Linux Desktop App
On Linux, three packages give you a GTK4/libadwaita desktop app plus a background systemd service that does the actual work - no group membership or relogin needed, and no admin/root prompt for enrolling, starting/stopping, or accepting routes.
| Light | Dark |
|---|---|
![]() | ![]() |
What’s included:
- nebula-commander-client – The
ncclientCLI (frozen binary, no Python runtime needed). - nebula-commander-service – Installs
ncclient.service(systemd), which polls for config/certs and runs Nebula as root. Exposes a system D-Bus API (org.beardedtek.NebulaCommander1) that the desktop app talks to, authorized per-call via polkit for any active local session. - nebula-commander-desktop – The GTK4 app: enroll, view connection/service status, and accept or reject offered subnet routes and exit nodes.
Because authorization goes through polkit (allow_active=yes) instead of Unix group membership, the desktop app works immediately after install and login - there is no usermod/relogin step like older group-based designs.
Package repository (recommended)
Add the signed Nebula Commander repository once, and new releases arrive with your normal system updates (apt upgrade, dnf upgrade, zypper update). It carries the current and the previous few releases, for amd64 and arm64. Installing nebula-commander-desktop and nebula-commander-service pulls in nebula-commander-client.
Debian / Ubuntu:
sudo apt install -y curl
sudo install -d -m 0755 /etc/apt/keyrings
sudo curl -fsSL -o /etc/apt/keyrings/nebula-commander.asc https://pkgs.nebulacommander.com/gpg.key
sudo curl -fsSL -o /etc/apt/sources.list.d/nebula-commander.sources https://pkgs.nebulacommander.com/deb/nebula-commander.sources
sudo apt update
sudo apt install nebula-commander-desktop nebula-commander-service
Fedora / RHEL:
sudo curl -fsSL -o /etc/yum.repos.d/nebula-commander.repo https://pkgs.nebulacommander.com/rpm/nebula-commander.repo
sudo dnf install nebula-commander-desktop nebula-commander-service
openSUSE:
sudo zypper addrepo https://pkgs.nebulacommander.com/rpm/nebula-commander.repo
sudo zypper install nebula-commander-desktop nebula-commander-service
On a server without a desktop, install just nebula-commander-service. The repository metadata and the RPMs are signed with the key at pkgs.nebulacommander.com/gpg.key.
The packages below can also be installed directly, without adding the repository.
.deb (Debian, Ubuntu, and derivatives)
Download all three packages from the Client Download page or GitHub Releases, then install together so apt resolves the dependency order:
sudo apt install ./nebula-commander-client.deb ./nebula-commander-service.deb ./nebula-commander-desktop.deb
.rpm (Fedora, RHEL, and derivatives)
sudo dnf install ./nebula-commander-client.rpm ./nebula-commander-service.rpm ./nebula-commander-desktop.rpm
On openSUSE, use zypper instead:
sudo zypper install ./nebula-commander-*.rpm
Flatpak
The desktop app is also available as a Flatpak bundle. It is not yet published on Flathub, so install the bundle directly:
flatpak install --user ./org.beardedtek.NebulaCommander.flatpak
The Flatpak is the GUI only - it still needs nebula-commander-service (or an equivalent backend, such as the NixOS module) installed and running separately, since a sandboxed Flatpak cannot run Nebula or create a TUN device itself.
After install
- Open Nebula Commander from your application launcher.
- Go to the Enrollment tab and enter the server URL and the one-time code from Nebula Commander (Nodes → open the node → Enroll).
- The Status tab shows connection/service state and lets you start/stop/restart the service, view the generated
config.yaml, and accept or reject offered subnet routes and exit nodes.
See ncclient usage for the equivalent CLI-only steps, or Development: Manual builds to build these packages yourself.

