Issues with upstream DNS provider
status.heroku.com
status.heroku.com
1. Find your DNS Target in heroku. It should end with .herokudns.com
2. Lookup the historical DNS record to get the IP addresses. You can find historical DNS records here: https://securitytrails.com/dns-trails
3. Replace your CNAME record in your DNS provider with A records that point to the IP addresses you just found.
Your site should come back up shortly. We plan to revert back to CNAME records once Heroku gets their DNS issues sorted.
Or is it possible in the Cloudflare dashboard there is somewhere to see your Heroku server's IP address?
EDIT: I MANAGED to make it work with this:
Make sure to go through all the tabs at the top (Cloudflare DNS, Google DNS) - for me they were all "no A records found". Only "Authoritative" gave me 3 A records which I successfully managed to use.
If you just use something like https://poof.io, then it would be @. Depends on your site.
There should be a few historical IP addresses, but you would create an A record for each of them.
That is a random public DNS server I found on a DNS checker site that works (as it seems to be down from all the common ones like 8.8.8.8, 1.1.1.1, etc). DOMAIN can be your actual domain or the long heroku alias.
Unfortunately the Heroku issue lost us a few thousand $ alongside a few customers.
What are the chances that their current work on the DNS issues might replace the underlying IP-addresses and hence we are making it harder on ourselves?
It worked for me, so once Heroku has sorted their s*t out and their DNS system is back up it's just a matter of deleting the A records and replacing it with the CName.
Worst case scenario is the underlying Amazon IP Addresses change and it goes back down.
And for those using Cloudflare, this method works.
For those on Cloudflare, this will still work. I just deleted the existing CNAME, added the 4 IP addresses as seperate A records and it came back up instantly.
Edit: It also works for subdomains.
You just caused a very painful outage for your entire customer base, and a number of us used this hack to get back online. If you don't recognize this, and cause ANOTHER outage (the third in the past few weeks...) we're going to flee even faster to more stable platforms.
1. Create a new temporary subdomain in the Cloudflare DNS panel, e.g. "temp-heroku-resolve.your-domain.com", with IPs from the responses you get by querying Heroku's upstream provider directly (`dig @1.1.1.1 +trace your-app.herokuapp.com`). Make them unproxied (grey cloud) A records with a 30s TTL.
2. Change your root CNAME to point at "temp-heroku-resolve.your-domain.com"
To undo, just reverse these steps and point your root CNAME back at Heroku.
(not trying to be snarky, trying to understand)
In our case, we have substantial logic running on the edge in Cloudflare Workers, as well as lots of other Cloudflare configuration options, and I don't even want to know what it could potentially do to our zone to remove the root DNS record that everything's tied to.
Note: If you used to have a CNAME record for yourdomain.com to www.yourdomain.com, then you have to add two A records per each IP (one whose name is yourdomain.com pointing to the IP, and another whose name is www pointing to the same IP)
Should be able to go back to CNAME now. Regardless, recheck yours
I did get a lot of perf increases moving from GCP to Fly, but I think I have to credit most of the improvements to SQLite being faster than Firestore:
https://mtlynch.io/retrospectives/2021/12/#migrating-my-side...
The one notable outage was this bug where Fly was evicting smaller instances at overloaded DCs rather than preventing new apps from acquiring resources:
https://community.fly.io/t/app-stuck-in-pending-state-after-...
The workaround was to upgrade to a larger instance, but I probably evicted someone else.
Sadly, we're still using Heroku DNS, but this should accelerate finding an alternative.
I just happened to try out Render last week - perfect timing.
We're currently using Heroku for app hosting, while evaluating fly.io, render.com and railway.app. All three have had exceptional reviews from other customers and differ slightly on their service offerings and setups. All seem like viable alternatives so far!
Most of the reviews we have seen of the competitors are all hobby level. And last time we check some of this competitors we found their security posture was not the level we would require.
So we had to simple rule them out and either stay with Heroku or move to a big 3.
If you’re keen to share - let me know and I’ll send you my details.
