Self-hosting
Run the NebulaCtrl control plane on your own Linux host, and see which parts you operate and which parts NebulaCtrl installs and runs on your clusters.
You run the control plane on one Linux host. NebulaCtrl installs and runs everything else on the clusters you connect. These pages cover the day-two work of the host: requirements, upgrades, backups, sign-in and removal.
What you run and what NebulaCtrl runs
| You operate | NebulaCtrl installs and runs |
|---|---|
| The control plane host. A Linux machine with Docker that runs the control plane container and, unless you bring your own, a PostgreSQL container with TimescaleDB. | On each cluster. K3s, the agent and its access broker, an in-cluster registry, rootless BuildKit build jobs, and a Traefik ingress. |
| The public URL. A DNS name, a TLS certificate and a reverse proxy in front of the control plane. | The mesh. A WireGuard network, nebula0, that every node of every cluster joins. All node-to-node traffic runs inside it. |
| The identity provider. An OpenID Connect provider. NebulaCtrl keeps no passwords. | On a cluster, on request. CloudNativePG, which runs your PostgreSQL database services, and the Tailscale operator, which exposes a service only through Tailscale. |
The master key and .env. They seal every stored secret. You back them up. | On a node. ufw rules, fail2ban, unattended upgrades and key-only SSH login when a key exists. |
| Backups of the control plane database. | On volumes. Backups to an object store you connect, when you ask for them. |
| The nodes. Linux machines that you give to clusters. |
The control plane never reaches into a cluster. Each agent dials the control plane, so a cluster needs no inbound rule for it. Details are in Requirements.
Choose a task
| I want to | Go to |
|---|---|
| Install the control plane | Install NebulaCtrl |
| Check my host, ports and DNS | Requirements |
| Move to a newer version, or go back | Upgrade the control plane |
| Back up or restore the control plane | Back up and restore the control plane |
| Change the master key | Rotate the master key |
| Set up OIDC sign-in or recover access | Set up sign-in and recover access |
| Remove the control plane | Uninstall the control plane |
| Lock the install down | Harden a production install |
Maturity
NebulaCtrl is in beta. Upgrades migrate your data in place and can be rolled back. The HTTP API and nebula.toml may still change before 1.0, and the changelog announces each change.