Skip to content

VPN Configuration

bnerd vpn up / down / status read three keys from the vpn: block of ~/.bnerd.yaml. Everything else — endpoint, gateway key, your tunnel address, allowed IPs — comes from b'nerd when the device enrols; nothing of it is stored in the config file. The top-level bnerd up / down / status are deprecated aliases of the same commands and read the same three keys (see Legacy).

bnerd vpn up — the keys it reads

Key Default Description
vpn.config-dir ~/.config/bnerd/wireguard Where the device key files (<device>.key, mode 0600) and the generated tunnel configs (<interface>.conf) live
vpn.interface bnerd0 Default interface name; --interface overrides it per call
vpn.cleanup-config false Remove the generated <interface>.conf on bnerd vpn down (the key file is never removed by down)
# ~/.bnerd.yaml
api-url: https://api.bnerd.cloud
token: your-org-wide-token      # scope vpn_devices:write (or wider)
org-id: your-organization-id

vpn:
  config-dir: ~/.config/bnerd/wireguard
  interface: bnerd0
  cleanup-config: false

What is not in the file, on purpose: the private key (it stays in <config-dir>/<device>.key and is never sent anywhere), the gateway's endpoint and public key, your tunnel address and the routed range — all of that is issued by b'nerd per device and written into <interface>.conf. See bnerd vpn and the VPN Quick Start.

Legacy: bnerd up (deprecated)

bnerd up, bnerd down and bnerd status are aliases of bnerd vpn up / down / status: same flags, same behaviour, same stdout, plus a deprecation notice on stderr. They will be removed in a future release.

Before self-service enrolment these commands built a static tunnel from a vpn: block that also held the key pair. Those keys are no longer read by any command:

Ignored key What replaces it
server-endpoint, server-public-key issued by b'nerd per device, written into <interface>.conf
private-key, public-key generated by bnerd vpn up on first run, kept in <config-dir>/<device>.key (mode 0600), never in the config file
client-address, allowed-ips pinned by b'nerd per device and gateway
dns not set by the device configuration

interface, config-dir and cleanup-config keep their meaning (table above).

Legacy Replacement
bnerd up bnerd vpn up
bnerd down, bnerd up --down bnerd vpn down
bnerd status, bnerd up --status bnerd vpn status
bnerd up --generate-keys, bnerd up --show-peer-info removed; the error names the replacement

Old key material in ~/.bnerd.yaml

If your config file still contains a private-key from the static client, remove it: nothing reads it any more, and a key pair in a config file is a liability. The device key bnerd vpn up creates never enters the config file.