Add nebula ctl, a local socket for the debug commands

Every diagnostic command nebula has was reachable through exactly one door:
the built-in ssh debug server. That server is off by default, and turning it
on means generating a host key, writing an sshd block with authorized public
keys, and SIGHUPing the daemon. That is a lot of ceremony to answer "what
version is this node running".

Nebula now serves the same commands over a local unix socket, enabled by
default, and `nebula ctl <command>` runs them. The socket lives in a 0700
directory so filesystem permissions are the access control; no keys, nothing
on the network. Failing to create it is logged and never blocks startup.

The command registry was already transport neutral, so this is mostly new
transport rather than new commands:

  - diag/ holds the registry, dispatch, writer and wire protocol, moved out
    of sshd because none of it was ever about ssh. sshd and ctl.go dispatch
    against one shared registry.
  - commands.go holds every command implementation, moved out of ssh.go
    (which was 85% not ssh) and renamed off the ssh prefix. Adding a command
    there makes it available over both transports.
  - ssh.go keeps only host keys, authorized users, and the listen address.
  - ctl.go supervises the socket, following the statsServer lifecycle shape.

The wire protocol frames the response rather than terminating it, because
print-cert -raw and list-hostmap -json both emit arbitrary bytes that no
sentinel could safely delimit. argv travels as a list so quoting survives.
Exit statuses are real: 0, 2 for usage, 127 for an unknown command.

Two things fall out. The ssh console now reports a real exit status instead
of a hardcoded zero, so `ssh host list-hostmap` is scriptable too. And eight
command callbacks that silently returned nil on a flags type mismatch now
report it, which the exit status makes visible.

Windows is a stub returning a clear "not supported" until it gets a named
pipe with a security descriptor; iOS and Android are never enabled, having no
daemon for a CLI to attach to.

Breaking for embedders of the sshd package: NewSSHServer takes a
*diag.Registry, SSHServer.RegisterCommand is gone in favor of registering on
that registry, and the command types live in diag rather than sshd.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014fya5fTXGiwX72FUmoL9y3
This commit is contained in:
Matt Richardson
2026-09-09 17:07:35 -04:00
co-authored by Claude Opus 5
parent 89178f45ba
commit 14a4d87faf
26 changed files with 3113 additions and 976 deletions
+24
View File
@@ -236,6 +236,30 @@ punchy:
# Overriding this to "" is the same as "/" and will allow overwriting any path on the host.
#sandbox_dir: /var/tmp/nebula-debug
# ctl exposes nebula's debug and administrative commands over a local unix socket, so that `nebula ctl <command>` can
# reach the same commands the sshd block offers above without running an ssh server. Run `nebula ctl` on its own for the
# list of commands. Anyone who can open the socket can do everything the ssh console can, including closing tunnels,
# changing remotes, and writing profile data to disk, so the socket lives in a directory only the user nebula runs as
# can enter. Enabled by default. Not supported on Windows yet, and never enabled on iOS or Android.
#ctl:
# Toggles the feature. This setting is reloadable.
#enabled: true
# socket is the unix socket to listen on. The parent directory is created if it is missing and made readable only by
# the user nebula runs as, and a socket left behind by a crashed nebula is replaced. Defaults to /run/nebula/ctl.sock
# on Linux and /var/run/nebula/ctl.sock everywhere else; running nebula as a non-root user means picking a path it can
# write. Two nebulas on one host need two paths, the second to start will log that the socket is already being served
# and carry on without one. `nebula ctl` reads this value from the same config file when it is given -config, and
# otherwise assumes the default above. This setting is reloadable.
#socket: /run/nebula/ctl.sock
# sandbox_dir restricts the file paths the profiling commands (start-cpu-profile, save-heap-profile,
# save-mutex-profile) may write, exactly like sshd.sandbox_dir above, which it defaults to. Note that these paths are
# resolved by the nebula process and not by the shell running `nebula ctl`, so a relative path lands in this directory
# rather than in your working directory, and under a systemd unit with PrivateTmp=yes it lands somewhere your shell
# cannot see at all. The directory is NOT automatically created.
#sandbox_dir: /var/tmp/nebula-debug
# EXPERIMENTAL: relay support for networks that can't establish direct connections.
relay:
# Relays are a list of Nebula IP's that peers can use to relay packets to me.