A single bridge.toml (or YAML) file describes the node, the proxy, and the fleet.
Config discovery
The daemon looks for its configuration in this order:
./bridge.toml: the current working directory
$BRIDGE_CONFIG: path from the environment variable
/etc/bridge/bridge.toml: the system location the installer uses
You can always override discovery with bridge --config /path/to/bridge.toml.
Both TOML and YAML are accepted. Omitting the [node] section runs the
daemon in standalone mode (no mesh, no election).
Direct (L7 HTTP reverse proxy per hostname), SniPassthrough (L4, TLS terminates on backends), or Managed (delegate to an existing Coolify install).
listeners
array
Listener kinds to enable, e.g. ["http"].
http_addr
string
Bind address for HTTP ingress, e.g. 0.0.0.0:80.
[dashboard]
Key
Type
Description
enabled
boolean
Serve the embedded operations dashboard.
listen_addr
string
Default 127.0.0.1:9090: loopback only unless changed.
[discovery]
Key
Type
Description
enabled
boolean
Watch Docker for labeled containers and turn them into routes automatically.
docker_socket
string
Path to the Docker socket, e.g. /var/run/docker.sock.
default_node_id
string
Node id assigned to discovered routes on this host.
[ipc]
Key
Type
Description
enabled
boolean
Serve the IPC socket the bridge CLI talks to.
socket_path
string
Default /tmp/bridge.sock.
[logger]
Key
Type
Description
level
string
Log level, e.g. INFO.
format
string
Output format, e.g. text.
[node]
Cluster identity for this node. Omit the whole section for standalone mode.
Key
Type
Description
id
string
Unique node identifier, e.g. node-01.
mesh_ip
string
This node's address on the WireGuard overlay, e.g. 10.8.0.1.
endpoint
string
Public address peers dial, host:port.
listen_port
number
WireGuard listen port, e.g. 51820. Keys are auto-generated if not configured.
priority
number
Bully election priority: higher wins leadership among alive nodes.
[[seeds]]
Key
Type
Description
endpoint
string
A peer endpoint gossip contacts first to join the fleet. Repeat the table for multiple seeds.
[[nodes]]
Key
Type
Description
node_id
string
Identifier of a known fleet member.
endpoint
string
Its public host:port endpoint.
[[services]]
Static routes. Repeat the table per service; discovered containers add routes alongside these.
Key
Type
Description
url
string
Public URL of the service, e.g. https://app.example.com.
node_id
string
Node hosting the upstream.
upstream
string
Backend address, e.g. 127.0.0.1:3000. Multiple targets across entries are spread by consistent-hash routing with session affinity.
[services.replicate]
Optional per-service failover duplication: when the hosting node fails, the
workload is spawned on a peer via the container driver.
Key
Type
Description
enabled
boolean
Turn on failover duplication for this service.
image
string
Container image spawned on the peer node.
env
table
Environment variables passed to the spawned container.
container_port
number
Port the container exposes.
placement
string
Placement rule selecting which peers may host the replica.
failback_mode
string
manual or automatic return of the workload once the original node recovers.
failback_cooldown_secs
number
Minimum time before failback runs, preventing flapping.
[handoff]
Key
Type
Description
mode
string
Ingress handoff tier: none, dns, tunnel, or floating_ip. See handoff tiers.
[handoff.tunnel]
Holds the Cloudflare Tunnel credentials used when mode = "tunnel".
The elected leader brings the tunnel up; on re-election the new leader takes it over.
[handoff.dns]
Holds the DNS provider configuration used when mode = "dns": the
provider credentials and record BRIDGE updates for health-checked DNS failover.
[sentry]
Optional error reporting.
Key
Type
Description
dsn
string
Sentry DSN.
environment
string
Environment tag attached to events, e.g. production.
sample_rate
number
Fraction of error events sent (0.0–1.0).
traces_sample_rate
number
Fraction of traces sent (0.0–1.0).
debug
boolean
Verbose Sentry SDK logging.
Environment variable:BRIDGE_CONFIG points the daemon at
a config file anywhere on disk and takes precedence over the system path. The
installer never overwrites an existing /etc/bridge/bridge.toml.