5 hours ago
Hi! I'm using Railway's PostgreSQL 18 service and need to create a logical database backup and inspect Prisma migration history before deploying an update.
My database is private-only, and Railway's SSH host-key fingerprints aren't independently published or verifiable.
Is there a supported way to run read-only PostgreSQL queries and create a pg_dump backup from within Railway's private environment, without exposing the database publicly or upgrading to a paid backup feature?
I'm looking for a safe approach that works with the existing Railway project. Thank you!
1 Replies
5 hours ago
When the database has no public TCP Proxy, railway connect postgres opens a local SSH tunnel into the service, so nothing gets exposed publicly. Adding --tunnel-only prints the connection details for an external client and keeps the tunnel open. Our SSH endpoint is served by multiple hosts, each with its own key, and those keys change at any time without notice. We don't publish fingerprints or a known_hosts list, and how you handle host-key trust for that endpoint is your call.
Other services in the same project can also reach the database over the private network at postgres.railway.internal:5432. That traffic never leaves your project.
Native volume backups are a Pro plan feature.
Status changed to Awaiting User Response Railway • about 5 hours ago