Static IP guide

Connecting to Postgres with a static IP from a Node app on Heroku

A Node app on Heroku connecting to an external Postgres server — an RDS instance, a client's database, or anything behind a security group — needs a source IP the database firewall can trust, and dyno IPs change too often to allowlist. Fixie Socks tunnels the connection at the TCP level, so the pg driver works unchanged apart from a custom connection stream.

RuntimeNode.js and JavaScript
PlatformHeroku
DestinationPostgres
Fixie productFixie Socks Heroku add-on

Recommended setup

Use Fixie Socks Heroku add-on for Postgres connections to a database that only accepts traffic from approved IP addresses. Store the proxy value in FIXIE_SOCKS_HOST, then configure Node.js to route outbound traffic through Fixie before connecting to Postgres.

Set up Fixie on Heroku

Heroku is a native Fixie marketplace flow. Install the Fixie Socks Heroku add-on or attach it from the Heroku CLI. Heroku will create FIXIE_SOCKS_HOST as a config var for the app.

Attach fixie-socks to your Heroku app

heroku addons:create fixie-socks
heroku config:get FIXIE_SOCKS_HOST

Implementation

The example below shows the core application-side change. Keep credentials in environment variables and avoid committing proxy, database, or API secrets.

Connect to Postgres through FIXIE_SOCKS_HOST

const pg = require('pg');
const SocksConnection = require('socksjs');

const fixieValues = process.env.FIXIE_SOCKS_HOST.split(new RegExp('[/(:\\/@)/]+'));

const databaseServer = {
  host: 'postgres.example.com',
  port: 5432,
};

const fixieConnection = new SocksConnection(databaseServer, {
  user: fixieValues[0],
  pass: fixieValues[1],
  host: fixieValues[2],
  port: fixieValues[3],
});

const client = new pg.Client({
  user: process.env.DB_USER,
  password: process.env.DB_PASSWORD,
  database: process.env.DB_NAME,
  stream: fixieConnection,
  ssl: true,
});

client.connect()
  .then(() => client.query('select 1 as ok'))
  .then((result) => console.log(result.rows[0]));

Good to know

  • For RDS, add an inbound rule for each Fixie IP on port 5432 — allowlisting only one causes intermittent connectivity.
  • TLS works through the tunnel; keep ssl: true (or sslmode=require) exactly as you would for a direct connection.

Allowlist and test the static IPs

  1. Open the Fixie dashboard and copy the outbound IP addresses for this proxy.
  2. Add both IPs to the Postgres firewall or security group.
  3. Deploy the updated Node.js app on Heroku.
  4. Run a small connection test before sending production traffic.

Related guides

Related docs