Configuration

A single bridge.toml (or YAML) file describes the node, the proxy, and the fleet.

Config discovery

The daemon looks for its configuration in this order:

  1. ./bridge.toml: the current working directory
  2. $BRIDGE_CONFIG: path from the environment variable
  3. /etc/bridge/bridge.toml: the system location the installer uses

You can always override discovery with bridge --config /path/to/bridge.toml. Both TOML and YAML are accepted. Omitting the [node] section runs the daemon in standalone mode (no mesh, no election).

Full reference

enable_telemetry = false

[proxy]
mode = "Direct"            # Direct | SniPassthrough | Managed
listeners = ["http"]
http_addr = "0.0.0.0:80"

[dashboard]
enabled = true
listen_addr = "127.0.0.1:9090"

[discovery]
enabled = true
docker_socket = "/var/run/docker.sock"
default_node_id = "node-01"

[ipc]
enabled = true
socket_path = "/tmp/bridge.sock"

[logger]
level = "INFO"
format = "text"

# This node's cluster identity (optional, omit for standalone)
[node]
id = "node-01"
mesh_ip = "10.8.0.1"
endpoint = "203.0.113.10:51820"
listen_port = 51820
priority = 100

[[seeds]]
endpoint = "203.0.113.11:51820"

[[nodes]]
node_id = "node-01"
endpoint = "203.0.113.10:51820"

[[services]]
url = "https://app.example.com"
node_id = "node-01"
upstream = "127.0.0.1:3000"

[handoff]
mode = "tunnel"            # none | dns | tunnel | floating_ip

[handoff.tunnel]
# Cloudflare Tunnel credentials go here when mode = "tunnel"

Sections

Top level

KeyTypeDescription
enable_telemetrybooleanOpt-in telemetry. Disabled by default.

[proxy]

KeyTypeDescription
modestringDirect (L7 HTTP reverse proxy per hostname), SniPassthrough (L4, TLS terminates on backends), or Managed (delegate to an existing Coolify install).
listenersarrayListener kinds to enable, e.g. ["http"].
http_addrstringBind address for HTTP ingress, e.g. 0.0.0.0:80.

[dashboard]

KeyTypeDescription
enabledbooleanServe the embedded operations dashboard.
listen_addrstringDefault 127.0.0.1:9090: loopback only unless changed.

[discovery]

KeyTypeDescription
enabledbooleanWatch Docker for labeled containers and turn them into routes automatically.
docker_socketstringPath to the Docker socket, e.g. /var/run/docker.sock.
default_node_idstringNode id assigned to discovered routes on this host.

[ipc]

KeyTypeDescription
enabledbooleanServe the IPC socket the bridge CLI talks to.
socket_pathstringDefault /tmp/bridge.sock.

[logger]

KeyTypeDescription
levelstringLog level, e.g. INFO.
formatstringOutput format, e.g. text.

[node]

Cluster identity for this node. Omit the whole section for standalone mode.

KeyTypeDescription
idstringUnique node identifier, e.g. node-01.
mesh_ipstringThis node's address on the WireGuard overlay, e.g. 10.8.0.1.
endpointstringPublic address peers dial, host:port.
listen_portnumberWireGuard listen port, e.g. 51820. Keys are auto-generated if not configured.
prioritynumberBully election priority: higher wins leadership among alive nodes.

[[seeds]]

KeyTypeDescription
endpointstringA peer endpoint gossip contacts first to join the fleet. Repeat the table for multiple seeds.

[[nodes]]

KeyTypeDescription
node_idstringIdentifier of a known fleet member.
endpointstringIts public host:port endpoint.

[[services]]

Static routes. Repeat the table per service; discovered containers add routes alongside these.

KeyTypeDescription
urlstringPublic URL of the service, e.g. https://app.example.com.
node_idstringNode hosting the upstream.
upstreamstringBackend address, e.g. 127.0.0.1:3000. Multiple targets across entries are spread by consistent-hash routing with session affinity.

[services.replicate]

Optional per-service failover duplication: when the hosting node fails, the workload is spawned on a peer via the container driver.

KeyTypeDescription
enabledbooleanTurn on failover duplication for this service.
imagestringContainer image spawned on the peer node.
envtableEnvironment variables passed to the spawned container.
container_portnumberPort the container exposes.
placementstringPlacement rule selecting which peers may host the replica.
failback_modestringmanual or automatic return of the workload once the original node recovers.
failback_cooldown_secsnumberMinimum time before failback runs, preventing flapping.

[handoff]

KeyTypeDescription
modestringIngress handoff tier: none, dns, tunnel, or floating_ip. See handoff tiers.

[handoff.tunnel]

Holds the Cloudflare Tunnel credentials used when mode = "tunnel". The elected leader brings the tunnel up; on re-election the new leader takes it over.

[handoff.dns]

Holds the DNS provider configuration used when mode = "dns": the provider credentials and record BRIDGE updates for health-checked DNS failover.

[sentry]

Optional error reporting.

KeyTypeDescription
dsnstringSentry DSN.
environmentstringEnvironment tag attached to events, e.g. production.
sample_ratenumberFraction of error events sent (0.0–1.0).
traces_sample_ratenumberFraction of traces sent (0.0–1.0).
debugbooleanVerbose Sentry SDK logging.
Environment variable: BRIDGE_CONFIG points the daemon at a config file anywhere on disk and takes precedence over the system path. The installer never overwrites an existing /etc/bridge/bridge.toml.