Your network, fully connected
Bline-X is an open-source WireGuard mesh VPN. Connect every server, laptop, and container into one private network that works behind any NAT — with Magic DNS, group-based access control, and a web dashboard.
$ curl -fsSL https://get.blinex.co.uk | sh
installing blinex-agent... done
$ sudo blinex-agent -setup-key BLINEX-DEFAULT-KEY
Connected to mesh as server-1 (100.64.0.1)
$ ping server-2.blinex
64 bytes from 100.64.0.2: icmp_seq=1 ttl=64 time=2.1 ms
64 bytes from 100.64.0.2: icmp_seq=2 ttl=64 time=1.9 msEverything you need for a private mesh
A complete, self-hostable alternative to commercial mesh VPNs — no per-seat pricing, no vendor lock-in.
WireGuard Encryption
Every byte between peers is encrypted end-to-end with WireGuard's modern Noise-protocol crypto. Keys never leave the device — the control plane only ever sees ciphertext.
Works Behind Any NAT
WireGuard traffic is relayed through the signal server by default, so there is no port forwarding to configure. When a direct path proves it can carry traffic, Bline-X upgrades to peer-to-peer automatically.
Magic DNS, automatic
Reach any peer by name. Every device gets a stable .blinex hostname, and the agent points the OS at its own resolver on startup — no /etc/hosts, no manual DNS configuration.
Group-Based Access Control
Place peers into groups and write allow rules between them. Deny-by-default: with no rules, nothing talks, so access is something you grant rather than something you remember to revoke.
Malicious-Domain Filtering
On by default. The control plane compiles a public threat-intel feed and serves it to every agent, whose resolver answers known malware and C2 domains with NXDOMAIN before they resolve.
Subnet Routes & Exit Nodes
Advertise a LAN to the mesh so peers can reach machines that never join it, or route a device’s internet traffic through another peer. Exit nodes are opt-in per device.
How it works
From zero to a working mesh in three steps.
Deploy the control plane
Bring up management, signal, and relay with a single docker compose command. Postgres-backed, or in-memory for a quick spin-up.
git clone https://github.com/DJR-FP/blinex
cd blinex
docker compose up -dInstall the agent
Run the install script on every machine you want on the mesh. It drops the blinex-agent binary and a service definition into place.
curl -fsSL https://get.blinex.co.uk | shJoin the mesh
Enroll with a setup key. The agent registers with management, builds its WireGuard tunnels, and is immediately reachable by every other peer.
sudo blinex-agent -setup-key BLINEX-DEFAULT-KEY