BBline-X
v0.22.0

Your network, fully connected

Bline-X is an open-source WireGuard mesh VPN. Connect every server, laptop, and container into one private network that works behind any NAT — with Magic DNS, group-based access control, and a web dashboard.

server-1 — bash
$ curl -fsSL https://get.blinex.co.uk | sh
installing blinex-agent... done

$ sudo blinex-agent -setup-key BLINEX-DEFAULT-KEY
Connected to mesh as server-1 (100.64.0.1)

$ ping server-2.blinex
64 bytes from 100.64.0.2: icmp_seq=1 ttl=64 time=2.1 ms
64 bytes from 100.64.0.2: icmp_seq=2 ttl=64 time=1.9 ms

Everything you need for a private mesh

A complete, self-hostable alternative to commercial mesh VPNs — no per-seat pricing, no vendor lock-in.

WireGuard Encryption

Every byte between peers is encrypted end-to-end with WireGuard's modern Noise-protocol crypto. Keys never leave the device — the control plane only ever sees ciphertext.

Works Behind Any NAT

WireGuard traffic is relayed through the signal server by default, so there is no port forwarding to configure. When a direct path proves it can carry traffic, Bline-X upgrades to peer-to-peer automatically.

Magic DNS, automatic

Reach any peer by name. Every device gets a stable .blinex hostname, and the agent points the OS at its own resolver on startup — no /etc/hosts, no manual DNS configuration.

Group-Based Access Control

Place peers into groups and write allow rules between them. Deny-by-default: with no rules, nothing talks, so access is something you grant rather than something you remember to revoke.

Malicious-Domain Filtering

On by default. The control plane compiles a public threat-intel feed and serves it to every agent, whose resolver answers known malware and C2 domains with NXDOMAIN before they resolve.

Subnet Routes & Exit Nodes

Advertise a LAN to the mesh so peers can reach machines that never join it, or route a device’s internet traffic through another peer. Exit nodes are opt-in per device.

How it works

From zero to a working mesh in three steps.

1

Deploy the control plane

Bring up management, signal, and relay with a single docker compose command. Postgres-backed, or in-memory for a quick spin-up.

git clone https://github.com/DJR-FP/blinex
cd blinex
docker compose up -d
2

Install the agent

Run the install script on every machine you want on the mesh. It drops the blinex-agent binary and a service definition into place.

curl -fsSL https://get.blinex.co.uk | sh
3

Join the mesh

Enroll with a setup key. The agent registers with management, builds its WireGuard tunnels, and is immediately reachable by every other peer.

sudo blinex-agent -setup-key BLINEX-DEFAULT-KEY