Document missing CLI flags and client environment variables (#687)

This commit is contained in:
Viktor Liu
2026-04-08 16:19:49 +02:00
committed by GitHub
parent 6755dbdb00
commit 5a575acdee
4 changed files with 444 additions and 70 deletions
+16
View File
@@ -242,6 +242,22 @@ The upload key is automatically copyable by clicking on it. Share this key throu
- Bundles are automatically uploaded to NetBird's secure storage (or your configured upload endpoint for self-hosted deployments)
- Upload keys expire after 30 days for security
### Tracing firewall rules
If a connection is being blocked and you suspect a policy issue, the `debug trace` command lets you simulate a packet through the firewall rules without sending real traffic. See the [CLI reference](/get-started/cli#debug-trace) for full usage and examples.
```shell
netbird debug trace in 100.64.1.1 self -p tcp --dport 80
```
<Note>
On Linux, the userspace packet filter is only active when the kernel firewall backend (nftables/iptables) is not available. `debug trace` is primarily useful on macOS and Windows.
</Note>
### Advanced environment variables
The client has environment variables for tuning routing, firewall behavior, ICE connectivity, and WireGuard mode. These can help work around edge cases (e.g. `NB_USE_LEGACY_ROUTING` for routing loop issues, `NB_WG_KERNEL_DISABLED` to force userspace WireGuard, `NB_SKIP_NFTABLES_CHECK` to fall back to iptables). See the full list at [Client Environment Variables](/client/environment-variables).
## Enabling debug logs on agent
Logs can be temporarily set using the following command.