Railway
Connect
Connect Railway from the terminal. Pass --help for the flags Railway accepts, plus --no-browser for headless environments.
polylane cloud connect --provider railwayOAuth authorization.
Railway connects via OAuth: click Continue to Railway, authorize read access on Railway, and you're redirected back with syncing already started. Tokens are encrypted before they are stored, and the agent never sees them.
Polylane discovers your projects, environments, services, deployments, volumes, domains, and TCP proxies. Service metrics power charts and anomaly detection. Variable names are synced for cross-cloud linking; variable values are never read. Ephemeral (pull request) environments are skipped.
Deploy and alert webhooks
Railway pushes deployment status changes and usage alerts through notification rules. Pointing one at Polylane alerts on failed or crashed deploys, resolves the alert on the next successful deploy, and schedules a resync:
- Copy the webhook URL from the cloud account's Settings page in Polylane (it ends with your Railway workspace ID).
- In Railway, open your workspace's Notifications settings and add a webhook rule pointing at that URL.
- Select the Deployment events you care about:
Deployment.deployed,Deployment.failed,Deployment.crashed, andDeployment.oom_killedcover the alerting flow (Railway's success event isDeployment.deployed; there is noDeployment.success). - Add the VolumeAlert and Monitor events, including
VolumeAlert.resolvedandMonitor.resolved, so volume and monitor alerts open and close automatically in Polylane.
Troubleshooting
Authorization fails or is canceled
- Make sure you're signed in to Railway with an account that can access the workspace.
- Retry from Continue to Railway; the authorization link is only valid for a few minutes.
Missing resources
- Railway can take a few minutes to sync everything.
- Ephemeral (pull request) environments are not synced.
- Trigger a manual Sync from the account header to refresh.
Disconnecting
Disconnect the account in Polylane, then revoke the OAuth grant in your Railway account settings, and remove the notification rule if you created one.
Connect Railway from a CI job or any other environment without a browser.
Connecting Railway needs no browser: the same endpoint the console calls fits in a CI job. One authenticated POST creates the connection and starts the first sync.
Prerequisites
- A Polylane API key with the
cloud_accounts:writeandcloud_accounts:readscopes. See API keys and OAuth. - Your workspace ID, which starts with
ws_. Read it fromGET /v1/workspaceswith the same key. - A Railway workspace token from your workspace settings. The console's OAuth flow needs a browser; workspace tokens do not.
Create the connection
curl -X POST https://api.polylane.com/v1/cloud_accounts \
-H "x-api-key: $POLYLANE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"provider": "railway",
"workspaceId": "ws_0abc123",
"token": "<railway-workspace-token>"
}'
One call connects every Railway workspace the token can reach; pass the optional railwayWorkspaceId to connect just one.
The response lists what was connected, with the first sync already running. Trimmed to the two fields the rest of the flow reads:
{
"success": true,
"result": {
"provider": "railway",
"accounts": [{ "id": "acc_34gky74ibc92h8t2efn8csrh", "status": "syncing" }],
"failures": []
}
}
An account that is already connected lands in failures instead of accounts, so repeating the call never duplicates a connection.
Wait for the first sync
Poll each returned account by its id until status reaches ready (new on registration, syncing while resources stream in):
until [ "$(curl -s "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY" | jq -r '.result.status')" = "ready" ]; do
sleep 15
done
Give the loop a deadline so a failed connect fails the job instead of hanging it. Once the account is ready, its resources are in the topology and Polylane has started its first check.
Disconnect from the API
Deleting the connection stops every sync and check and deletes the credentials Polylane held. The call needs the cloud_accounts:delete scope:
curl -X DELETE "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY"
Then revoke the Railway credential on the provider side, as described under Disconnect below.
Disconnect
Disconnecting stops every sync and check and deletes the credentials Polylane held. Polylane removes what Railway's API lets it remove. The following stays until you remove it yourself:
- OAuth grant
polylane cloud disconnect <id>Tools
4Operations agents can perform in threads.
Supported resources
8Resource types that show up in your infrastructure graph.