AI Native WorkshopGo from AI experimentation to AI-native execution across your organization.
Railway → Azure migration

Railway to Azure in an hour.
Under your own tenant.

One command. An agent reads your repository and your railway.json, then deploys into the Azure subscription you already own - governed by the directory you already run.

No step is destructiveBoth stacks run in parallelRailway stays up until you move DNS
your-app — qovery agent
$ deploy this project with Qovery
Scanning repository...
web Node.js 20 Dockerfile generated
worker Node.js 20 detected from railway.json
scheduler cron 2 jobs
database PostgreSQL 15 Railway Postgres, connected remotely
Plan: 3 services, 1 external database, 12 environment variables
Nothing has been created yet. Approve to continue.
200+ companies run on their own cloud with Qovery4.8 on G2 · 80+ reviews
  • Talkspace
  • Alan
  • Powens
  • Prezi
  • Prosperity
  • Getsafe
Migrated from Heroku
We migrated our whole staging environment with a single prompt. Production was a one-click clone of staging. Once the tests gave us confidence we moved DNS off Heroku - we have been running production on our own cloud with Qovery ever since.
Miguel VictoriaSoftware Engineer, Sofive
Migrated from Heroku
We liked the Heroku experience, and we knew the cloud meant skills and effort we did not have spare - that is why we kept putting the migration off. We do not regret doing it with Qovery. Deployments that took me over two hours now take 30 minutes.
Kyle FlavinDirector of DevOps, RxVantageCase study →
Where Railway stops

Railway is the best DX in the category. It is also a ceiling.

The canvas, the templates and the deploy speed are genuinely good, and none of that is what teams leave over. They leave because the workload has outgrown what somebody else’s account can be asked to do.

Four regions, all on Railway’s own metal

California, Virginia, Amsterdam and Singapore. There is no fifth, and no option to run somewhere your customers or your regulator require. Volumes make this sharper: a volume follows the region of the service it is attached to, so moving a stateful service between regions migrates the volume and takes the service down while it copies. Any Azure region, with multi-region and multi-cluster from one control plane. Storage is not welded to that choice.

Private networking inside a project is not a network you own

Railway gives services encrypted Wireguard tunnels and internal DNS within a project environment, which is the right design for what Railway is. What it is not is a VPC. There is no security group you write, no peering to the database or the VPN or the internal service you already run elsewhere, and no route table. You already own the virtual network. NSGs, private endpoints, peering and NAT gateway egress are yours, and Entra ID governs who can change any of it.

The plan tier caps the workload itself

Replica count per service, RAM, vCPU and volume size are all bounded by which plan you are on, so scaling becomes a billing conversation before it is an engineering one. Deploying from a private container registry needs Pro. Egress is metered and billed per gigabyte on top of compute, which penalises exactly the data-heavy services that are hardest to move. Compliance commitments and SLAs live at Enterprise. In your own subscription none of those are tiers: Entra ID governs access, the Azure activity log records the changes, and the capacity ceiling is whatever quota you ask Azure to raise.
How the migration runs

Three steps, then the agent does it.

Your side takes about five minutes. Everything after that is automated.

  1. 01

    A service principal provisions the network and an AKS cluster in your own subscription - about twenty minutes, and nothing leaves your boundary. Qovery gets a role you can read, scope down or revoke. Talk to a migration engineer before you connect anything.

  2. 02

  3. 03

  4. 04

    Optional
In the Azure console
One service principal, about twenty minutes.
network
your VPC, three fixed egress IPs
cluster
AKS, in your region
access
a role scoped to Qovery
10–60 min

From there it is automatic. Your apps come up running and live on Azure, reachable on a public URL - while the Railway stack keeps serving traffic untouched.

What it costs

You pay Azure. And it counts toward your commitment.

Money metered by Railway counts toward nothing. If your organisation has an Enterprise Agreement or a MACC, the same compute running in your own subscription draws down an obligation you owe Microsoft regardless - which for most finance teams turns the migration from a cost into a transfer.

Depends on your replica counts, RAM and vCPU footprint, volume storage, egress volume and region. A migration engineer will model your estate against the equivalent Azure shape before you commit to anything.

Specific to Azure

Why Azure, when the blocker is the network or the auditor.

The usual reason a team outgrows Railway is not price. It is that something now has to be reached privately, or evidenced to somebody, and a project-scoped Wireguard network cannot do either.

A virtual network, not a project-scoped tunnel

Railway gives services encrypted tunnels and internal DNS inside a project environment. It does not give you a network. In your own subscription you get a virtual network with NSGs you write, private endpoints onto Azure Database and Key Vault, peering to the estate you already run, and a NAT gateway with stable egress addresses somebody else can allowlist.

Entra ID governs deployment, and the audit trail is yours

Access is decided by the directory you already run - your groups, your conditional access policies, your leaver process - rather than by a separate list of project members. Qovery supports SAML SSO, and the Azure activity log records every change to the infrastructure in a tenant your auditors can already reach.

Spend counts toward your EA or MACC

Compute runs on AKS in your subscription, so it draws down an Enterprise Agreement or Microsoft Azure Consumption Commitment like any other Azure workload. Reserved instances cover the steady-state footprint and the savings plan for compute covers the part that moves. On a metered platform there is nothing to reserve and nothing to draw down.
Qovery is not a PaaS

Our control plane. Your account, your bill.

