2 months ago
Railway Support confirmed that public TLS terminates at Railway’s edge and that the subsequent hop to a customer container uses plaintext HTTP/1.1 over Railway’s internal network.
For an OWASP ASVS 5.0 V12.3.1 assessment, what exact Railway-supported configuration prevents plaintext traffic between the public ingress boundary and the first customer-controlled process?
Support suggested a gateway service that terminates TLS and forwards to backend services over Railway’s WireGuard private network. How does encrypted traffic reach that gateway without first being terminated and forwarded as plaintext by Railway’s public edge?
Does Railway support TLS passthrough, TCP Proxy ingress, an external ingress connected through private networking, or another documented configuration for this requirement? If the gateway still receives plaintext HTTP from Railway’s edge, please confirm that this architecture does not eliminate the unencrypted hop.
This is a platform-architecture question; no application logs, credentials, secrets, or customer data are required.
Pinned Solution
2 months ago
- Yes,
cloudflaredwould run as its own service, and you'll be routing traffic through the private network. - Yes and yes (https://docs.railway.com/networking/private-networking).
- Yes.
- Yes, since traffic would be going from Cloudflare to the tunnel service directly.
- https://docs.railway.com/deployments/scaling#horizontal-scaling-with-replicas
- Below:
For WS/streaming, timeout is 100s, so you'd need keepalives.
For upload, https://developers.cloudflare.com/cache/concepts/default-cache-behavior/#upload-limits.
For client IP, you can use the CF-Connecting-IP header injected by Cloudflare.
4 Replies
2 months ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • about 2 months ago
2 months ago
You could run a Cloudflare Tunnel into your service.
Traffic would reach the tunnel, then it would be routed into the service via private networking.
0x5b62656e5d
You could run a Cloudflare Tunnel into your service. Traffic would reach the tunnel, then it would be routed into the service via private networking.
2 months ago
Thank you. Could you please confirm the complete supported architecture?
- Would cloudflared run as a dedicated Railway service, with the Glideslope application reachable only through its *.railway.internal address?
- Is traffic from Cloudflare’s edge to cloudflared encrypted by Cloudflare Tunnel, and then from cloudflared to the application encrypted by Railway’s WireGuard private network?
- Must Railway public networking be removed from the application service to prevent clients from bypassing the tunnel and reaching Railway’s normal TLS-terminating edge?
- Does this mean public requests no longer pass through Railway’s public edge-to-container plaintext HTTP path?
- Can you provide Railway-supported implementation documentation and recommended production high-availability configuration?
- Are there known latency, WebSocket, streaming, upload, client-IP, or availability considerations?
We need an evidence-backed architecture for OWASP ASVS 5.0 V12.3.1 while preserving or improving application performance.
2 months ago
- Yes,
cloudflaredwould run as its own service, and you'll be routing traffic through the private network. - Yes and yes (https://docs.railway.com/networking/private-networking).
- Yes.
- Yes, since traffic would be going from Cloudflare to the tunnel service directly.
- https://docs.railway.com/deployments/scaling#horizontal-scaling-with-replicas
- Below:
For WS/streaming, timeout is 100s, so you'd need keepalives.
For upload, https://developers.cloudflare.com/cache/concepts/default-cache-behavior/#upload-limits.
For client IP, you can use the CF-Connecting-IP header injected by Cloudflare.
0x5b62656e5d
1. Yes, `cloudflared` would run as its own service, and you'll be routing traffic through the private network. 2. Yes and yes (https://docs.railway.com/networking/private-networking). 3. Yes. 4. Yes, since traffic would be going from Cloudflare to the tunnel service directly. 5. https://docs.railway.com/deployments/scaling#horizontal-scaling-with-replicas 6. Below: For WS/streaming, timeout is 100s, so you'd need keepalives. For upload, https://developers.cloudflare.com/cache/concepts/default-cache-behavior/#upload-limits. For client IP, you can use the `CF-Connecting-IP` header injected by Cloudflare. https://railway.com/deploy/cloudflare-tunnel--cf-tunnel
2 months ago
Thank you so much!
Status changed to Solved mayori • about 2 months ago