Quickstart
Stand up the control plane and join your first two peers.
1. Deploy the control plane
Three services run server-side, plus Postgres:
management— gRPC:50051and HTTPS:8080(peers, groups, ACLs, setup keys)signal—:10000, ICE signaling and the always-on packet relayrelay— STUN/TURN on:3478for direct-path discoverydashboard— the web UI on:3000
git clone https://github.com/DJR-FP/blinex
cd blinex
docker compose up -d2. Install the agent
Run this on every machine that should join the mesh:
curl -fsSL https://get.blinex.co.uk | sh3. Enroll with a setup key
A default key, BLINEX-DEFAULT-KEY, is seeded at startup and valid for a year. Create real keys on the Setup Keys page before production.
sudo blinex-agent -setup-key BLINEX-DEFAULT-KEYThe agent registers, receives a stable 100.64.0.0/10 address, and builds tunnels to every other peer.
4. Check it works
$ sudo blinex-agent status
$ sudo blinex-agent peers
HOSTNAME MESH IP DNS PATH
server-2 100.64.0.2 server-2.blinex relay
$ ping server-2.blinexThe PATH column shows relay or direct. Peers start on the relay and upgrade to a direct path only once repeated full-size probes prove it carries traffic, so a marginal NAT binding never black-holes your data.
Next steps
Point your devices at each other by name with Magic DNS, restrict who can reach what with Access Control Lists, or reach machines that never join the mesh with subnet routes.