Systems architecture & ingress

Distributed. Self-aware. Fault-tolerant ingress for dynamic cloud infrastructure.

BRIDGE is infrastructure software: a single Rust binary daemon that runs on each VPS node and turns a scattered fleet, across cloud providers, into one encrypted, self-healing system with a single ingress point.

curl -fsSL https://bridgemesh.space/install.sh | sh

Why BRIDGE exists

Running a cluster as one.

Distributed fleets fail in a specific way: every application can be running while the system as a whole is down. One node holds the ingress entrypoint: the public IP, the DNS record, the tunnel. When that node dies, or a workload moves to another host, the entry boundary goes stale and every backend becomes unreachable. The infrastructure changed; the configuration did not.

Manual reconfiguration cannot keep up with that rate of change. Rewiring DNS, upstream targets, and tunnels by hand after every deploy and every failure doesn't prevent downtime: it schedules it. The entrypoint is a single point of failure, and the human in the loop is the latency.

BRIDGE closes that gap. Nodes form an encrypted WireGuard mesh, track each other's health over gossip, elect a leader to hold the ingress entrypoint, and reroute around failure automatically, moving the entrypoint itself when the leader dies. The fleet behaves like one system because, to BRIDGE, it is one system.

Capabilities

Everything the fleet needs, in one binary

Networking

WireGuard L3 mesh

Nodes form an encrypted overlay network (e.g. 10.8.0.x). Keys are auto-generated if not configured.

Membership

SWIM gossip

Nodes discover and health-track each other (Alive → Suspected → Dead → Recovered), converging in seconds.

Consensus

Leader election

Bully algorithm with configurable priorities. One leader holds the ingress entrypoint for the fleet.

Ingress

Three proxy modes

L7 Direct HTTP reverse proxy per hostname, L4 SNI passthrough, or Managed delegation to an existing Coolify install.

Failover

Ingress handoff tiers

None, health-checked DNS failover, Cloudflare Tunnel held by the leader, or a Floating IP: pick per deployment.

Routing

Route management

Static routes from config plus Docker auto-discovery of labeled containers. Consistent-hash routing with session affinity.

Resilience

Failover duplication

Workloads can be replicated to peer nodes on failure, with manual or automatic failback and cooldowns.

Operations

Dashboard & CLI

Embedded ops console on 127.0.0.1:9090, WebSocket real-time events, JSON API, and a CLI over a Unix socket.

Architecture

A daemon on every node, a leader at the edge

Every node runs the same BRIDGE daemon. Gossip keeps membership current; the bully algorithm keeps exactly one leader. If the leader dies, the fleet re-elects and the tunnel or DNS entrypoint moves with it.

How it works

Three steps to a fleet

Install the daemon on each node

One command per VPS installs the binary, a dedicated user, and a systemd unit.

Nodes form the mesh and elect a leader

WireGuard links come up, gossip membership converges in seconds, and the highest-priority alive node takes the ingress.

Point DNS or the tunnel at the fleet

The leader terminates ingress and routes to any node over the mesh. Failure triggers re-election and handoff, not downtime.