Release v1.1.0
This commit is contained in:
1 parent
34227efd2b
commit
edc710cbd2
46 files changed
+5324
-190
No files matched your search
@@ -4,7 +4,7 @@
|
||||

|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
> **Sovereign, self-hosted, Linux-native VPN and network control plane built directly around the kernel's WireGuard implementation.**
|
||||
|
||||
@@ -57,21 +57,22 @@ Rather than functioning as a user interface wrapper that shells out to external
|
||||
|
||||
---
|
||||
|
||||
## 2. Key Capabilities
|
||||
|
||||
- **WireGuard Interface & Peer Lifecycle**: Direct RTNETLINK link management (`RTM_NEWLINK`/`RTM_DELLINK`) and WireGuard Generic Netlink (`WG_CMD_SET_DEVICE`/`WG_CMD_GET_DEVICE`) with cryptokey routing.
|
||||
- **Explicit Interface Roles (Overlay vs Upstream)**: Formal separation of the primary protected overlay interface (`wg0`) from optional third-party WireGuard VPN upstream interfaces (e.g. `proton0`).
|
||||
- **Third-Party WireGuard .conf Import**: In-process parser and validator for standard `.conf` files (supporting single `[Interface]` and single `[Peer]`), with live configuration preview before atomic database persistence.
|
||||
- **Optional Local Listen Ports**: Strict modeling of `Interface.listen_port` as `Option<u16>`, allowing Linux WireGuard to select ephemeral dynamic UDP ports when `ListenPort` is omitted from imported configurations, preventing local port collisions with `wg0` (51820).
|
||||
- **WireGuard Interface & Peer Lifecycle**: Direct RTNETLINK link management (`RTM_NEWLINK`/`RTM_DELLINK`) and WireGuard Generic Netlink (`WG_CMD_SET_DEVICE`/`WG_CMD_GET_DEVICE`) with role-aware cryptokey routing.
|
||||
- **Persistent Server Endpoint Settings**: Authoritative configuration of public client-reachable endpoint (`wireguard.server_host`, `wireguard.server_port`, `wireguard.server_endpoint_enabled`) automatically embedded into client exports and QR codes.
|
||||
- **Strict AllowedIPs Semantic Separation**: Correctly derives server-side cryptokey routing AllowedIPs (`/32` and `/128`) from assigned tunnel addresses, distinct from client full-tunnel (`0.0.0.0/0, ::/0`) routing policies.
|
||||
- **Strict AllowedIPs Semantic Separation**: Correctly derives server-side cryptokey routing AllowedIPs (`/32` and `/128`) from assigned tunnel addresses for Overlay peers, while preserving full-tunnel provider AllowedIPs (`0.0.0.0/0, ::/0`) for Upstream peers without mutating the host default routing table.
|
||||
- **IPv4/IPv6 Address Management**: In-process `RTM_NEWADDR` and `RTM_DELADDR` Netlink execution without invoking `ip addr`.
|
||||
- **Protected Route Management**: In-process routing table reconciliation protecting host default routes from accidental disruption.
|
||||
- **In-Process nftables Firewall & NAT**: Transactional rule compilation via `libnftables.so.1` strictly scoped to `table inet nx9_wg`.
|
||||
- **Scoped Outbound NAT Masquerade**: Automated masquerading scoped to managed WireGuard client subnets and non-WireGuard egress interfaces.
|
||||
- **Atomic IP Packet Forwarding**: Direct `/proc/sys/net/ipv4/ip_forward` and IPv6 forwarding control.
|
||||
- **Live Kernel Telemetry**: Live handshake timestamps, authenticated roaming endpoints, and 64-bit RX/TX byte counters merged into API and WebUI responses.
|
||||
- **Closed-Loop Reconciliation**: Continuous drift detection, dry-run deterministic planning, and serialized convergence.
|
||||
- **Closed-Loop Reconciliation**: Continuous drift detection, dry-run deterministic planning, orphan interface removal, and serialized convergence with empty-desired-state safety guards.
|
||||
- **Cold-Boot Restart Recovery**: Deterministic reconstruction of live kernel networking from authoritative SQLite state upon boot.
|
||||
- **Single Administrator Identity**: Database-level `CHECK (id = 1)` constraint, Argon2id password hashing, and SHA-256 API token digests.
|
||||
- **Zero-Dependency Single Page Application (SPA)**: Embedded HTML5/CSS/JS frontend with dark/light themes, live WebSocket telemetry, and responsive mobile-first UI.
|
||||
- **Zero-Dependency Single Page Application (SPA)**: Embedded HTML5/CSS/JS frontend with dark/light themes, live WebSocket telemetry, responsive mobile-first UI, Upstream import modal with live preview, and read-only CLI console.
|
||||
- **Pure Rust Client Configuration & QR**: In-process generation of standard `.conf` text and SVG, PNG, and terminal ASCII QR codes.
|
||||
- **Automated Health Diagnostics**: Deep inspection across 11 subsystems with actionable remediation hints.
|
||||
- **Atomic SQLite Online Backups**: Non-blocking `VACUUM INTO` snapshots with SHA-256 integrity manifests and pre-restore safety snapshots.
