Static IP guide

Connecting to Amazon Redshift with a static IP from a Node app on Heroku

Redshift clusters sit behind VPC security groups, and analytics jobs running on Heroku dynos arrive from a different IP every restart. Redshift speaks the Postgres wire protocol, so the same pg-plus-socksjs pattern used for Postgres connects to your cluster on port 5439 through Fixie's fixed addresses.

RuntimeNode.js and JavaScript
PlatformHeroku
DestinationAmazon Redshift
Fixie productFixie Socks Heroku add-on

Recommended setup

Use Fixie Socks Heroku add-on for Amazon Redshift connections that require a stable source IP. Store the proxy value in FIXIE_SOCKS_HOST, then configure Node.js to route outbound traffic through Fixie before connecting to Amazon Redshift.

Set up Fixie on Heroku

Heroku is a native Fixie marketplace flow. Install the Fixie Socks Heroku add-on or attach it from the Heroku CLI. Heroku will create FIXIE_SOCKS_HOST as a config var for the app.

Attach fixie-socks to your Heroku app

heroku addons:create fixie-socks
heroku config:get FIXIE_SOCKS_HOST

Implementation

The example below shows the core application-side change. Keep credentials in environment variables and avoid committing proxy, database, or API secrets.

Connect to Amazon Redshift through FIXIE_SOCKS_HOST

const pg = require('pg');
const SocksConnection = require('socksjs');

const fixieValues = process.env.FIXIE_SOCKS_HOST.split(new RegExp('[/(:\\/@)/]+'));

const databaseServer = {
  host: 'redshift-cluster.example.com',
  port: 5439,
};

const fixieConnection = new SocksConnection(databaseServer, {
  user: fixieValues[0],
  pass: fixieValues[1],
  host: fixieValues[2],
  port: fixieValues[3],
});

const client = new pg.Client({
  user: process.env.DB_USER,
  password: process.env.DB_PASSWORD,
  database: process.env.DB_NAME,
  stream: fixieConnection,
  ssl: true,
});

client.connect()
  .then(() => client.query('select 1 as ok'))
  .then((result) => console.log(result.rows[0]));

Good to know

  • The cluster (or Redshift Serverless workgroup) must be publicly accessible, with an inbound security-group rule for both Fixie IPs on port 5439.
  • Batch jobs that pause between queries should reconnect or send a keepalive rather than assuming a long-idle connection is still open.

Allowlist and test the static IPs

  1. Open the Fixie dashboard and copy the outbound IP addresses for this proxy.
  2. Add both IPs to the Redshift security group.
  3. Deploy the updated Node.js app on Heroku.
  4. Run a small connection test before sending production traffic.

Related guides

Related docs