Install Kimo Bridge
Install kimo-bridge with Docker, Helm or the static binary, enroll it with a one-time token, and verify it with kimo-bridge doctor.
Updated Oct 9, 20267 min readEdit on GitHub
This page is the short reference. For a fully explained walkthrough with Compose, secrets and troubleshooting, follow the Docker guide or the Kubernetes guide.
Requirements
| Requirement | Minimum |
|---|---|
| Host | Linux x86_64 or arm64, 1 vCPU, 1 GB RAM |
| Runtime | Docker Engine, Kubernetes 1.27+ with Helm 3.8+, or systemd |
| Egress | TCP 443 to bridge.eu.getkimo.com or bridge.us.getkimo.com, plus DNS |
| Database | Network path from the host; a read replica is recommended |
| Inbound rules | None |
1. Create a read-only role
PostgreSQL, as an administrator
CREATE ROLE kimo_bridge LOGIN PASSWORD 'use-a-generated-secret';ALTER ROLE kimo_bridge SET default_transaction_read_only = on;ALTER ROLE kimo_bridge SET statement_timeout = '30s';GRANT USAGE ON SCHEMA analytics TO kimo_bridge;GRANT SELECT ON ALL TABLES IN SCHEMA analytics TO kimo_bridge;2. Get an enrollment token
In the Bridge console, choose Add a bridge, name it after where it runs (for example fra-prod-01) and copy the token. Tokens start with kbt_, work once and expire after 24 hours.
3. Install
docker run -d --name kimo-bridge \ --restart unless-stopped --read-only --cap-drop ALL \ --security-opt no-new-privileges --user 10001:10001 \ -e KIMO_BRIDGE_TOKEN_FILE=/run/secrets/token \ -e KIMO_BRIDGE_CONFIG=/etc/kimo-bridge/kimo-bridge.yaml \ -v /opt/kimo-bridge/kimo-bridge.yaml:/etc/kimo-bridge/kimo-bridge.yaml:ro \ -v /opt/kimo-bridge/secrets:/run/secrets:ro \ -v kimo-bridge-data:/var/lib/kimo-bridge \ -p 127.0.0.1:8080:8080 \ ghcr.io/getkimo/bridge:1.4.24. Verify
Expected output
$ kimo-bridge doctorok dns bridge.eu.getkimo.com resolvedok egress 443/tcp reachable (proxy: none)ok identity certificate valid, renews in 21hok tunnel connected, TLS 1.3, mutual authok source crm_pg postgres 16.4, role read-onlyok policy 2 tables, 11 columns allowed, default denyThen confirm the bridge shows Connected in the Bridge console. With Docker, prefix commands with docker exec kimo-bridge.
Day-two commands
| Command | Effect |
|---|---|
kimo-bridge reload | Applies policy changes without dropping the tunnel |
kimo-bridge pause / resume | Closes the tunnel and cancels in-flight queries, then reconnects |
kimo-bridge policy check | Validates kimo-bridge.yaml before a reload |
kimo-bridge test-source <id> --sql "…" | Runs a query locally through the full policy path |
kimo-bridge doctor --bundle | Writes a redacted diagnostics archive for support |
