Static IP guide

Connecting to Postgres with a static IP from a Node app on Vercel

Connecting Vercel functions to Postgres behind an IP allowlist — RDS, Supabase with network restrictions, a corporate database — fails by default because function egress IPs are unpredictable. Fixie Socks solves it in code: a socksjs stream handed to the pg client, created inside the invocation, presenting a fixed IP to the database.

RuntimeNode.js and JavaScript
PlatformVercel
DestinationPostgres
Fixie productFixie Vercel integration

Recommended setup

Use Fixie Vercel integration for Postgres connections to a database that only accepts traffic from approved IP addresses. Store the proxy value in FIXIE_SOCKS_HOST, then configure Node.js to route outbound traffic through Fixie before connecting to Postgres.

Set up Fixie on Vercel

Add the Fixie Vercel integration, create a proxy in the Fixie dashboard, and connect it to the Vercel project and environment. The integration can create FIXIE_SOCKS_HOST in Vercel Environment Variables for the connected project.

Pull Vercel environment variables locally

vercel env pull
grep FIXIE_SOCKS_HOST .env.local

Implementation

The example below shows the core application-side change. Keep credentials in environment variables and avoid committing proxy, database, or API secrets.

Connect to Postgres through FIXIE_SOCKS_HOST

const pg = require('pg');
const SocksConnection = require('socksjs');

const fixieValues = process.env.FIXIE_SOCKS_HOST.split(new RegExp('[/(:\\/@)/]+'));

const databaseServer = {
  host: 'postgres.example.com',
  port: 5432,
};

const fixieConnection = new SocksConnection(databaseServer, {
  user: fixieValues[0],
  pass: fixieValues[1],
  host: fixieValues[2],
  port: fixieValues[3],
});

const client = new pg.Client({
  user: process.env.DB_USER,
  password: process.env.DB_PASSWORD,
  database: process.env.DB_NAME,
  stream: fixieConnection,
  ssl: true,
});

client.connect()
  .then(() => client.query('select 1 as ok'))
  .then((result) => console.log(result.rows[0]));

Good to know

  • Open and close the client within the invocation — a connection cached across invocations can go stale between requests and fail confusingly.
  • This must run on the Node.js runtime; the Edge runtime has no TCP sockets.
  • Security-group rules need both Fixie IPs on port 5432.

Allowlist and test the static IPs

  1. Open the Fixie dashboard and copy the outbound IP addresses for this proxy.
  2. Add both IPs to the Postgres firewall or security group.
  3. Deploy the updated Node.js app on Vercel.
  4. Run a small connection test before sending production traffic.

Related guides

Related docs