current sandbox docs or CLI code for -A / agent forwarding or remote Unix socket forwarding. The forwarding Railway documents for sandboxes is railway sandbox forward, which is local TCP forwarding into the sandbox rather than the reverse/Unix-socket forwarding needed for an SSH agent.
So I don't think there's another local SSH config option that will fix this one — the relay would need to support forwarding the agent channel.
For now, if this is mainly for Git access, the practical workaround would be something like a scoped GitHub token/credential passed into the sandbox, or authenticating inside the sandbox and checkpointing that state, instead of copying your SSH private key into it.
As for whether ssh -A support is planned, I couldn't find anything public confirming that, so I think Railway would have to answer that part.
