Linux VM: DEB or RPM
Start your first server on Ubuntu/Debian or RHEL/Rocky/AlmaLinux.
Installation guide →Install
Install the LinkMesh Server on any Linux VM in a single command. The.deb / .rpm postinstall generates the JWT secret, initializes the GitOps config repo, and seeds the default admin account, then starts the systemd service. It serves plain HTTP on port 8080 — put a reverse proxy in front to terminate TLS. Open the web UI and enroll your first Collector.
Full step-by-step server walkthrough, including the UI: Quickstart in the docs →
Start your first server on Ubuntu/Debian or RHEL/Rocky/AlmaLinux.
Installation guide →Install and update through your system package manager.
Installation guide →Run the server in a container and persist the entire /data directory.
Installation guide →Connect a Helm-managed or DaemonSet collector fleet to your server.
Installation guide →Download server and agent packages →
Your collector appears in the fleet with current status and a recent “Last seen”. Allow roughly 30 seconds for OpAMP or one polling cycle for Alloy (60 seconds by default). The Events tab shows registration followed by configuration delivery.
Next connect a source, route and destination, send a test event, and confirm it arrives at the destination. A Debug destination works for the first local test without a cloud account. Test the data flow →
Check the server address, DNS, TLS certificate and connectivity. Use the token for your selected management protocol.
Troubleshooting guide →Compare the runtime version with the compatibility matrix and inspect collector logs for rejected components.
Troubleshooting guide →Check externalUrl and collector self-telemetry. A connected management channel alone does not prove data delivery.
Troubleshooting guide →Validated versions reported by the product documentation. This does not mean every newer release has been tested.
| Runtime | Minimum supported | Validated version | Configuration | Setup guide |
|---|---|---|---|---|
| otelcol-contrib | 0.151.0 | 0.153.0 | OpAMP + opampsupervisor | Connect collector |
| Grafana Alloy | 1.13.0 | 1.13.2 | remotecfg | Connect collector |
Reviewed on . Current support matrix in maintained documentation.
The documentation sets no upper version limit. Validate newer releases against your configuration before rollout. Below the minimum, missing components can cause the entire configuration to be rejected.
How it fits together
You install one thing: the Server (the .deb / .rpm below). Each OpenTelemetry Collector then enrolls with it over a single HTTPS connection on port 443 — otelcol-contrib via OpAMP, Grafana Alloy via remotecfg — authenticating with a bearer token. Alloy pulls its config; the OpAMP supervisor receives config pushes and manages the collector process; your telemetry never flows through LinkMesh — it goes straight from the collector to your own backends. Optionally, the LinkMesh agent runs alongside as an edge connector for guided onboarding and service/log discovery — it carries no telemetry and doesn't run your collector. See Trust for the data-handling specifics, and Architecture on docs for the component topology in depth.
Quickstart — Linux
Pick the line that matches your distro and paste it on a fresh Linux VM. That's the whole install — the postinstall generates the JWT secret, initializes the GitOps config repo, and seeds the admin account, then starts the systemd service.
curl -fsSL https://artifacts.saas.opensight.ch/binaries/linkmesh-server/latest/linkmesh-server_latest_amd64.deb -o linkmesh-server.deb && sudo apt install -y ./linkmesh-server.debcurl -fsSL https://artifacts.saas.opensight.ch/binaries/linkmesh-server/latest/linkmesh-server-latest.x86_64.rpm -o linkmesh-server.rpm && sudo dnf install -y ./linkmesh-server.rpmThe install creates an admin account with a random password that is deliberately never written to any log. Set your own with the recovery command — it talks to the local server, so no prior login is needed:
sudo linkmesh-server reset-password --email admin --password 'choose-a-strong-password'Then open http://YOUR_HOST:8080 and sign in as admin. Omit--password to have a strong one generated and printed instead.
Collectors on Kubernetes, or auto-updates from APT/YUM?
