BBline-X

Subnet Routes & Exit Nodes

A peer can advertise a network it can reach, so the rest of the mesh reaches it too — a LAN full of machines that will never run an agent, or the whole internet.

Subnet routes

Advertise a CIDR from the peer that sits on it. Other peers install a route for it and reach those addresses through the mesh.

curl -sk -X PUT https://your-host:8080/api/v1/peers/$KEY/routes \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{"routes":["192.168.1.0/24"]}'

The advertising peer enables IP forwarding and NAT for mesh-sourced traffic. Access is still governed by your ACLs, and replies come back without needing a rule of their own.

Exit nodes

A peer advertising 0.0.0.0/0 offers itself as an exit node. It does not impose one: choosing to use it is a decision each device makes.

# offer: this peer is willing to be an exit node
curl -sk -X PUT https://your-host:8080/api/v1/peers/$GATEWAY/routes \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{"routes":["0.0.0.0/0"]}'

# opt in: this one device routes its internet traffic through it
curl -sk -X PUT https://your-host:8080/api/v1/peers/$DEVICE/exit-node \
  -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' \
  -d '{"exit_node":"'"$GATEWAY"'"}'

A consuming device installs 0.0.0.0/1 and 128.0.0.0/1 — two halves that together cover everything while leaving the real default route in place — and pins host routes for the control plane so the tunnel cannot swallow its own connection. Clear the selection with {"exit_node":""}.

A selection is validated, not trusted

If the chosen gateway disappears or stops advertising 0.0.0.0/0, the device falls back to no exit node. Sending a machine’s entire default route to a gateway that is not offering one is a worse failure than not using an exit node at all.

Platform support

Every platform can use subnet routes and exit nodes. Serving as one requires Linux: Windows needs the WinNAT component, which is absent from a stock Windows installation without the Hyper-V or Containers feature.