Skip to content

Reference ​

Everything muxen-eagle exposes, in tables.

Command ​

muxen-eagle-init

It takes no options and no arguments, and ignores anything passed to it. Every value it uses is either a constant in the script or read from the local NetBird client. It must run as root.

Constants ​

Fixed inside /usr/bin/muxen-eagle-init; changing one means shipping a new package.

NameValueUsed for
MGMT_UP_URLhttps://eagle.muxen.frthe --management-url passed to netbird up
MGMT_STATUS_URLhttps://eagle.muxen.fr:443compared against .management.url from netbird status --json
MGMT_HOSTeagle.muxen.fr:443compared against .ManagementURL.Host in the legacy profile file
KEY_FILE${MUXEN_EAGLE_KEY_FILE:-/etc/muxen/eagle.key}the setup key
PROFILEeaglethe NetBird profile name
NETBIRD_OPTSsee belowappended to netbird up

NETBIRD_OPTS:

--allow-server-ssh
--enable-ssh-local-port-forwarding
--enable-ssh-remote-port-forwarding
--enable-ssh-sftp

Environment ​

VariableDefaultEffect
MUXEN_EAGLE_KEY_FILE/etc/muxen/eagle.keypath of the setup key

The systemd unit sets no environment and reads no environment file, so on a Brain the default always applies.

Messages ​

One line per run, and it identifies the outcome.

MessageStreamExit
Already connected using default profile (legacy install)stdout0
Already connected to eaglestdout0
Enrolled with eagle but not connected yet; leaving it to netbirdstdout0
netbird daemon not answering yet; will retrystderr1
No setup key at <path> and not enrolled: cannot register with eaglestderr78

A run that enrols the boat prints none of them; the output on that path is whatever netbird itself writes.

Exit codes ​

CodeMeaningRetried by the unit
0enrolled during this run, or already enrolled—
1the netbird daemon did not answer; state unknown, so retryableyes
78EX_CONFIG — no usable setup key and not enrolledno (RestartPreventExitStatus=78)
otherset -e propagated the status of a failing netbird, jq or systemctl commandyes

Files ​

PathOwnerModeContent
/usr/bin/muxen-eagle-initpackage0755the script — the whole application
/usr/lib/systemd/system/muxen-eagle.servicepackage0644the systemd unit
/etc/muxen/eagle.keypackage0600 root:rootthe NetBird setup key. Not a conffile. Deleted by the script once enrolled
/var/lib/netbird/default.jsonnetbird—read: .ManagementURL.Host, for legacy-install detection
/var/lib/netbird/active_profile.jsonnetbird—read: .name, holding the active profile's identifier

The script creates nothing, opens no socket, and writes no file. The only write it performs is the deletion of the key.

meson.build installs the whole of scripts/ into /usr/bin with the directory stripped, so every file added there becomes a command on the Brain.

Commands it invokes ​

CommandWhenFailure is
jq -r .ManagementURL.Host /var/lib/netbird/default.jsonif that file existstolerated (|| true)
systemctl show netbird --property=Environmentevery run past step 1tolerated (guard condition)
netbird service reconfigure --service-env NB_DISABLE_SSH_CONFIG=trueonly when the setting is missingfatal
netbird status --jsonevery run past step 2tolerated; an empty result is a documented case
netbird profile list [--show-id]when enrolment is neededthe --show-id probe is the client-generation test
netbird profile add eaglewhen no eagle profile existsfatal
jq -r .name /var/lib/netbird/active_profile.jsonnewer clients onlytolerated (|| true)
netbird profile remove <id>per surplus duplicatetolerated (|| true)
netbird profile select <id|eagle>when enrolment is neededfatal
netbird up --management-url … --setup-key-file … $NETBIRD_OPTSwhen enrolment is neededfatal

set -e is in force, so "fatal" means the script exits with that command's own status.

Network ​

EndpointProtocolPurpose
eagle.muxen.fr:443HTTPSNetBird management server: enrolment and management connection

That is the only endpoint named anywhere in this package. Peer-to-peer traffic between enrolled devices is arranged by NetBird itself and is outside the scope of this manual.

systemd ​

Unit muxen-eagle.service:

DirectiveValue
DescriptionMuxen Eagle Init
PartOfmuxen.target
After / Wantsnetwork-online.target
ConditionHost!bali-58-999
StartLimitIntervalSec / StartLimitBurst0 / 0 — rate limiter disabled
ExecStart/usr/bin/muxen-eagle-init
Typeoneshot, RemainAfterExit=yes
Restarton-failure, RestartSec=300
RestartPreventExitStatus78
User / Grouproot / root
WantedBymuxen-deploy.target

Notes:

  • Runs as root. It reads a 0600 key, reconfigures another system service and drives a privileged VPN client. The unit carries no hardening stanza.
  • WantedBy=muxen-deploy.target is what schedules the first run: the package installs the unit without starting it, so enrolment follows the boat's deployment rather than the apt install.
  • PartOf=muxen.target means a restart of that target stops this unit; the deploy target then pulls it back up, which is how a muxen-restart-target trigger re-runs it.
  • ConditionHost=!bali-58-999 skips the unit on that one host. systemd reports the start job as successful and the script does not execute.

Packaging ​

FieldValue
Source / binary packagemuxen-eagle
Architectureall, Multi-Arch: foreign
Section / Prioritylibs / optional
Pre-Dependsnetbird (>= 0.28.8)
Depends${misc:Depends}, apt, jq, bash (>= 5.0)
Build-Dependsdebhelper-compat (= 13), cmake, meson
Triggeractivates muxen-restart-target
Rules-Requires-Rootno

The netbird floor of 0.28.8 is the version that accepts --setup-key-file.

Packaging behaviour worth knowing:

RuleEffect
dh_installsystemd --no-startthe unit is enabled but not started at install time
execute_after_dh_auto_installwrites /etc/muxen/eagle.key from $SETUP_KEY; fails a tag build if unset; ships an empty key otherwise
override_dh_fixpermsexcludes the key so its 0600 survives
execute_after_dh_installdebremoves the key from DEBIAN/conffiles, and drops the file if it ends up empty

Two lintian overrides record the intent: file-in-etc-not-marked-as-conffile and non-standard-file-perm 0600, both on etc/muxen/eagle.key.

Build ​

sh
meson setup build
meson install -C build --destdir /tmp/stage
sh
make deb

make deb runs dpkg-buildpackage -us -uc -b followed by dh_clean. There is nothing to compile: meson.build installs the scripts/ directory into /usr/bin and delegates the unit to service/meson.build, which resolves the systemd unit directory from systemd.pc and normalises a /lib/... answer to /usr/lib/... so the staged tree matches on both bookworm and trixie.

A locally built package has no setup key unless $SETUP_KEY is exported into the build environment — see The setup key.

Integration of multiplexed solutions
MUXEN and the MUXEN logo are trademarks of MUXEN SAS.