Qovery sits above the infrastructure and never owns it. Every cluster, database and bucket is provisioned inside the Azure subscription you already hold - Azure invoices you directly.

  • We do not take a cut of your Azure spend. A flat subscription, whether your bill is $2k or $200k.
  • We push it the other way: idle nodes, oversized requests and preview environments left running get flagged so you stop paying for them.
  • Railway runs all of this on its own metal. Qovery runs it in yours.

Not sure which Azure services fit your workload? A solution engineer will map it with you.

QoveryCONTROL PLANE
deploymentsenvironmentspreview envsRBAC + auditcost signals
provisions standard Terraform and Kubernetes manifests
Your Azure subscription
invoiced by Azure, directly to you
VPC · your network policy
AKS clusterwebworkercronpreview-pr-482Azure DatabaseAzure CacheBlob Storagesecrets
IAM: yours · data residency: yours · audit trail: yours

Stop paying Qovery and the stack keeps running - the manifests and qovery/qovery Terraform are already in your account.

Leave Railway

Your first service on Azure,
live within the hour.

Any Azure region, with multi-region and multi-cluster from one control plane. Nothing you do here touches your existing Railway project until you decide to move the domain.

Frequently asked

Railway to Azure

Something not covered here? Talk to a migration engineer - they have done this on estates larger than yours.

How long does a Railway to Azure migration take?

First app live in under an hour. Full estates finish in days: the agent reads your repository and your railway.json, so the services, build settings and variables you already declared become the deployment plan. The pace is set by your data and your change windows, not by the tooling.

Will migrating disrupt our running Railway services?

No. Nothing in the process modifies or removes anything on Railway. Both stacks run in parallel until you move DNS, and you can move it back.

Can Qovery migrate our Railway Postgres database to Azure?

Yes. Under 100 GB migrates live with minimal interruption. Larger datasets use a replication-based cutover rather than a dump and restore. The database lands in your own Azure subscription on Azure Database for PostgreSQL, under your keys and your backup policy.

We use Railway volumes. What happens to them?

They become persistent volume claims in your own cluster, or object storage where the data is really blobs rather than a filesystem. Either way the region coupling goes: a Railway volume follows its service’s region and moving one means a migration with downtime, which is not true of storage in an account you control.

Is Qovery just another Railway?

No, and this is the whole difference. Railway runs your services on Railway’s own metal. Qovery installs into the cloud account you already own - you hold the cloud bill, the VPC, the cluster and the audit trail. The control plane is ours, the infrastructure is yours.

What happens if we stop using Qovery?

Everything keeps running. Qovery generates standard Terraform and native Kubernetes manifests in your account, so the estate outlives the subscription. Leaving Railway means moving the workload; leaving Qovery does not.

Can this burn our existing Azure commitment?

Yes. Compute runs on AKS in your own subscription, so the spend counts toward an Enterprise Agreement or a Microsoft Azure Consumption Commitment exactly like any other Azure workload. Money spent with Railway counts toward neither.

Does Qovery work with Entra ID for single sign-on?

Yes. Qovery supports SAML single sign-on, so access is governed by the same Entra ID groups and conditional access policies as the rest of your Microsoft estate.

Does the workload stay inside our tenant?

Yes. The AKS cluster, the databases and the application data all live inside your own Azure subscription and your own virtual network. Qovery operates them through the Azure API and never hosts your workloads.

How does every Railway primitive map to Azure?

On Railway
On Azure
What changes
Service
AKS pod on Azure Virtual Machines
Autoscales on real utilisation, and the underlying node pool can carry a reservation, the savings plan for compute, or Spot - all billed to your subscription.
Worker service
AKS pod in the same cluster
Long-running work without the 30-second router timeout.
Cron service
Kubernetes CronJob
Real cron expressions instead of fixed ten-minute, hourly and daily buckets.
Railway Postgres
Azure Database for PostgreSQL
Container mode for development, Azure Database for PostgreSQL Flexible Server for production - zone-redundant high availability, automated backups, and private endpoint access only.
Railway Redis
Azure Cache for Redis
Azure Cache for Redis, sized independently of the application and reachable over a private endpoint inside your virtual network.
Message brokers
Azure Service Bus or a Helm chart
Deployed by Qovery as a service inside your environment.
Volume
A PersistentVolumeClaim, or object storage
A Railway volume is pinned to its service’s region and moving the service migrates the volume with downtime. A volume claim in your own cluster carries no such coupling, and durable blobs belong in object storage.
Variables and shared variables
Qovery variables and secrets
Scoped per project, environment and service, with aliases and overrides instead of one flat list.
Environments
Environments and deployment stages
Ordered stages with approval gates, promoting the same artifact.
PR environments
Preview environments
One per pull request, created on open and shut down when idle.
railway.json / railway.toml
Qovery service config and qovery/qovery Terraform
The agent reads your config-as-code to build the plan. What it writes out is standard Terraform and Kubernetes manifests in your own repository and account.
Railpack build
Dockerfile or Buildpacks
Both supported. The agent writes a Dockerfile if your repository does not have one.
Private networking and the Railway edge
Your own VPC, fronted by an Azure Load Balancer
You already own the virtual network. NSGs, private endpoints, peering and NAT gateway egress are yours, and Entra ID governs who can change any of it.