Linux

Where Does Nebula Store Its Config?

Nebula reads config.yml plus three credential files per node. Debian and Ubuntu packages expect them under /etc/nebula.

Last updated

Nebula keeps per-node config in config.yml: PKI paths, lighthouse map, listen port, firewall rules, and tun settings. Credentials travel beside it as ca.crt, host.crt, and host.key. The example file points all three at /etc/nebula, and distro packages plus the systemd template ([email protected]) assume that directory.

Key handling matters more than paths. Generate the CA once, sign each host, and distribute only what each node needs. The ca.key file never belongs on a node; anyone holding it can mint trusted hosts. SIGHUP reloads credentials without dropping tunnels, which makes cert rotation painless when planned and painful when certs simply expire unnoticed.

Where Nebula stores this, by platform

Linux
/etc/nebula/config.yml

PKI block, lighthouse map, firewall, tun. Credentials (ca.crt, host crt/key) sit beside it by convention. Systemd template [email protected] enables per-file units like nebula@office.

Frequently asked questions

how do i move nebula to a new machine

Copy ca.crt plus the host crt, key, and config.yml to the replacement with nebula stopped. Never copy ca.key to nodes; it signs certificates and belongs offline. Restart the nebula@unit or service after.

how long do nebula certificates last

By default CAs live about a year, and host certs expire with them. Use nebula-cert print to check dates, rotate with fresh sign calls, and redistribute. Expired nodes fail handshakes with no other symptom.

Notice an outdated path? Let us know.