Now I assume you were speaking to the 3 mentioned, render, railway, fly in terms of hobby level. All three are fairly young relative to Heroku's age, but Fly did recently get their SOC2 and the team really took it to heart and invested in it so I'd put some stock in that. I can't speak definitively to the others, but do know all three can be solid for production apps. If you've got HIPAA or other specific requirements I'd encourage a conversation with them.
[1] https://www.wiz.io/blog/the-cloud-has-an-isolation-problem-p...
I just read fly had SOC2 type I recently. But I mean this hosting infra containing all our data and our customers data. People providing infra really need to take security extremely seriously and prove it.
Awesome what they are doing - just don’t feel like they are ready for primetime busines. We are a small startup (5k monthly on Heroku) but there is just no reasonable way we can tell our enterprise customers security teams are hosted on these guys and can vouch and vet their security.
Once fly has type II - we’ll take another look.
$ dig @1.1.1.1 stark-wisteria-rnbgkawldfk6gq7m8308ytts.herokudns.com A
...
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; OPT=15: 00 09 6e 6f 20 53 45 50 20 6d 61 74 63 68 69 6e 67 20 74 68 65 20 44 53 20 66 6f 75 6e 64 20 66 6f 72 20 68 65 72 6f 6b 75 64 6e 73 2e 63 6f 6d 2e ("..no SEP matching the DS found for herokudns.com.")
;; QUESTION SECTION:
;stark-wisteria-rnbgkawldfk6gq7m8308ytts.herokudns.com. IN A
I wonder if there is any way to get out an IP address of the Heroku router we were assigned to that we can use in place of the CNAME.Might be in the logs somewhere, or in Cloudflare somewhere?
Hopefully someone has a backup of those keys. If not, I think they have to contact .com. to replace the keys. It can take several hours to come back.
If you're interested in getting early access - get in touch here: hello@awareops.com
Haven't changed DNS in months. Site is down.
Heroku is looking increasingly like nobody is minding the store these days. I still know of no competitor which can match the DX when it's working, but what good does that do you if it breaks all the time.
We're still waiting on them fixing our ability to restore from backups without manual hack -- which is effecting many customers, but which they don't even have an active published incident on.
Ouch. Not a great look, Heroku!
We proxy some services through Cloudflare to gain IPv6 support, and all of those are down, which suggests the Cloudflare -> Heroku network route is broken.
dig NS @1.1.1.1 test.herokuapp.com -> fail
dig @1.1.1.1 test.herokuapp.com -> fail
dig NS @dns1.p03.nsone.net test.herokuapp.com -> works
dig @dns1.p03.nsone.net test.herokuapp.com -> works
So my conclusion is that NS1 is having issue responding DNS queries from other DNS servers. Interestingly, there is no public information on heroku being dependent on NS1 or any current outages from NS1 status page.I have a migration plan in place but it's been put on hold to launch a new Product.
They don't share upstream DNS (and I'm not sure heroku's homepage has the same DNS provider as customer domains). NS matches SOA for each of these domains.
SOA heroku.com. 1h00m00s "dns1.p04.nsone.net." "hostmaster.nsone.net."
SOA hackerweb.app. 1h00m00s "olga.ns.cloudflare.com." "dns.cloudflare.com."
SOA substack.com. 1h00m00s "ali.ns.cloudflare.com." "dns.cloudflare.com."Email I get, because there has been a hard push for decades to force everyone on to big providers, but DNS can literally be run by anyone, anywhere.
Did the primary servers push bad data, making the secondary / tertiary ones break, too? If not, why not extend the cache lifetime and run off of them until the primary are fixed?
Sigh. This is rather ridiculous, and is rather embarrassing for Heroku.
Looks like they nuked their DNS.
Is Salesforce committed to Heroku?
Note: If you used to have a CNAME record for yourdomain.com to www.yourdomain.com, then you have to add two A records per each IP (one whose name is yourdomain.com pointing to the IP, and another whose name is www pointing to the same IP)
Is this isolated to Heroku?