NX9 WireGuard Documentation Index
Welcome to the official documentation for the NX9 WireGuard (nx9-wg) appliance and management platform.
1. Getting Started & Philosophy
- NX9 Design Principles — Architectural philosophy, self-hosted sovereignty, zero scripting runtime, and SQLite authority.
- Installation & Deployment Guide — Production installation, systemd service, admin bootstrap, first interface, and peer setup.
- Linux Platform & Kernel Requirements — Kernel 5.6+, in-tree WireGuard module, Netlink sockets,
libnftables.so.1, and capabilities.
2. Architecture & Native Linux Execution
- System Architecture & Workspace Structure — Six-crate workspace breakdown, layer boundaries, and end-to-end data flows.
- Native WireGuard Netlink Engine — Direct RTNETLINK and Generic Netlink (
wireguard) protocol implementation. - Native Network & Routing Engine — RTNETLINK link/address/route lifecycle and direct procfs IP packet forwarding.
- Native nftables Engine — In-process
libnftables.so.1FFI transactions and dedicatedtable inet nx9_wgscoping. - Firewall & NAT Domain Model — Typed rules, protocol groups, port ranges, priorities, and outbound NAT masquerading.
3. Control Plane, UI & Telemetry
- Reconciliation Engine & Convergence — Closed-loop drift detection, read-only planning, serialized apply, and convergence lifecycle states.
- Web User Interface (SPA) — Zero-dependency embedded HTML5/CSS/JS frontend, theme engine, and all 15 application routes.
- Axum REST API & WebSocket Protocol — Complete endpoint reference, JSON schemas, error handling, and real-time event broadcaster.
- Native CLI Command Reference — Full reference for all 17 CLI subcommands, multi-format output (
table/json/yaml/csv), and secret files.
4. Security & Disaster Recovery
- Security Model & Privilege Architecture — Single admin model (
CHECK (id=1)), Argon2id hashing, SHA-256 tokens, permissions matrix, and brute-force protection. - Backup & Disaster Recovery Guide — Atomic online SQLite backups (
VACUUM INTO), SHA-256 manifests, and pre-restore safety snapshots.
5. Operations, Development & Release
- Release Engineering & Packaging — Standalone distribution packages (
.tar.gz/.tar.xz), systemd sandboxing, installer, and rollback strategy. - Quality Assurance & Testing Strategy — Multi-tiered test suites, SAFE mode (
LIVE=0) vs real-kernel mode (LIVE=1), and automated security audits. - Developer & Contributing Guide — Building, testing, linting, and workspace contribution standards.
- Configuration Reference — TOML configuration format and
NX9_WG_*environment variable precedence. - Docker & Container Deployment — Containerized deployment with Linux capability isolation and volume persistence.