Static IP guide
Connecting to Postgres with a static IP from a Python app on Heroku
Django and SQLAlchemy apps on Heroku reach IP-allowlisted Postgres servers through a Fixie-Wrench tunnel: the binary listens on localhost:5432 and relays through Fixie Socks, so psycopg needs no proxy awareness at all. The database only ever sees your two static Fixie addresses.
Recommended setup
Use Fixie Socks Heroku add-on for Postgres connections to a database that only accepts traffic from approved IP addresses. Store the proxy value in FIXIE_SOCKS_HOST, then configure Python to route outbound traffic through Fixie before connecting to Postgres.
Set up Fixie on Heroku
Heroku is a native Fixie marketplace flow. Install the Fixie Socks Heroku add-on or attach it from the Heroku CLI. Heroku will create FIXIE_SOCKS_HOST as a config var for the app.
Attach fixie-socks to your Heroku app
heroku addons:create fixie-socks
heroku config:get FIXIE_SOCKS_HOSTImplementation
The example below shows the core application-side change. Keep credentials in environment variables and avoid committing proxy, database, or API secrets.
Forward a local port to Postgres through Fixie Socks
# Install Fixie-Wrench in your app build or deploy process.
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/usefixie/fixie-wrench/HEAD/install.sh)"
# Start a tunnel from localhost:5432 to postgres.example.com:5432.
# Your Python app connects to localhost:5432; Fixie handles the outbound static IP.
./bin/fixie-wrench 5432:postgres.example.com:5432Good to know
- Django settings: HOST: "
127.0.0.1", PORT:5432— credentials and sslmode stay exactly as for a direct connection. - Start the tunnel in the Procfile before the app:
web: ./bin/fixie-wrench 5432:postgres.example.com:5432 & gunicorn config.wsgi. - Heroku's own Heroku Postgres does not need any of this; the tunnel is for external databases that enforce allowlists.
Allowlist and test the static IPs
- Open the Fixie dashboard and copy the outbound IP addresses for this proxy.
- Add both IPs to the Postgres firewall or security group.
- Deploy the updated Python app on Heroku.
- Run a small connection test before sending production traffic.
Related guides
- Making API requests with a static IP from a Python app on Heroku
- Connecting to Postgres with a static IP from a Python app on Render
- Connecting to Postgres with a static IP from a Node app on Heroku
- Connecting to MySQL with a static IP from a Python app on Heroku
- Connecting to Postgres with a static IP from a Ruby app on Heroku
- Connecting to Amazon Redshift with a static IP from a Python app on Heroku