|
||||
@@ -139,8 +140,8 @@ When generating client configuration files (`.conf`) and QR codes, `nx9-wg` auto
|
||||
|
||||
```bash
|
||||
# Extract release archive:
|
||||
tar -xzf nx9-wg-v1.0.0-linux-x86_64.tar.gz
|
||||
cd nx9-wg-v1.0.0-linux-x86_64
|
||||
tar -xzf nx9-wg-v1.1.0-linux-x86_64.tar.gz
|
||||
cd nx9-wg-v1.1.0-linux-x86_64
|
||||
|
||||
# Run production installer as root:
|
||||
sudo bash install.sh
|
||||
@@ -213,7 +214,7 @@ max_count = 5
|
||||
Access the Web UI at `http://<server-ip>:8080/`. The interface is a zero-dependency SPA embedded inside the binary:
|
||||
|
||||
- **Dashboard (`#dashboard`)**: System status, uptime, interface/peer counts, diagnostics health summary, and live reconciliation status.
|
||||
- **Interfaces (`#interfaces`)**: Interface list, "+ Create Interface" modal, interface **Edit** action (preserves private/public key identity), enable/disable toggle, and delete action.
|
||||
- **Interfaces (`#interfaces`)**: Interface list with explicit **Role** badges (`Overlay` vs `Upstream`), "+ Create Interface" modal with tabbed **Standard Overlay** vs **Import Upstream VPN** (`.conf` parser & live preview), interface **Edit** action (preserves private/public key identity), **Restart** action (link teardown + re-sync), enable/disable toggle, and delete action (protected against `wg0`), plus an embedded read-only CLI console.
|
||||
- **Peers (`#peers`)**: Enrolled peer table with real-time handshakes, status filters, "+ Add Peer" modal with MTU profile resolution, client configuration export modal, and live SVG QR rendering.
|
||||
- **Networks (`#networks`)**: Subnet network definitions, CIDR blocks, available unallocated IP inspection, and "+ Create Network" modal.
|
||||
- **Routes (`#routes`)**: Kernel routing table entries, gateway assignments, and "+ Create Route" modal.
|
||||
@@ -240,11 +241,19 @@ nx9-wg system settings set wireguard.server_host vpn.thakares.com
|
||||
nx9-wg system settings set wireguard.server_port 51820
|
||||
nx9-wg system settings set wireguard.server_endpoint_enabled true
|
||||
|
||||
# 2. Interface Creation & Editing
|
||||
# 2. Interface Creation, Editing & Restart
|
||||
nx9-wg interface create wg0 --address-v4 10.100.0.1/24 --port 51820 --mtu 1420
|
||||
nx9-wg interface update wg0 --mtu 1420
|
||||
nx9-wg interface restart wg0
|
||||
|
||||
# 3. Peer Enrollment & Client Config Export
|
||||
# 3. Third-Party Upstream Management (e.g. ProtonVPN)
|
||||
nx9-wg interface upstream import proton0 --file /path/to/protonvpn.conf
|
||||
nx9-wg interface upstream list
|
||||
nx9-wg interface upstream show proton0
|
||||
nx9-wg interface upstream status proton0
|
||||
nx9-wg interface upstream restart proton0
|
||||
|
||||
# 4. Peer Enrollment & Client Config Export
|
||||
nx9-wg peer create --interface wg0 --name alice-phone --profile full_tunnel --mtu 1280
|
||||
|
||||
# Export client configuration (uses persistent server endpoint):
|
||||
@@ -259,16 +268,16 @@ nx9-wg peer qr <PEER_UUID>
|
||||
# Render QR code as SVG:
|
||||
nx9-wg peer qr <PEER_UUID> --qr-format svg
|
||||
|
||||
# 4. Reconciliation
|
||||
# 5. Reconciliation
|
||||
nx9-wg reconcile plan
|
||||
nx9-wg reconcile apply
|
||||
nx9-wg reconcile verify
|
||||
|
||||
# 5. Live Telemetry & Diagnostics
|
||||
# 6. Live Telemetry & Diagnostics
|
||||
nx9-wg live peer wg0
|
||||
nx9-wg diagnostics all
|
||||
|
||||
# 6. Database Backups
|
||||
# 7. Database Backups
|
||||
nx9-wg backup create --description "Pre-maintenance snapshot"
|
||||
nx9-wg backup list
|
||||
nx9-wg backup verify /var/lib/nx9-wg/backups/snapshot.db
|
||||
@@ -326,8 +335,8 @@ All release quality gates have been executed and verified on Debian Linux:
|
||||
| **Formatting** | `cargo fmt --all -- --check` | **PASS** (0 errors) |
|
||||
| **Compilation** | `cargo check --workspace --all-targets` | **PASS** (0 errors) |
|
||||
| **Clippy Linting** | `cargo clippy --workspace --all-targets --all-features -- -D warnings` | **PASS** (0 warnings) |
|
||||
| **Workspace Test Suite** | `cargo test --workspace --all-targets` | **PASS** (All 162 tests passing) |
|
||||
| **CLI Test Suite** | `cargo test --test test_cli_commands` | **PASS** (11 tests passing) |
|
||||
| **Workspace Test Suite** | `cargo test --workspace --all-targets` | **PASS** (All 195 tests passing) |
|
||||
| **CLI Test Suite** | `cargo test --test test_cli_commands` | **PASS** (12 tests passing) |
|
||||
| **Release Compilation** | `cargo build --release --workspace` | **PASS** (Optimized release binary) |
|
||||
| **Production Server Acceptance** | Physical Android WireGuard client connection | **VERIFIED** (Live handshake and RX/TX telemetry confirmed) |
|
||||
|
||||
|
||||
Reference in new issue
Block a user