The server itself is the Linux VM (or Docker) install above — there is no Helm chart for the control plane yet. If your collectors run on Kubernetes, the collector fleet guide covers Grafana Alloy via Helm and otelcol as a DaemonSet. For auto-updates of the server via your system package manager, see Install from APT or YUM.
Windows hosts work the same way
The Server itself is Linux-only, but collectors enroll from any OS. Windows hosts run otelcol-contrib (OpAMP) or Grafana Alloy (remotecfg) and connect over the same port-443 bearer-token handshake; the optional LinkMesh agent ships a Windows AMD64 binary too. After your Linux server is up, follow Add a Collector on docs for the platform-specific enrollment commands.
Enroll your collectors
LinkMesh manages supported upstream collector versions. Point otelcol-contrib at LinkMesh with the upstream opampsupervisor (OpAMP), or add a remotecfg block to Grafana Alloy. These are distinct remote-management protocols; both authenticate with a bearer token over port 443 and leave the data plane (OTLP) untouched. Use the enrollment token for OpAMP or the per-collector bearer token for Alloy. Follow the runtime-specific guide and verify the first connection.
otelcol-contrib · OpAMP
The one-liner fetches both upstream binaries (collector + supervisor), writes the supervisor config, and starts the systemd unit. Swap in your own server's address if you're self-hosting.
curl -fsSL https://linkmesh.example.com/install-opamp.sh | \
sudo sh -s -- --token YOUR_TOKENThe supervisor opens a WebSocket to /v1/opamp, receives the config LinkMesh pushes, and writes it to the collector subprocess — you don't author the collector's config.yaml by hand. Full walkthrough: Onboard otelcol-contrib via OpAMP →
Grafana Alloy · remotecfg
Alloy speaks its native remotecfg protocol — HTTP polling rather than OpAMP push. Add one block to your existing Alloy config, point it at the LinkMesh base URL, and authenticate with a per-collector bearer token minted from the collector detail page.
remotecfg {
url = "https://linkmesh.example.com"
id = constants.hostname
poll_frequency = "60s"
bearer_token = env("LINKMESH_TOKEN")
}Alloy reloads its pipelines automatically when the remote config changes — no service restart needed. Full walkthrough: Onboard Grafana Alloy via remotecfg →
Optional: add the onboarding agent
The LinkMesh agent is an optional edge connector — install it on a host (or as a Kubernetes DaemonSet) and it auto-detects running services, discovers log sources, and rolls up cluster workloads to make onboarding faster. It carries no telemetry and does not run your collector; your collector still manages itself over OpAMP or remotecfg. Grab it from Downloads.
Episode 1 · 5:47
A real walkthrough on two fresh VMs — from a blank machine to a collector reporting into LinkMesh.
Everything beyond the one-liner — UI walkthrough, enrollment tokens, reverse-proxy setup, certificate lifecycle, collector enrollment commands, and troubleshooting — lives in the operator docs. Single source of truth, kept current with each release.
Quickstart
First Collector in 10 minutes
UI walkthrough from blank install to a live route with throughput. With inline screenshots. →
Collector fleet on Kubernetes
Grafana Alloy Helm + otelcol DaemonSet
Enroll collectors on the cluster. The server itself is the Linux VM / Docker install above. →
Enroll a Collector
otelcol via OpAMP, or Alloy via remotecfg
Both enrollment paths with the actual one-liner commands and token lifecycle. →
Reverse proxy
nginx / Caddy / HAProxy
HTTPS termination for the API, UI, OpAMP/remotecfg enrollment, and OTLP — all on port 443. Annotated config. →
Reference
Configuration schema
All config.yaml keys, CLI flags, and the linkmesh-server cert lifecycle commands. →
Troubleshooting
Operational runbooks
Enrollment failures, cert renewal, server IP changes, common mistakes and how to recover. →
Browse the full operator docs, or reach the OpenSight team directly.