Files
nx9-wg/docs/cli.md
T

133 lines
5.8 KiB
Markdown

# Native CLI Command Reference (`nx9-wg`)
The `nx9-wg` binary provides 100% native CLI coverage across all 17 application subcommands without spawning external subprocesses.
---
## 1. Global Options
| Option | Environment Variable | Description |
| :--- | :--- | :--- |
| `-c, --config <PATH>` | `NX9_WG_CONFIG` | Path to configuration file (default: `/etc/nx9-wg/config.toml`) |
| `-d, --data-dir <PATH>` | `NX9_WG_DATA_DIR` | Path to data directory (default: `/var/lib/nx9-wg`) |
| `--database <PATH>` | `NX9_WG_DATABASE` | Specific SQLite database file path or URL |
| `--format <FORMAT>` | N/A | Output format (`table`, `json`, `yaml`, `csv`, default: `table`) |
| `--json` | N/A | Convenience flag for strict JSON output |
| `-q, --quiet` | N/A | Suppress status and conversational messages |
| `-v, --verbose` | N/A | Enable verbose trace logging |
| `--log-level <LEVEL>` | `NX9_WG_LOG_LEVEL` | Log verbosity level (`trace`, `debug`, `info`, `warn`, `error`) |
---
## 2. Command Groups Reference
### 1. `version`
Displays version, build edition, architecture, OS platform, and security flags.
```bash
nx9-wg version
nx9-wg version --format json
```
### 2. `serve`
Starts the Axum REST API daemon, WebSocket streamer, and background reconciliation scheduler.
```bash
nx9-wg serve
nx9-wg serve --bind 0.0.0.0:8080
```
### 3. `init`
Initializes the single administrator account across 7 bootstrap sources.
```bash
# Generated secure password:
nx9-wg init --generate-password --write-password-file /var/lib/nx9-wg/admin-password
# Password via stdin:
echo "StrongPassword123!" | nx9-wg init --password-stdin
# Password from file:
nx9-wg init --password-file /run/secrets/admin_pw
```
### 4. `system`
- `nx9-wg system status`: System database statistics and object counts.
- `nx9-wg system health`: System and SQLite connectivity health check.
- `nx9-wg system info`: System platform, architecture, and runtime paths.
- `nx9-wg system settings list`: List all key-value settings.
- `nx9-wg system settings get <KEY>`: Query setting value.
- `nx9-wg system settings set <KEY> <VALUE> [--secret]`: Save setting.
- `nx9-wg system settings delete <KEY>`: Delete setting.
### 5. `admin`
- `nx9-wg admin info`: Query administrator account metadata.
- `nx9-wg admin password`: Change administrator password.
- `nx9-wg admin token create <NAME> [--expires-in-days N] [--write-token-file PATH]`: Generate API token.
- `nx9-wg admin token list`: List active API tokens.
- `nx9-wg admin token revoke <TOKEN_ID>`: Revoke an API token.
- `nx9-wg admin session list`: List active browser sessions.
- `nx9-wg admin session revoke-all`: Invalidate all active sessions.
### 6. `interface`
- `nx9-wg interface list`: List all WireGuard interfaces.
- `nx9-wg interface create <NAME> --address-v4 <CIDR> [--port PORT] [--mtu MTU]`: Create interface.
- `nx9-wg interface show <NAME_OR_ID>`: Show interface configuration.
- `nx9-wg interface enable <NAME_OR_ID>`: Enable interface (`IFF_UP`).
- `nx9-wg interface disable <NAME_OR_ID>`: Disable interface (`IFF_DOWN`).
- `nx9-wg interface delete <NAME_OR_ID>`: Delete interface.
### 7. `peer`
- `nx9-wg peer list [--interface NAME]`: List enrolled peers.
- `nx9-wg peer create --interface <IFACE> --name <NAME> [--profile PROFILE] [--mtu MTU]`: Enroll peer.
- `nx9-wg peer show <PEER_ID>`: Show peer configuration.
- `nx9-wg peer enable <PEER_ID>` / `disable <PEER_ID>`: Toggle peer state.
- `nx9-wg peer delete <PEER_ID>`: Delete peer.
- `nx9-wg peer config <PEER_ID> [--device DEV] [--connection CONN]`: Output `.conf` client file.
- `nx9-wg peer qr <PEER_ID>`: Render ASCII QR code in terminal for mobile scanning.
### 8. `network`
- `nx9-wg network list`: List subnet networks.
- `nx9-wg network create <NAME> --cidr <CIDR>`: Create network.
- `nx9-wg network delete <NAME_OR_ID>`: Delete network.
### 9. `route`
- `nx9-wg route list`: List routing table entries.
- `nx9-wg route add --destination <CIDR> [--gateway IP] [--interface-name IFACE] [--metric M]`: Add route.
- `nx9-wg route delete <ROUTE_ID>`: Delete route.
### 10. `firewall`
- `nx9-wg firewall list`: List nftables firewall rules.
- `nx9-wg firewall add --name <NAME> [--protocol PROTO] [--port PORT] [--action ACTION] [--priority P]`: Add rule.
- `nx9-wg firewall enable <RULE_ID>` / `disable <RULE_ID>`: Toggle rule.
- `nx9-wg firewall delete <RULE_ID>`: Delete rule.
### 11. `nat`
- `nx9-wg nat status`: Query NAT masquerade state.
- `nx9-wg nat enable` / `disable`: Toggle outbound NAT masquerading.
### 12. `forwarding`
- `nx9-wg forwarding status`: Query kernel `/proc/sys/net/ipv4/ip_forward` status.
- `nx9-wg forwarding enable` / `disable`: Toggle kernel IP forwarding.
### 13. `reconcile`
- `nx9-wg reconcile plan`: Calculate read-only drift between SQLite and kernel.
- `nx9-wg reconcile apply`: Apply mutations across all execution planes.
- `nx9-wg reconcile verify`: Post-apply verification check.
### 14. `backup`
- `nx9-wg backup list`: List backup snapshots.
- `nx9-wg backup create [--description DESC]`: Generate atomic SQLite online backup (`VACUUM INTO`).
- `nx9-wg backup verify <PATH>`: Verify SQLite 3 header and SHA-256 checksum.
- `nx9-wg backup restore <PATH_OR_ID>`: Restore database with automatic safety snapshot.
### 15. `audit`
- `nx9-wg audit list [--limit N] [--event-type TYPE]`: List append-only audit trail records.
### 16. `live`
- `nx9-wg live interfaces`: Query active Linux kernel WireGuard interfaces.
- `nx9-wg live peers <IFACE>`: Query live peers, transfer bytes, and handshakes.
- `nx9-wg live routes`: Query live kernel routing table.
- `nx9-wg live nftables`: Query active `table inet nx9_wg` ruleset.
### 17. `diagnostics`
- `nx9-wg diagnostics inspect all`: Inspect health across all 9 subsystems.
- `nx9-wg diagnostics inspect <SUBSYSTEM>`: Inspect specific subsystem (`system`, `network`, `wireguard`, `peer`, `routing`, `forwarding`, `firewall`, `nat`, `reconciliation`).