Skip to main content

Networking

RailPush services run on a custom-built deployment engine with built-in service discovery, TLS termination, and load balancing.

Public Access

Every web service gets a public URL at service-name.railpush.com with automatic TLS. Custom domains can be added with automatic certificate provisioning via Let's Encrypt.

Private Networking (Internal DNS)

Services within the same workspace can communicate using private internal DNS without going through the public internet. Use the internal hostname:

Internal service URL
# Format: <service-subdomain>.railpush.svc.cluster.local:<port>
# Example: connect to "my-api" service on port 10000
http://my-api.railpush.svc.cluster.local:10000

# In your service's env vars:
API_URL=http://my-api.railpush.svc.cluster.local:10000

RailPush also injects internal discovery environment variables automatically:

auto-injected env vars
# Current service
RAILPUSH_INTERNAL_HOST=<internal-service-host>
RAILPUSH_INTERNAL_PORT=<port>
RAILPUSH_INTERNAL_URL=http://<internal-service-host>:<port>
RAILPUSH_INTERNAL_SERVICE_ID=<service-id>

# Peer services by name/subdomain label
RAILPUSH_SERVICE_<SERVICE_LABEL>_URL=http://<peer-host>:<peer-port>
RAILPUSH_SERVICE_<SERVICE_LABEL>_ID=<peer-service-id>
RAILPUSH_SERVICE_<SERVICE_LABEL>_PROJECT_ID=<project-id>
RAILPUSH_SERVICE_<SERVICE_LABEL>_ENVIRONMENT_ID=<environment-id>

# Peer services by ID token (stable, collision-safe)
RAILPUSH_SERVICE_ID_<SERVICE_ID_TOKEN>_URL=http://<peer-host>:<peer-port>
Private by default

Internal DNS traffic stays within the cluster network and never traverses the public internet. worker and pserv (private service) types have no public ingress -- they're only reachable via internal DNS.

Disable public ingress for web/static

You can keep a web or static service internal-only by setting one of these env vars, then redeploying:

internal-only ingress toggle
# Any one of these disables public ingress for this service
RAILPUSH_INTERNAL_ONLY=true
# or
RAILPUSH_DISABLE_PUBLIC_INGRESS=true
# or
RAILPUSH_NETWORK_VISIBILITY=internal

When public ingress is disabled, default/public hosts, custom-domain ingresses, and rewrite-rule ingresses are removed for that service while internal DNS discovery remains available.

Service Types & Network Exposure

TypePublic URLInternal DNSUse Case
webYesYesHTTP APIs, web apps
pservNoYesInternal microservices
workerNoYesBackground jobs, queue consumers
cronNoNoScheduled tasks
staticYesNoStatic sites, SPAs

Port Configuration

Each service listens on a single port (default: 10000). The ingress controller handles TLS termination and routes traffic to your service's port. Configure it in your blueprint:

railpush.yaml
services:
- type: web
name: my-api
port: 3000 # your app listens on this port

Rewrite & Proxy Rules

Route specific URL paths from one service to another using server-side proxying. This is useful when a static frontend needs to proxy /api/* requests to a backend service without CORS or mixed-content issues.

  • Requests are proxied server-side via the ingress controller -- no CORS headers needed
  • Rules apply to all hosts: the default subdomain and all custom domains
  • Both source and destination services must be in the same workspace
API: Add rewrite rule
POST /services/:id/rewrite-rules
{
"source_path": "/api/",
"dest_service_id": "<backend-service-id>",
"dest_path": "/api/",
"rule_type": "proxy"
}
// All requests to /api/* on this service will be proxied to the
// destination service at /api/* — path is preserved by default.

Manage rewrite rules in the service's Networking tab or via the API / MCP tools.