Files
nx9-wg/docs/linux_requirements.md
T
thakaresandCopilot 2ac6c81dfe cli: avoid data-dir initialization for version; create db parent dirs; redact generated passwords in CLI output
- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization.
- Create parent directories when an explicit --database path is provided.
- Redact printed generated administrator passwords; announce file path or redact instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-16 16:26:24 +05:30

35 lines
1.3 KiB
Markdown

# Linux Platform and Kernel Requirements
`nx9-wg` is built for modern Linux systems and relies directly on kernel networking features.
---
## 1. Kernel Requirements
- **Linux Kernel Version**: 5.6 or newer (WireGuard module is included in mainline kernel 5.6+).
- **Kernel Module**: `wireguard.ko` (`modprobe wireguard`).
- **Sysctl IP Forwarding**:
- `/proc/sys/net/ipv4/ip_forward` (must be `1` for VPN client internet routing).
- `/proc/sys/net/ipv6/conf/all/forwarding` (optional, for IPv6 dual-stack).
---
## 2. Firewall and Packet Filtering
- **`nftables`**: `nx9-wg` requires `nftables` in the kernel.
- **Isolated Table**: All rules are scoped inside `table inet nx9_wg`. `nx9-wg` does not alter or flush tables created by Docker, Kubernetes, or other firewall utilities.
---
## 3. Capability Requirements
When running without full root privileges, the process requires:
- `CAP_NET_ADMIN`: For configuring network links, routes, and packet filter tables.
- `CAP_NET_BIND_SERVICE`: If binding to low UDP ports (< 1024).
---
## 4. Unsupported Environments
- macOS and Windows do not support the Linux in-tree WireGuard kernel module. For local testing on non-Linux platforms, `nx9-wg` automatically engages the built-in `SimulatedWireGuardEngine` and `SimulatedNetworkEngine`.