Supported way to obtain a trusted client IP behind Railway’s HTTP edge
adminjumi
HOBBYOP

21 days ago

We need the client IP for login rate limiting and audit records in an app behind Railway’s HTTP edge.

A temporary test using a generated HTTPS domain in EU West, without a TCP Proxy, showed:

  • Client-supplied X-Real-IP was replaced with the actual client address.
  • Client-supplied X-Forwarded-For was replaced with two entries: the client address and another proxy hop.
  • The connecting socket address varied within 100.64.0.0/10.
  • Client-supplied Forwarded passed through unchanged.

Could Railway staff confirm the supported trust contract?

  1. Is X-Real-IP always overwritten by Railway on every supported HTTP ingress path?
  2. Can a public or private ingress path reach the service without that overwrite?
  3. What proxy-trust configuration is recommended? Are stable proxy ranges documented, or should applications use a specific Railway-controlled header under defined conditions?

We don’t want to base a security configuration on one observed test. A link to authoritative documentation or confirmation from Railway staff would be appreciated.

$10 Bounty

1 Replies

Railway
BOT

21 days ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • 21 days ago


  1. X-Real-IP is overwritten at the edge.
  2. Not unless you use a TCP proxy or private networking.
  3. All proxies should be trusted. There isn’t a documented CIDR range.

Welcome!

Sign in to your Railway account to join the conversation.

Loading...