Static IP guide

Connecting to Postgres with a static IP from a Node app on Fly.io

For a Node app on Fly.io reaching a Postgres database that enforces an IP allowlist — outside Fly's private network, where WireGuard cannot help — Fixie Socks provides the fixed source address. The pg driver connects over a socksjs stream, and the database firewall needs only Fixie's two IPs, not whatever egress path a machine has today.

RuntimeNode.js and JavaScript
PlatformFly.io
DestinationPostgres
Fixie productFixie Socks proxy

Recommended setup

Use Fixie Socks proxy for Postgres connections to a database that only accepts traffic from approved IP addresses. Store the proxy value in FIXIE_SOCKS_HOST, then configure Node.js to route outbound traffic through Fixie before connecting to Postgres.

Set up Fixie on Fly.io

Create a Fixie Socks proxy in the Fixie dashboard. Copy the proxy value into Fly.io secrets as FIXIE_SOCKS_HOST, and copy the outbound IPs into the destination allowlist.

Set a Fly.io secret

fly secrets set FIXIE_SOCKS_HOST=...

Implementation

The example below shows the core application-side change. Keep credentials in environment variables and avoid committing proxy, database, or API secrets.

Connect to Postgres through FIXIE_SOCKS_HOST

const pg = require('pg');
const SocksConnection = require('socksjs');

const fixieValues = process.env.FIXIE_SOCKS_HOST.split(new RegExp('[/(:\\/@)/]+'));

const databaseServer = {
  host: 'postgres.example.com',
  port: 5432,
};

const fixieConnection = new SocksConnection(databaseServer, {
  user: fixieValues[0],
  pass: fixieValues[1],
  host: fixieValues[2],
  port: fixieValues[3],
});

const client = new pg.Client({
  user: process.env.DB_USER,
  password: process.env.DB_PASSWORD,
  database: process.env.DB_NAME,
  stream: fixieConnection,
  ssl: true,
});

client.connect()
  .then(() => client.query('select 1 as ok'))
  .then((result) => console.log(result.rows[0]));

Good to know

  • This is for external databases; Fly Postgres reached over the internal private network needs no proxy at all.
  • Set FIXIE_SOCKS_HOST with fly secrets set so it is encrypted at rest and injected at boot.
  • Match the Fixie region to your primary machine region — database round-trips amplify added latency far more than one-off API calls.

Allowlist and test the static IPs

  1. Open the Fixie dashboard and copy the outbound IP addresses for this proxy.
  2. Add both IPs to the Postgres firewall or security group.
  3. Deploy the updated Node.js app on Fly.io.
  4. Run a small connection test before sending production traffic.

Related guides

Related docs