Appearance
Reference
Everything muxen-eagle exposes, in tables.
Command
muxen-eagle-initIt takes no options and no arguments, and ignores anything passed to it. Every value it uses is either a constant in the script or read from the local NetBird client. It must run as root.
Constants
Fixed inside /usr/bin/muxen-eagle-init; changing one means shipping a new package.
| Name | Value | Used for |
|---|---|---|
MGMT_UP_URL | https://eagle.muxen.fr | the --management-url passed to netbird up |
MGMT_STATUS_URL | https://eagle.muxen.fr:443 | compared against .management.url from netbird status --json |
MGMT_HOST | eagle.muxen.fr:443 | compared against .ManagementURL.Host in the legacy profile file |
KEY_FILE | ${MUXEN_EAGLE_KEY_FILE:-/etc/muxen/eagle.key} | the setup key |
PROFILE | eagle | the NetBird profile name |
NETBIRD_OPTS | see below | appended to netbird up |
NETBIRD_OPTS:
--allow-server-ssh
--enable-ssh-local-port-forwarding
--enable-ssh-remote-port-forwarding
--enable-ssh-sftpEnvironment
| Variable | Default | Effect |
|---|---|---|
MUXEN_EAGLE_KEY_FILE | /etc/muxen/eagle.key | path of the setup key |
The systemd unit sets no environment and reads no environment file, so on a Brain the default always applies.
Messages
One line per run, and it identifies the outcome.
| Message | Stream | Exit |
|---|---|---|
Already connected using default profile (legacy install) | stdout | 0 |
Already connected to eagle | stdout | 0 |
Enrolled with eagle but not connected yet; leaving it to netbird | stdout | 0 |
netbird daemon not answering yet; will retry | stderr | 1 |
No setup key at <path> and not enrolled: cannot register with eagle | stderr | 78 |
A run that enrols the boat prints none of them; the output on that path is whatever netbird itself writes.
Exit codes
| Code | Meaning | Retried by the unit |
|---|---|---|
| 0 | enrolled during this run, or already enrolled | — |
| 1 | the netbird daemon did not answer; state unknown, so retryable | yes |
| 78 | EX_CONFIG — no usable setup key and not enrolled | no (RestartPreventExitStatus=78) |
| other | set -e propagated the status of a failing netbird, jq or systemctl command | yes |
Files
| Path | Owner | Mode | Content |
|---|---|---|---|
/usr/bin/muxen-eagle-init | package | 0755 | the script — the whole application |
/usr/lib/systemd/system/muxen-eagle.service | package | 0644 | the systemd unit |
/etc/muxen/eagle.key | package | 0600 root:root | the NetBird setup key. Not a conffile. Deleted by the script once enrolled |
/var/lib/netbird/default.json | netbird | — | read: .ManagementURL.Host, for legacy-install detection |
/var/lib/netbird/active_profile.json | netbird | — | read: .name, holding the active profile's identifier |
The script creates nothing, opens no socket, and writes no file. The only write it performs is the deletion of the key.
meson.build installs the whole of scripts/ into /usr/bin with the directory stripped, so every file added there becomes a command on the Brain.
Commands it invokes
| Command | When | Failure is |
|---|---|---|
jq -r .ManagementURL.Host /var/lib/netbird/default.json | if that file exists | tolerated (|| true) |
systemctl show netbird --property=Environment | every run past step 1 | tolerated (guard condition) |
netbird service reconfigure --service-env NB_DISABLE_SSH_CONFIG=true | only when the setting is missing | fatal |
netbird status --json | every run past step 2 | tolerated; an empty result is a documented case |
netbird profile list [--show-id] | when enrolment is needed | the --show-id probe is the client-generation test |
netbird profile add eagle | when no eagle profile exists | fatal |
jq -r .name /var/lib/netbird/active_profile.json | newer clients only | tolerated (|| true) |
netbird profile remove <id> | per surplus duplicate | tolerated (|| true) |
netbird profile select <id|eagle> | when enrolment is needed | fatal |
netbird up --management-url … --setup-key-file … $NETBIRD_OPTS | when enrolment is needed | fatal |
set -e is in force, so "fatal" means the script exits with that command's own status.
Network
| Endpoint | Protocol | Purpose |
|---|---|---|
eagle.muxen.fr:443 | HTTPS | NetBird management server: enrolment and management connection |
That is the only endpoint named anywhere in this package. Peer-to-peer traffic between enrolled devices is arranged by NetBird itself and is outside the scope of this manual.
systemd
Unit muxen-eagle.service:
| Directive | Value |
|---|---|
Description | Muxen Eagle Init |
PartOf | muxen.target |
After / Wants | network-online.target |
ConditionHost | !bali-58-999 |
StartLimitIntervalSec / StartLimitBurst | 0 / 0 — rate limiter disabled |
ExecStart | /usr/bin/muxen-eagle-init |
Type | oneshot, RemainAfterExit=yes |
Restart | on-failure, RestartSec=300 |
RestartPreventExitStatus | 78 |
User / Group | root / root |
WantedBy | muxen-deploy.target |
Notes:
- Runs as root. It reads a 0600 key, reconfigures another system service and drives a privileged VPN client. The unit carries no hardening stanza.
WantedBy=muxen-deploy.targetis what schedules the first run: the package installs the unit without starting it, so enrolment follows the boat's deployment rather than theapt install.PartOf=muxen.targetmeans a restart of that target stops this unit; the deploy target then pulls it back up, which is how amuxen-restart-targettrigger re-runs it.ConditionHost=!bali-58-999skips the unit on that one host. systemd reports the start job as successful and the script does not execute.
Packaging
| Field | Value |
|---|---|
| Source / binary package | muxen-eagle |
| Architecture | all, Multi-Arch: foreign |
| Section / Priority | libs / optional |
Pre-Depends | netbird (>= 0.28.8) |
Depends | ${misc:Depends}, apt, jq, bash (>= 5.0) |
Build-Depends | debhelper-compat (= 13), cmake, meson |
| Trigger | activates muxen-restart-target |
Rules-Requires-Root | no |
The netbird floor of 0.28.8 is the version that accepts --setup-key-file.
Packaging behaviour worth knowing:
| Rule | Effect |
|---|---|
dh_installsystemd --no-start | the unit is enabled but not started at install time |
execute_after_dh_auto_install | writes /etc/muxen/eagle.key from $SETUP_KEY; fails a tag build if unset; ships an empty key otherwise |
override_dh_fixperms | excludes the key so its 0600 survives |
execute_after_dh_installdeb | removes the key from DEBIAN/conffiles, and drops the file if it ends up empty |
Two lintian overrides record the intent: file-in-etc-not-marked-as-conffile and non-standard-file-perm 0600, both on etc/muxen/eagle.key.
Build
sh
meson setup build
meson install -C build --destdir /tmp/stagesh
make debmake deb runs dpkg-buildpackage -us -uc -b followed by dh_clean. There is nothing to compile: meson.build installs the scripts/ directory into /usr/bin and delegates the unit to service/meson.build, which resolves the systemd unit directory from systemd.pc and normalises a /lib/... answer to /usr/lib/... so the staged tree matches on both bookworm and trixie.
A locally built package has no setup key unless $SETUP_KEY is exported into the build environment — see The setup key.
