VPN Configuration¶
bnerd vpn up / down / status read three keys from the vpn: block of ~/.bnerd.yaml. Everything else — endpoint, gateway key, your tunnel address, allowed IPs — comes from b'nerd when the device enrols; nothing of it is stored in the config file. The top-level bnerd up / down / status are deprecated aliases of the same commands and read the same three keys (see Legacy).
bnerd vpn up — the keys it reads¶
| Key | Default | Description |
|---|---|---|
vpn.config-dir | ~/.config/bnerd/wireguard | Where the device key files (<device>.key, mode 0600) and the generated tunnel configs (<interface>.conf) live |
vpn.interface | bnerd0 | Default interface name; --interface overrides it per call |
vpn.cleanup-config | false | Remove the generated <interface>.conf on bnerd vpn down (the key file is never removed by down) |
# ~/.bnerd.yaml
api-url: https://api.bnerd.cloud
token: your-org-wide-token # scope vpn_devices:write (or wider)
org-id: your-organization-id
vpn:
config-dir: ~/.config/bnerd/wireguard
interface: bnerd0
cleanup-config: false
What is not in the file, on purpose: the private key (it stays in <config-dir>/<device>.key and is never sent anywhere), the gateway's endpoint and public key, your tunnel address and the routed range — all of that is issued by b'nerd per device and written into <interface>.conf. See bnerd vpn and the VPN Quick Start.
Legacy: bnerd up (deprecated)¶
bnerd up, bnerd down and bnerd status are aliases of bnerd vpn up / down / status: same flags, same behaviour, same stdout, plus a deprecation notice on stderr. They will be removed in a future release.
Before self-service enrolment these commands built a static tunnel from a vpn: block that also held the key pair. Those keys are no longer read by any command:
| Ignored key | What replaces it |
|---|---|
server-endpoint, server-public-key | issued by b'nerd per device, written into <interface>.conf |
private-key, public-key | generated by bnerd vpn up on first run, kept in <config-dir>/<device>.key (mode 0600), never in the config file |
client-address, allowed-ips | pinned by b'nerd per device and gateway |
dns | not set by the device configuration |
interface, config-dir and cleanup-config keep their meaning (table above).
| Legacy | Replacement |
|---|---|
bnerd up | bnerd vpn up |
bnerd down, bnerd up --down | bnerd vpn down |
bnerd status, bnerd up --status | bnerd vpn status |
bnerd up --generate-keys, bnerd up --show-peer-info | removed; the error names the replacement |
Old key material in ~/.bnerd.yaml
If your config file still contains a private-key from the static client, remove it: nothing reads it any more, and a key pair in a config file is a liability. The device key bnerd vpn up creates never enters the config file.