Skip to content
NebulaCtrldocs

Self-hosting

Run the NebulaCtrl control plane on your own Linux host, and see which parts you operate and which parts NebulaCtrl installs and runs on your clusters.

You run the control plane on one Linux host. NebulaCtrl installs and runs everything else on the clusters you connect. These pages cover the day-two work of the host: requirements, upgrades, backups, sign-in and removal.

What you run and what NebulaCtrl runs

You operateNebulaCtrl installs and runs
The control plane host. A Linux machine with Docker that runs the control plane container and, unless you bring your own, a PostgreSQL container with TimescaleDB.On each cluster. K3s, the agent and its access broker, an in-cluster registry, rootless BuildKit build jobs, and a Traefik ingress.
The public URL. A DNS name, a TLS certificate and a reverse proxy in front of the control plane.The mesh. A WireGuard network, nebula0, that every node of every cluster joins. All node-to-node traffic runs inside it.
The identity provider. An OpenID Connect provider. NebulaCtrl keeps no passwords.On a cluster, on request. CloudNativePG, which runs your PostgreSQL database services, and the Tailscale operator, which exposes a service only through Tailscale.
The master key and .env. They seal every stored secret. You back them up.On a node. ufw rules, fail2ban, unattended upgrades and key-only SSH login when a key exists.
Backups of the control plane database.On volumes. Backups to an object store you connect, when you ask for them.
The nodes. Linux machines that you give to clusters.

The control plane never reaches into a cluster. Each agent dials the control plane, so a cluster needs no inbound rule for it. Details are in Requirements.

Choose a task

I want toGo to
Install the control planeInstall NebulaCtrl
Check my host, ports and DNSRequirements
Move to a newer version, or go backUpgrade the control plane
Back up or restore the control planeBack up and restore the control plane
Change the master keyRotate the master key
Set up OIDC sign-in or recover accessSet up sign-in and recover access
Remove the control planeUninstall the control plane
Lock the install downHarden a production install

Maturity

NebulaCtrl is in beta. Upgrades migrate your data in place and can be rolled back. The HTTP API and nebula.toml may still change before 1.0, and the changelog announces each change.

On this page