Commit Graph

3 Commits

Author SHA1 Message Date
mlsmaycon
ba3db38932 [client] Hint at sudo when the profile config is not readable
The agent-network commands dial management directly with the profile's
WireGuard key, and the default profile config is root-owned — running
unprivileged fails reading it. Surface a clear "re-run with sudo"
message instead of a bare permission error.

Linear: NET-1399
2026-08-04 08:48:48 +00:00
mlsmaycon
9169a36658 [management, client] Make the agent-network setup RPC provable at runtime
An Unimplemented answer to GetAgentNetworkSetup can only come from a
server binary compiled without the regenerated management proto — the
combined and management servers share the one registration path in
boot.go. Make that failure mode self-diagnosing:

- Log "ManagementService registered on gRPC server (agent-network
  setup RPC available)" at boot, so server logs prove which build is
  running.
- Have the CLI name the management URL it dialed in every error, and
  map Unimplemented to an actionable message including the binary
  check (grep -ac GetAgentNetworkSetup <server binary>).
- Pin the wire path with a round-trip test: a real gRPC server built
  from this tree routes the RPC through the NaCl envelope end to end.

Verified live: a combined server built from this branch answers an
unregistered probe with PermissionDenied "peer is not registered",
never Unimplemented.

Linear: NET-1399
2026-08-04 02:06:48 +00:00
mlsmaycon
74b2f5cf4f [client] Add netbird agent-network ls and env commands
Surface the caller-scoped Agent Network setup on the CLI. Both
commands dial management directly with the active profile's WireGuard
key — the same path foreground login uses — so no daemon proto or
engine wiring is needed for the proof of concept.

netbird agent-network ls prints the proxy endpoint, the authorized
providers, and the allowed models (--json for the raw response).

netbird agent-network env prints POSIX export lines for
Anthropic-compatible tools such as Claude Code, applied with
eval "$(netbird agent-network env)": ANTHROPIC_BASE_URL points at
the account's proxy endpoint and ANTHROPIC_AUTH_TOKEN carries a
placeholder (the proxy authenticates by tunnel peer and injects the
real upstream credentials). A model is never guessed: ANTHROPIC_MODEL
is exported only when exactly one model is allowed or --model pins
one; anything ambiguous is printed as comment lines instead.

"Not available for this peer" is an answer, not an error: both
commands exit 0 with a plain message (on stderr for env, keeping the
eval a harmless no-op).

Linear: NET-1399
2026-08-04 00:32:03 +00:00