BBline-X

Agent — Installation & Usage

blinex-agent is the single binary that runs on every device. It builds the WireGuard tunnels, runs Magic DNS, enforces access rules, and exposes a local status CLI.

Install

On Linux, one line installs the binary and a systemd service:

curl -fsSL https://get.blinex.co.uk | sh

Or take a pre-built binary from the releases page:

Windows service

From an elevated prompt, register the agent so it starts on boot and restarts if it crashes:

blinex-agent install ^
  -setup-key BLINEX-DEFAULT-KEY ^
  -management-url your-host:50051 ^
  -signal-url your-host:10000 ^
  -turn-user blinex -turn-pass your-relay-auth-pass

blinex-agent uninstall removes it. A crash is restarted automatically; a deliberate Stop-Service is honoured and reverts the DNS override first.

Unsigned binary

The Windows binary is not yet code-signed, and Defender has been observed removing it — an agent that creates a service, rewrites system DNS and binds a DNS port matches its heuristics closely. Add an exclusion until signing is in place.

Configuration

The agent reads /etc/blinex/agent.json on Linux, or %ProgramData%\blinex\agent.json on Windows. Flags and environment variables override it.

{
  "management_url": "your-host:50051",
  "signal_url": "your-host:10000",
  "setup_key": "BLINEX-DEFAULT-KEY",
  "stun_urls": ["stun:your-host:3478", "turn:your-host:3478?transport=udp"],
  "turn_user": "blinex",
  "turn_pass": "your-relay-auth-pass",
  "tls_skip_verify": false
}

Include a turn: URL

Without a turn: entry in stun_urls, ICE has no relay candidate, and a device behind a NAT that does not support hole-punching has no fallback for a direct path. It will still work over the signal relay, but it will never upgrade.

Flags

FlagEnvironment variableDescription
-setup-keyBLINEX_SETUP_KEYEnrollment key.
-management-urlBLINEX_MANAGEMENT_URLManagement gRPC address, host:50051.
-signal-urlBLINEX_SIGNAL_URLSignal server address, host:10000.
-turn-passBLINEX_TURN_PASSTURN auth password for the relay.
-dns-upstreamBLINEX_DNS_UPSTREAMUpstream resolver for non-mesh queries.
-tls-skip-verifyBLINEX_TLS_SKIP_VERIFYSkip TLS verification, for a self-signed control plane.

Status CLI

bash
sudo blinex-agent status   # enrollment, mesh IP, version
sudo blinex-agent peers    # every peer, its .blinex name, and its data path
sudo blinex-agent routes   # subnet routes in effect

The PATH column reads relay or direct. A peer stays on the relay until a direct path proves itself over repeated full-size probes, and drops back to relay with exponential backoff the moment one is missed — see Troubleshooting if a link is flapping.