kimo
Docs

Install Kimo Bridge

Install kimo-bridge with Docker, Helm or the static binary, enroll it with a one-time token, and verify it with kimo-bridge doctor.

Updated Oct 9, 20267 min readEdit on GitHub

This page is the short reference. For a fully explained walkthrough with Compose, secrets and troubleshooting, follow the Docker guide or the Kubernetes guide.

Requirements

RequirementMinimum
HostLinux x86_64 or arm64, 1 vCPU, 1 GB RAM
RuntimeDocker Engine, Kubernetes 1.27+ with Helm 3.8+, or systemd
EgressTCP 443 to bridge.eu.getkimo.com or bridge.us.getkimo.com, plus DNS
DatabaseNetwork path from the host; a read replica is recommended
Inbound rulesNone

1. Create a read-only role

CREATE ROLE kimo_bridge LOGIN PASSWORD 'use-a-generated-secret';ALTER ROLE kimo_bridge SET default_transaction_read_only = on;ALTER ROLE kimo_bridge SET statement_timeout = '30s';GRANT USAGE ON SCHEMA analytics TO kimo_bridge;GRANT SELECT ON ALL TABLES IN SCHEMA analytics TO kimo_bridge;

2. Get an enrollment token

In the Bridge console, choose Add a bridge, name it after where it runs (for example fra-prod-01) and copy the token. Tokens start with kbt_, work once and expire after 24 hours.

3. Install

docker run -d --name kimo-bridge \  --restart unless-stopped --read-only --cap-drop ALL \  --security-opt no-new-privileges --user 10001:10001 \  -e KIMO_BRIDGE_TOKEN_FILE=/run/secrets/token \  -e KIMO_BRIDGE_CONFIG=/etc/kimo-bridge/kimo-bridge.yaml \  -v /opt/kimo-bridge/kimo-bridge.yaml:/etc/kimo-bridge/kimo-bridge.yaml:ro \  -v /opt/kimo-bridge/secrets:/run/secrets:ro \  -v kimo-bridge-data:/var/lib/kimo-bridge \  -p 127.0.0.1:8080:8080 \  ghcr.io/getkimo/bridge:1.4.2

4. Verify

Expected output
$ kimo-bridge doctorok  dns        bridge.eu.getkimo.com resolvedok  egress     443/tcp reachable (proxy: none)ok  identity   certificate valid, renews in 21hok  tunnel     connected, TLS 1.3, mutual authok  source     crm_pg postgres 16.4, role read-onlyok  policy     2 tables, 11 columns allowed, default deny

Then confirm the bridge shows Connected in the Bridge console. With Docker, prefix commands with docker exec kimo-bridge.

Day-two commands

CommandEffect
kimo-bridge reloadApplies policy changes without dropping the tunnel
kimo-bridge pause / resumeCloses the tunnel and cancels in-flight queries, then reconnects
kimo-bridge policy checkValidates kimo-bridge.yaml before a reload
kimo-bridge test-source <id> --sql "…"Runs a query locally through the full policy path
kimo-bridge doctor --bundleWrites a redacted diagnostics archive for support