- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization. - Create parent directories when an explicit --database path is provided. - Redact printed generated administrator passwords; announce file path or redact instead. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
8.1 KiB
8.1 KiB
Native CLI Command Reference (nx9-wg)
The nx9-wg binary provides 100% native CLI coverage for the entire NX9 WireGuard application stack.
The CLI directly executes native Rust application services (Store, WireGuardEngine, NetworkEngine, ReconciliationEngine, BackupService, AuthService) without calling external subprocesses.
Global Options
-c, --config <PATH>: Path to configuration file (env:NX9_WG_CONFIG, default:/etc/nx9-wg/config.toml)-d, --data-dir <PATH>: Path to data directory (env:NX9_WG_DATA_DIR, default:/var/lib/nx9-wg)--database <PATH>: Explicit SQLite database path or URL (env:NX9_WG_DATABASE)--format <table|json|yaml|csv>: Output formatting style (default:table)--json: Output strictly in formatted JSON-q, --quiet: Suppress status and conversational messages-v, --verbose: Enable debug trace output--log-level <LEVEL>: Log verbosity level (trace,debug,info,warn,error, env:NX9_WG_LOG_LEVEL)
Command Groups
1. version
Displays version, build metadata, target architecture, and feature capabilities.
nx9-wg version
nx9-wg version --format json
2. serve
Starts the Axum REST API, WebSocket event streamer, and background reconciliation daemon.
nx9-wg serve --bind 0.0.0.0:8080
3. init
Initializes the single administrator account across 7 supported bootstrap sources.
# Generated password:
nx9-wg init --generate-password --write-password-file /root/admin-pw.txt
# Password from standard input:
echo "SecureSecret123!" | nx9-wg init --password-stdin
# Password from file:
nx9-wg init --password-file /run/secrets/admin_pw
4. system
nx9-wg system status: System database statistics and object counts.nx9-wg system health: System and database connectivity health check.nx9-wg system info: System platform, architecture, and runtime paths.nx9-wg system settings list: List all configuration key-value settings.nx9-wg system settings get <KEY>: Query setting value.nx9-wg system settings set <KEY> <VALUE> [--secret]: Save setting.nx9-wg system settings delete <KEY>: Delete setting.
5. admin
nx9-wg admin status: View administrator profile and last login metrics.nx9-wg admin create: Provision administrator if not already initialized.nx9-wg admin password --new-password <PW> | --stdin | --password-file <PATH> | --generate: Update password and invalidate all sessions.nx9-wg admin sessions list: List active sessions.nx9-wg admin sessions revoke <SESSION_ID>: Invalidate specific session.nx9-wg admin sessions revoke-all: Invalidate all active administrator sessions.nx9-wg admin tokens create --name <NAME> [--days <DAYS>]: Generate a long-lived API token.nx9-wg admin tokens list: List all API token metadata.nx9-wg admin tokens revoke <TOKEN_ID>: Revoke an API token.
6. interface
nx9-wg interface list: List all WireGuard interfaces.nx9-wg interface show <NAME_OR_ID>: Inspect interface details.nx9-wg interface create <NAME> --address-v4 <CIDR> [--port <PORT>] [--address-v6 <CIDR>] [--mtu <MTU>] [--dns <DNS>]: Create an interface.nx9-wg interface update <NAME_OR_ID> [--port <PORT>] [--address-v4 <CIDR>] [--enabled <BOOL>]: Update interface properties.nx9-wg interface enable <NAME_OR_ID>/disable <NAME_OR_ID>: Toggle administrative state.nx9-wg interface delete <NAME_OR_ID>: Delete interface and associated peers.nx9-wg interface status <NAME>: Query live interface telemetry.nx9-wg interface reconcile <NAME>: Reconcile interface state with the Linux kernel.
7. peer
nx9-wg peer list [--interface <NAME_OR_ID>]: List enrolled peers.nx9-wg peer show <PEER_ID>: Inspect peer configuration and metadata.nx9-wg peer create --interface <NAME_OR_ID> --name <NAME> [--address-v4 <CIDR>] [--allowed-ips <CIDRS>] [--endpoint <IP:PORT>]: Enroll peer.nx9-wg peer update <PEER_ID> [--name <NAME>] [--allowed-ips <CIDRS>] [--enabled <BOOL>]: Update peer parameters.nx9-wg peer enable <PEER_ID>/disable <PEER_ID>/revoke <PEER_ID>: Peer lifecycle transitions.nx9-wg peer delete <PEER_ID>: Remove peer.nx9-wg peer status <PEER_ID>: Live handshake, endpoint, and bandwidth telemetry.nx9-wg peer config <PEER_ID> [--output <PATH>]: Generate standard client.conffile.nx9-wg peer qr <PEER_ID> [--qr-format <terminal|svg|png>]: Generate enrollment QR code.
