This is the client for Netmaker networks. To learn more about Netmaker, see here.
https://docs.netmaker.io/docs/client-installation/netclient#installation
https://docs.netmaker.io/docs/client-installation/netclient#managing-netclient__joining-a-network
With Token:
netclient join -t <token>
With User (Basic Auth):
netclient join -n <net name> -u <username> -s api.<netmaker domain>
With User (SSO):
netclient join -n <net name> -s api.<netmaker domain>
Netclient excludes certain interfaces from being advertised to peers. By default, the following patterns are excluded: docker, netmaker, flannel, cni, and bridge networks.
You can customize excluded interfaces using the NETCLIENT_EXCLUDE_INTERFACES environment variable:
NETCLIENT_EXCLUDE_INTERFACES=flannel,cni,calico,weave- Comma-separated list of interface name patterns (substring match)
- Default (if not set):
flannel,cni
Netmaker's netclient agent and CLI to manage wireguard networks
Join, leave, connect and disconnect from netmaker wireguard networks.
Usage:
netclient [command]
Available Commands:
completion Generate the autocompletion script for the specified shell
connect connect to a netmaker network
daemon netclient daemon
disconnect disconnet from a network
help Help about any command
install install netclient binary and daemon
join join a network
leave leave a network
list display list of netmaker networks
pull get the latest node configuration
uninstall uninstall netclient
version Displays version information
Flags:
--config string use specified config file
-h, --help help for netclient
-v, --verbosity int set logging verbosity 0-4
Use "netclient [command] --help" for more information about a command.
When the Netmaker control plane enables TCP uplink:
- Gateway (
tcp_proxy_enabled): netclient listens with TLS for framed WireGuard uplinks (tcp_proxy_listen_port, default 443). Uses a local self-signed cert under the netclient config directory. - Assigned node (
use_tcp_uplink): netclient dials the gateway’stcp_proxy_endpointfrom peer updates and carries WireGuard ciphertext over TCP/TLS instead of UDP to that gateway.
On Linux this forces userspace WireGuard so traffic can be diverted via conn.Bind. Windows TCP uplink Bind is not supported yet.
WireGuard is a registered trademark of Jason A. Donenfeld.
Netclient's source code and all artifacts in this repository are freely available under the Apache 2.0 License, which can be found here: LICENSE.txt.