Static IP guide

Connecting to Postgres with a static IP from a Node app on AWS Lambda

A Lambda function querying an allowlisted Postgres database usually gets forced into a VPC with NAT just to stabilize its address. Fixie Socks avoids that entirely: the function stays VPC-free, opens a socksjs stream inside the invocation, and RDS admits it because the security group lists Fixie's two IPs.

RuntimeNode.js and JavaScript
PlatformAWS Lambda
DestinationPostgres
Fixie productFixie Socks proxy

Recommended setup

Use Fixie Socks proxy for Postgres connections to a database that only accepts traffic from approved IP addresses. Store the proxy value in FIXIE_SOCKS_HOST, then configure Node.js to route outbound traffic through Fixie before connecting to Postgres.

Set up Fixie on AWS Lambda

Create a Fixie Socks proxy in the Fixie dashboard. Copy the proxy value into AWS Lambda environment variables as FIXIE_SOCKS_HOST, and copy the outbound IPs into the destination allowlist.

Set an AWS Lambda environment variable

aws lambda update-function-configuration \
  --function-name YOUR_FUNCTION \
  --environment "Variables={FIXIE_SOCKS_HOST=...}"

Implementation

The example below shows the core application-side change. Keep credentials in environment variables and avoid committing proxy, database, or API secrets.

Connect to Postgres through FIXIE_SOCKS_HOST

const pg = require('pg');
const SocksConnection = require('socksjs');

const fixieValues = process.env.FIXIE_SOCKS_HOST.split(new RegExp('[/(:\\/@)/]+'));

const databaseServer = {
  host: 'postgres.example.com',
  port: 5432,
};

const fixieConnection = new SocksConnection(databaseServer, {
  user: fixieValues[0],
  pass: fixieValues[1],
  host: fixieValues[2],
  port: fixieValues[3],
});

const client = new pg.Client({
  user: process.env.DB_USER,
  password: process.env.DB_PASSWORD,
  database: process.env.DB_NAME,
  stream: fixieConnection,
  ssl: true,
});

client.connect()
  .then(() => client.query('select 1 as ok'))
  .then((result) => console.log(result.rows[0]));

Good to know

  • Connect and disconnect within the handler; sockets left open when the execution environment freezes will be dead on thaw.
  • Add both Fixie IPs to the security group on port 5432; a database in a private subnet must also be made publicly accessible for this path.
  • For high-frequency functions, batch events (SQS batching works well) so connection churn does not overwhelm the database.

Allowlist and test the static IPs

  1. Open the Fixie dashboard and copy the outbound IP addresses for this proxy.
  2. Add both IPs to the Postgres firewall or security group.
  3. Deploy the updated Node.js app on AWS Lambda.
  4. Run a small connection test before sending production traffic.

Related guides

Related docs