Skip to content

Latest commit

 

History

2,654 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Automated WireGuard® Management Client

This is the client for Netmaker networks. To learn more about Netmaker, see here.

Installation

https://docs.netmaker.io/docs/client-installation/netclient#installation

Usage

https://docs.netmaker.io/docs/client-installation/netclient#managing-netclient__joining-a-network

Join a network

With Token: netclient join -t <token>

With User (Basic Auth): netclient join -n <net name> -u <username> -s api.<netmaker domain>

With User (SSO): netclient join -n <net name> -s api.<netmaker domain>

Interface Exclusion

Netclient excludes certain interfaces from being advertised to peers. By default, the following patterns are excluded: docker, netmaker, flannel, cni, and bridge networks.

You can customize excluded interfaces using the NETCLIENT_EXCLUDE_INTERFACES environment variable:

NETCLIENT_EXCLUDE_INTERFACES=flannel,cni,calico,weave
  • Comma-separated list of interface name patterns (substring match)
  • Default (if not set): flannel,cni

Commands

Netmaker's netclient agent and CLI to manage wireguard networks

Join, leave, connect and disconnect from netmaker wireguard networks.

Usage:
  netclient [command]

Available Commands:
  completion  Generate the autocompletion script for the specified shell
  connect     connect to a netmaker network
  daemon      netclient daemon
  disconnect  disconnet from a network
  help        Help about any command
  install     install netclient binary and daemon
  join        join a network
  leave       leave a network
  list        display list of netmaker networks
  pull        get the latest node configuration
  uninstall   uninstall netclient
  version     Displays version information

Flags:
      --config string   use specified config file
  -h, --help            help for netclient
  -v, --verbosity int   set logging verbosity 0-4

Use "netclient [command] --help" for more information about a command.

TCP uplink (server-driven)

When the Netmaker control plane enables TCP uplink:

  • Gateway (tcp_proxy_enabled): netclient listens with TLS for framed WireGuard uplinks (tcp_proxy_listen_port, default 443). Uses a local self-signed cert under the netclient config directory.
  • Assigned node (use_tcp_uplink): netclient dials the gateway’s tcp_proxy_endpoint from peer updates and carries WireGuard ciphertext over TCP/TLS instead of UDP to that gateway.

On Linux this forces userspace WireGuard so traffic can be diverted via conn.Bind. Windows TCP uplink Bind is not supported yet.

Disclaimer

WireGuard is a registered trademark of Jason A. Donenfeld.

License

Netclient's source code and all artifacts in this repository are freely available under the Apache 2.0 License, which can be found here: LICENSE.txt.

About

No description, website, or topics provided.

Resources

Stars

97 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages