Which client-address headers does the Railway edge set, and are caller copies replaced?
launcherry
HOBBYOP
7 days ago
Hello Railway team. Our API service serves a custom domain proxied by Cloudflare. In your HTTP logs, srcIp shows the real visitor, while our application's socket peer is always an address in 100.64.0.0/10. We want to identify visitors reliably and would like to confirm:
- Which of these headers does your edge set or overwrite before the request reaches the container: X-Real-IP, X-Forwarded-For, X-Forwarded-Proto, X-Forwarded-Host, Forwarded, X-Envoy-External-Address?
- Does it discard caller-supplied copies of X-Real-IP and X-Forwarded-For, or append to them?
- When the connecting party is a Cloudflare edge, does X-Real-IP carry the Cloudflare address or the visitor from CF-Connecting-IP? What produces srcIp in your HTTP logs in that case?
- Is CF-Connecting-IP forwarded to the container unchanged?
- Which addresses can the container's socket peer have? Is 100.64.0.0/10 stable and documented, and can the peer be IPv6 (for example in fd12::/16)?
- Is this behaviour documented and treated as a stable contract?
Thank you.
Pinned Solution
7 days ago
X-Real-IP,X-Forwarded-For,X-Forwarded-Proto,X-Forwarded-Hostare all overwritten at Railway's edge.- Answered above (yes, it's overwritten at the edge).
- You can still get the client’s IP from
X-Real-IPeven if you have Cloudflare’s proxy in front of your service. - Yes, unless you have a separate proxy that modifies headers.
- There are no documented ranges for Railway's proxies.
- What is the "behavior" in question 6? If you mean Railway's proxy CIDR range, then no,
100.64.0.0/10is not a stable range. It may change at any time.
https://docs.railway.com/networking/public-networking/specs-and-limits#technical-specifications
1 Replies
Railway
BOT
7 days ago
This thread has been opened as a bounty so the community can help solve it.
Status changed to Open Railway • 7 days ago
7 days ago
X-Real-IP,X-Forwarded-For,X-Forwarded-Proto,X-Forwarded-Hostare all overwritten at Railway's edge.- Answered above (yes, it's overwritten at the edge).
- You can still get the client’s IP from
X-Real-IPeven if you have Cloudflare’s proxy in front of your service. - Yes, unless you have a separate proxy that modifies headers.
- There are no documented ranges for Railway's proxies.
- What is the "behavior" in question 6? If you mean Railway's proxy CIDR range, then no,
100.64.0.0/10is not a stable range. It may change at any time.
https://docs.railway.com/networking/public-networking/specs-and-limits#technical-specifications
Status changed to Solved medim • 6 days ago
