# Installation and Deployment Guide ## Prerequisites - Linux kernel 5.6+ (with native in-tree WireGuard module) - `nftables` packet filtering engine - Linux capabilities: `CAP_NET_ADMIN` and `CAP_NET_BIND_SERVICE` --- ## 1. Native Binary Installation ### Building from Source ```bash git clone ssh://git@git.nx9.in:6645/thakares/nx9-wg.git cd nx9-wg cargo build --release --bin nx9-wg # Install binary sudo install -m 0755 target/release/nx9-wg /usr/local/bin/nx9-wg ``` ### Initializing Directories and Configuration ```bash sudo mkdir -p /var/lib/nx9-wg /etc/nx9-wg /var/lib/nx9-wg/backups sudo cp config.example.toml /etc/nx9-wg/config.toml ``` ### Bootstrapping the Administrator Account ```bash sudo nx9-wg --config /etc/nx9-wg/config.toml --data-dir /var/lib/nx9-wg init --generate-password --write-password-file /var/lib/nx9-wg/admin-password ``` --- ## 2. Systemd Service Deployment ```bash # Copy systemd unit file sudo cp nx9-wg.service /etc/systemd/system/nx9-wg.service # Reload systemd and enable service sudo systemctl daemon-reload sudo systemctl enable --now nx9-wg # Check service status and logs sudo systemctl status nx9-wg sudo journalctl -u nx9-wg -f ``` --- ## 3. Upgrading nx9-wg 1. Stop the active service: ```bash sudo systemctl stop nx9-wg ``` 2. Create a safety backup: ```bash sudo nx9-wg --config /etc/nx9-wg/config.toml --data-dir /var/lib/nx9-wg backup create --description "Pre-upgrade backup" ``` 3. Install new binary: ```bash sudo install -m 0755 target/release/nx9-wg /usr/local/bin/nx9-wg ``` 4. Restart service (database schema migrations run automatically at startup): ```bash sudo systemctl start nx9-wg ```