8. network
nx9-wg network list: List defined subnet networks.nx9-wg network show <ID>: Inspect network details.nx9-wg network create <NAME> <CIDR> [--description <TEXT>]: Create subnet network.nx9-wg network update <ID> [--name <NAME>] [--cidr <CIDR>] [--enabled <BOOL>]: Update network.nx9-wg network delete <ID>: Delete subnet network.
9. route
nx9-wg route list: List configured kernel routing rules.nx9-wg route show <ID>: Inspect route rule.nx9-wg route add --destination <CIDR> [--gateway <IP>] [--interface-name <IFACE>] [--metric <METRIC>]: Add route.nx9-wg route update <ID> [--destination <CIDR>] [--gateway <IP>] [--metric <METRIC>]: Update route.nx9-wg route delete <ID>: Delete route.nx9-wg route status: Status of kernel routing table management.nx9-wg route sync: Synchronize desired routes to Linux kernel routing table.
10. firewall
nx9-wg firewall list: List nftables firewall rules.nx9-wg firewall show <ID>: Inspect firewall rule.nx9-wg firewall add --name <NAME> [--direction <in|out|forward>] [--source <CIDR>] [--destination <CIDR>] [--protocol <tcp|udp|icmp|any>] [--port <PORT>] [--action <accept|drop|reject>] [--priority <INT>]: Add rule.nx9-wg firewall update <ID> [--action <ACTION>] [--priority <INT>] [--enabled <BOOL>]: Update rule.nx9-wg firewall delete <ID>/enable <ID>/disable <ID>: Rule management.nx9-wg firewall status: Inspect active nftables ruleset and table.nx9-wg firewall sync: Synchronize firewall ruleset to nftables.
11. nat
nx9-wg nat status: Inspect NAT masquerade status and managed subnets.nx9-wg nat enable/disable: Toggle NAT masquerade setting.nx9-wg nat list: List subnets configured for NAT masquerade.nx9-wg nat sync: Synchronize NAT rules to nftables postrouting chain.
12. forwarding
nx9-wg forwarding status: Inspect IPv4 and IPv6 kernel packet forwarding state.nx9-wg forwarding enable/disable: Enable or disable kernel packet forwarding.nx9-wg forwarding sync: Synchronize sysctl forwarding parameters.
13. reconcile
nx9-wg reconcile status: Summary of detected drift across all subsystems.nx9-wg reconcile plan [--interface <NAME>]: Dry-run drift analysis without state mutation.nx9-wg reconcile apply [--interface <NAME>]: Reconcile SQLite desired state to Linux kernel.nx9-wg reconcile verify: Assert zero drift exists between SQLite and kernel (returns exit code 1 if drift exists).
14. backup
nx9-wg backup create [--description <TEXT>]: Generate consistent SQLite backup snapshot with SHA-256 manifest.nx9-wg backup list: List all backup snapshots.nx9-wg backup show <ID>: Inspect backup metadata and file size.nx9-wg backup verify --path <PATH>: Verify integrity and checksum of backup archive.nx9-wg backup restore --path <PATH> --yes: Safely restore database with pre-restore safety snapshot.nx9-wg backup delete <ID>: Delete backup record and archive.
15. audit
nx9-wg audit list [--event-type <TYPE>] [--actor <ACTOR>] [--resource-type <RESOURCE>] [--limit <N>] [--offset <N>]: Query security audit trail.nx9-wg audit show <ID>: Inspect complete audit event details.
16. live
nx9-wg live interface list/show <NAME>: Query active WireGuard interfaces from kernel.nx9-wg live peer list <IFACE>/show <KEY_OR_ID>: Query active peers from kernel.nx9-wg live routes: Query live kernel routing status.nx9-wg live firewall: Query live nftables ruleset.nx9-wg live forwarding: Query live kernel forwarding sysctls.nx9-wg live nat: Query live NAT state.