Skip to content

Static outbound IP for serverless apps: a Fixie and QuotaGuard alternative

Partner APIs, payment providers, banks, and database firewalls often only accept traffic from IP addresses you register in advance. Serverless platforms and autoscaling containers don’t give you one: each request can leave from a different, shared address.

The usual fixes are a static IP proxy add-on (such as Fixie or QuotaGuard), a NAT gateway with an elastic IP in your own cloud network, or a platform’s own static-egress feature where one exists. Consensus offers another option: lease a node, and your requests leave from that node’s IPv4 address.

import { ProxyClient, createPaymentFetch } from '@canister-software/consensus-cli'
const proxy = ProxyClient(await createPaymentFetch(), {
node_domain: 'a3f1c94b2e07.consensus.canister.software', // your leased node
})
const res = await proxy.fetch('https://api.partner.example/v1/orders')

The full walkthrough, including how to find the IP to whitelist, is in Static IP for API whitelisting.

ConsensusStatic IP proxy add-onNAT gateway + elastic IP
Works from serverless (Vercel, Netlify, Lambda)YesYesOnly inside your VPC
Account or subscriptionNoneMonthly planCloud account, hourly + data charges
How your code uses itSDK (ProxyClient) or POST /proxyStandard HTTP_PROXY / SOCKSTransparent
IP is dedicated to youNo, it’s the node’s addressDepends on planYes
RedundancyLease a second node as a fallbackUsually two IPs includedPer availability zone
PriceFree during the public betaPaidPaid
  • you’re on a serverless or edge platform and only need a handful of upstream calls whitelisted;
  • you don’t want a monthly add-on or to run a VPC and NAT gateway just for egress;
  • you also want deduplicated, cached requests, for example from replicated or retried workers that would otherwise call the partner API many times.
  • You need a standard HTTP proxy. Consensus routes requests through its SDK or POST /proxy; it isn’t a drop-in HTTP_PROXY setting yet.
  • The IP must be yours alone. A leased node’s address can also carry other users’ traffic.
  • The integration can’t tolerate a node going offline. If your leased node is down, requests can leave from another IP. Whitelist a second leased node, or use a NAT gateway for critical paths.

How do I get a static outbound IP on Vercel or Netlify? Route the calls that need whitelisting through a leased Consensus node with ProxyClient, then whitelist that node’s IP. The rest of your traffic is unaffected.

Which IP do I whitelist? The node list doesn’t publish addresses, so you ask an IP echo service through your leased node. See Find the IP to whitelist.

Does the IP change? Not while you keep routing through the same leased node. See Keep it reliable.

Is it free? Proxied requests are free during the public beta.