Install BRIDGE
One command per node. The installer detects your platform, verifies the download, and sets up the daemon as a systemd service.
Quick install
Run this on every node you want in the fleet. The installer re-executes itself
through sudo when it needs root for system paths. As with any
piped installer, review the script first: it is plain POSIX shell, published
in the GitHub repository.
What the installer does
- Detects your OS and CPU architecture and maps them to a release target triple.
- Resolves the release version (the latest GitHub release, unless pinned).
- Downloads the release tarball and the published
sha256sums.txtinto a temporary directory. - Verifies the SHA-256 checksum of the tarball: an unverified binary is never installed.
- Installs the
bridgebinary to/usr/local/bin(mode 0755). - On Linux with root: creates a
bridgesystem user, creates/etc/bridge(0750, root:bridge), and writes a minimal standalonebridge.toml, only if none exists. Your existing config is never overwritten. - On systemd systems: writes
/etc/systemd/system/bridge.service, runsdaemon-reload, and enables and starts the service. - Prints a summary with the install location, config path, and next steps.
Requirements
- Linux on x86_64 or aarch64 for a full service install (macOS x86_64/aarch64 binaries are installed for manual runs).
- systemd is optional: without it, the installer prints how to run the daemon manually.
- Root (or sudo) for installing to system paths, creating the service user, binding ports 80/443, and configuring WireGuard. The systemd unit grants
CAP_NET_BIND_SERVICEandCAP_NET_ADMINso the daemon does not run as full root. curlandtaravailable on the host.
Installer environment variables
| Variable | Default | Purpose |
|---|---|---|
BRIDGE_REPO | bridgemesh/bridge | GitHub repository to download releases from. |
BRIDGE_VERSION | latest | Release tag to install; latest queries the GitHub API. |
INSTALL_DIR | /usr/local/bin | Directory the bridge binary is installed into. |
Manual install
If you prefer not to run the script, install from a GitHub release by hand:
# 1. Download the tarball and checksums for your platform
curl -fsSLO https://github.com/bridgemesh/bridge/releases/download/<version>/bridge-<version>-x86_64-unknown-linux-gnu.tar.gz
curl -fsSLO https://github.com/bridgemesh/bridge/releases/download/<version>/sha256sums.txt
# 2. Verify the checksum (use: shasum -a 256 -c on macOS)
grep x86_64-unknown-linux-gnu.tar.gz sha256sums.txt | sha256sum -c -
# 3. Extract and install the binary
tar -xzf bridge-<version>-x86_64-unknown-linux-gnu.tar.gz
sudo cp bridge /usr/local/bin/bridge
sudo chmod 0755 /usr/local/bin/bridge
Then create a minimal configuration at /etc/bridge/bridge.toml:
enable_telemetry = false
[proxy]
mode = "Direct"
listeners = ["http"]
http_addr = "0.0.0.0:80"
[dashboard]
enabled = true
listen_addr = "127.0.0.1:9090"
[logger]
level = "INFO"
format = "text"
And start the daemon:
bridge --config /etc/bridge/bridge.toml
Verify it works
Check the daemon over its IPC socket:
bridge status
Then open the embedded operations dashboard at http://127.0.0.1:9090.
The dashboard binds to loopback by default, so it is only reachable from the node
itself unless you change listen_addr.