bm tunnel CLI reference
bm is Fixedmark's planned command-line tool. bm tunnel forwards local ports to IP-restricted databases and TCP services through your static IPs, for drivers that have no proxy support.
Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.
Status
bm ships as a single static Go binary, so it runs in slim containers and on PaaS build images without extra libraries.
Port-forward mode
The core command maps a local port to a remote host and port:
bm tunnel LOCAL_PORT:REMOTE_HOST:REMOTE_PORT| Part | Example | Meaning |
|---|---|---|
| `LOCAL_PORT` | 5432 | Port the CLI listens on, on 127.0.0.1. Your driver connects here. |
| `REMOTE_HOST` | db.example.com | The database host. The proxy resolves this name in its region. |
| `REMOTE_PORT` | 5432 | The database port. The connection leaves from one of your static IPs. |
# Postgres
bm tunnel 5432:db.example.com:5432
# MySQL
bm tunnel 3306:mysql.example.com:3306
# SSH
bm tunnel 2222:server.example.com:22Each connection to the local port opens one new connection through the proxy. TLS between your driver and the database runs inside it. Because the driver connects to 127.0.0.1, tell it the real server name for certificate checks. The databases guide shows how for each driver.
Transparent mode
Transparent mode is planned for apps that should keep their existing connection strings, with real host names instead of 127.0.0.1. Its interface and how it captures connections are not final. Until it ships, use port-forward mode or SOCKS5.
Config file
bm reads a local config file. The planned contents are your app credentials, the region endpoint, and the tunnels to open. Because the file holds everything, startup does not depend on any Fixedmark API. Some tunnel tools fetch their config from the vendor's API at boot, so an API outage stops the app from starting. bm avoids that.
Treat the file as a secret. It contains your token. Keep it out of source control and mount it from your platform's secret store. The file name and format will be documented at launch.
Running beside your app
The tunnel must run for as long as your app does. On platforms with a single start command, start it in the background first:
# Procfile or start command (illustrative)
web: bm tunnel 5432:db.example.com:5432 & node server.js- Your app may start before the tunnel listens. Retry the first database connection, which most pools do already.
- Serverless functions cannot run a background process. Use SOCKS5 there instead.
- In CI, start the tunnel in one step and run migrations in the next.
bm logs
The build plan also lists bm logs --tail for following connection logs from the terminal: destination, SNI, bytes, egress IP, and result. It is planned alongside the dashboard's live log view.
How it connects
The CLI is planned to reach the proxy over SOCKS5 wrapped in TLS on a separate port, so your token is never sent in clear text. The proxy then connects to the remote host from your static IP, after checking your token's destination allowlist. See limits and security.
Platform guides
Frequently asked questions
Is bm tunnel available now?
No. bm tunnel is planned for the public launch. This page describes the planned behavior. Flags, file names, and the config format may change before release.
Does bm tunnel call a Fixedmark API when it starts?
No. It is planned to read everything it needs from a local config file, so your app can start even if the Fixedmark control plane is unreachable.
Is traffic through bm tunnel encrypted?
The hop from the CLI to the proxy is planned to use SOCKS5 over TLS, so your token is not sent in clear text. Your database's own TLS also runs end to end inside the tunnel.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.