TCP proxy still routing to my Postgres service after public networking was removed

I removed Public Access and the DATABASE_PUBLIC_URL variable from a Postgres service

(production environment). Settings > Networking now shows public access as off, and

the Railway agent staged and applied a removal of the TCP proxy for application port

  1. However, the proxy endpoint that was assigned before still accepts connections:

a test with a deliberately wrong password returns "password authentication failed",

so it is still reaching the database.

Could a Railway team member remove the leftover TCP proxy for this service? I can

share the project and service IDs privately if needed. The app connects over

postgres.railway.internal, so removing the proxy should not affect it.

Solved

2 Replies

Railway
BOT

4 hours ago

TCP proxy domains and ports come from a shared pool and are not permanently reserved for your account. Once you remove a proxy, that same domain and port can be reassigned to another customer's service, which may also be a Postgres database. A "password authentication failed" response at the old address only shows that some Postgres server is answering there. It does not mean your database is still exposed.

Remove the old connection string from any clients, and don't send your real credentials to that address. Your app can keep using postgres.railway.internal.


Status changed to Awaiting User Response Railway • about 4 hours ago


Railway

TCP proxy domains and ports come from a shared pool and are not permanently reserved for your account. Once you remove a proxy, that same domain and port can be reassigned to another customer's service, which may also be a Postgres database. A "password authentication failed" response at the old address only shows that some Postgres server is answering there. It does not mean your database is still exposed. Remove the old connection string from any clients, and don't send your real credentials to that address. Your app can keep using `postgres.railway.internal`.

Update: the proxy appears to be gone. My database's logs show no connection attempts

from my tests, so the old host/port now answers from another service. Please disregard

unless you see a leftover proxy on my service. Thanks.


Status changed to Awaiting Railway Response Railway • about 3 hours ago


Status changed to Solved Railway • about 3 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...