Agent — Installation & Usage
blinex-agent is the single binary that runs on every device. It builds the WireGuard tunnels, runs Magic DNS, enforces access rules, and exposes a local status CLI.
Install
On Linux, one line installs the binary and a systemd service:
curl -fsSL https://get.blinex.co.uk | shOr take a pre-built binary from the releases page:
- Linux — amd64 and arm64. Kernel TUN, falling back to userspace netstack where
/dev/net/tunis unavailable, such as an unprivileged LXC container. - Windows — amd64. A real kernel interface via wintun, falling back to netstack if the adapter cannot be created (for example when not running elevated).
Windows service
From an elevated prompt, register the agent so it starts on boot and restarts if it crashes:
blinex-agent install ^
-setup-key BLINEX-DEFAULT-KEY ^
-management-url your-host:50051 ^
-signal-url your-host:10000 ^
-turn-user blinex -turn-pass your-relay-auth-passblinex-agent uninstall removes it. A crash is restarted automatically; a deliberate Stop-Service is honoured and reverts the DNS override first.
Unsigned binary
The Windows binary is not yet code-signed, and Defender has been observed removing it — an agent that creates a service, rewrites system DNS and binds a DNS port matches its heuristics closely. Add an exclusion until signing is in place.
Configuration
The agent reads /etc/blinex/agent.json on Linux, or %ProgramData%\blinex\agent.json on Windows. Flags and environment variables override it.
{
"management_url": "your-host:50051",
"signal_url": "your-host:10000",
"setup_key": "BLINEX-DEFAULT-KEY",
"stun_urls": ["stun:your-host:3478", "turn:your-host:3478?transport=udp"],
"turn_user": "blinex",
"turn_pass": "your-relay-auth-pass",
"tls_skip_verify": false
}Include a turn: URL
Without a turn: entry in stun_urls, ICE has no relay candidate, and a device behind a NAT that does not support hole-punching has no fallback for a direct path. It will still work over the signal relay, but it will never upgrade.
Flags
| Flag | Environment variable | Description |
|---|---|---|
-setup-key | BLINEX_SETUP_KEY | Enrollment key. |
-management-url | BLINEX_MANAGEMENT_URL | Management gRPC address, host:50051. |
-signal-url | BLINEX_SIGNAL_URL | Signal server address, host:10000. |
-turn-pass | BLINEX_TURN_PASS | TURN auth password for the relay. |
-dns-upstream | BLINEX_DNS_UPSTREAM | Upstream resolver for non-mesh queries. |
-tls-skip-verify | BLINEX_TLS_SKIP_VERIFY | Skip TLS verification, for a self-signed control plane. |
Status CLI
sudo blinex-agent status # enrollment, mesh IP, version
sudo blinex-agent peers # every peer, its .blinex name, and its data path
sudo blinex-agent routes # subnet routes in effectThe PATH column reads relay or direct. A peer stays on the relay until a direct path proves itself over repeated full-size probes, and drops back to relay with exponential backoff the moment one is missed — see Troubleshooting if a link is flapping.