A network configuration CLI for Linux with a systemctl-style interface. Links and addresses over netlink; systemd-networkd, systemd-resolved and systemd-hostnamed over D-Bus; declarative YAML/TOML apply with dry-run, profiles, history rollback, backups and doctor diagnostics.
Rust, async-first · 17 subcommands · Declarative YAML/TOML apply · History and rollback · TUI dashboard
📖 User docs — installation, declarative apply, and troubleshooting.
| When this happens… | netctl gives you… |
|---|---|
Every host change is a string of ip commands nobody can review |
netctl apply a YAML or TOML file, with --dry-run first and validate offline |
| A change goes wrong and nobody remembers the previous state | netctl history with rollback to an entry, plus named backup create / restore / export |
| You switch between known-good setups (lab, bench, maintenance) | netctl profile save, load, list and show, and diff a profile against current |
| "Is it the network or the host?" takes an hour | netctl doctor diagnostics and netctl test for connectivity, DNS and ping |
| Scripts scrape human-readable output | --json on show, JSON stats, and export to YAML, TOML or JSON |
| You want to watch interfaces while you work | netctl tui dashboard and netctl watch with a refresh interval |
| netctl | ip + networkctl (stock tools) | |
|---|---|---|
| Links and addresses | netctl link set, netctl addr add over rtnetlink |
ip link, ip addr over rtnetlink |
| systemd integration | networkd, resolved and hostnamed over D-Bus from one tool | networkctl, resolvectl, hostnamectl as separate tools |
| Declarative config | netctl apply YAML or TOML, --dry-run, validate |
.network / .netdev INI files written by hand |
| Undo | history rollback, named backups, saved profiles |
Not built in |
| Compare | diff profiles against the current state |
Not built in |
| Live view | tui dashboard, watch, stats |
ip monitor, networkctl status |
| Choose ip + networkctl when | You need the full iproute2 feature surface, or want nothing beyond the base system on the host |
Workspace crates: netctl (CLI), netctl-core, netctl-netlink, netctl-dbus, netctl-config, netctl-types.
Requires Rust 1.75+ to build, and root or CAP_NET_ADMIN to change the network.
git clone https://github.com/zyvorai/netctl.git
cd netctl
cargo build --release
sudo cp target/release/netctl /usr/local/bin/sudo netctl show
sudo netctl link set eth0 state up
sudo netctl addr add eth0 192.168.1.100/24
netctl show --jsonDeclarative apply:
sudo netctl apply config/network-config.example.yaml- Link, address, route, DNS, and hostname management
- Declarative YAML/TOML apply, profiles, backup/restore, diff, and
doctordiagnostics - JSON output, watch mode, TUI, shell completions, and dry-run previews
git clone https://github.com/zyvorai/netctl.git
cd netctl
cargo build --release
sudo cp target/release/netctl /usr/local/bin/Pre-built binaries: GitHub Releases.
Docker:
docker build -t netctl:latest .
docker run --rm netctl:latest --helpStatic musl build:
cargo install cross
cross build --release --target x86_64-unknown-linux-musl| File | Description |
|---|---|
| config/network-config.example.yaml | YAML network profile |
| config/network-config.example.toml | TOML network profile |
cargo test --workspace
cargo fmt --all -- --check
cargo clippy --workspace -- -D warnings- Network changes require root or
CAP_NET_ADMIN. - D-Bus features need
systemd-networkd,systemd-resolved, andsystemd-hostnamedrunning. - Debian/Ubuntu build deps:
sudo apt install libdbus-1-dev pkg-config
Issues and PRs: github.com/zyvorai/netctl.
| Community Edition (this repo) | Enterprise (zyvor.dev) | |
|---|---|---|
| Support | GitHub Issues | SLA, [email protected], professional services |
| Scope | CLI and declarative apply | Supported rollouts with netevd and cloud-netconfig |
| Platform | netctl | Full Zyvor networking and migration stack |
| Features | Link/address/route/DNS/hostname management, declarative YAML/TOML apply, doctor diagnostics, TUI, shell completions |
Same feature set, operated at fleet scale with SLA-backed support |
| Demo | zyvor.dev/demo |
| ROI | zyvor.dev/roi |
| Pricing | zyvor.dev/pricing |
| Contact | zyvor.dev/contact · [email protected] |
Community Edition covers CLI usage and declarative apply. Enterprise SLAs and the full stack with netevd and cloud-netconfig → contact Zyvor (not GitHub Issues). Details: docs/enterprise.md.
netctl Community Edition is free and open source, maintained by Susant Sahani · Zyvor AI Labs
- Enterprise / production: zyvor.dev/contact · [email protected]
- Demo and PoC: Book a demo · 30-day PoC
- Community help: GitHub Issues
netctl is at version 1.1.1 (workspace Cargo.toml), with pre-built binaries on GitHub Releases. The Community Edition covers CLI usage and declarative apply; supported fleet rollouts are an Enterprise engagement (docs/enterprise.md).
| Product | Role next to netctl |
|---|---|
| netctl | Network configuration CLI for Linux: netlink plus systemd over D-Bus |
| netevd | Pairs with netctl: turns netlink and opt-in eBPF events into hook scripts, policy routing, a REST API and metrics |
| cloud-netconfig | Pairs with netctl on cloud VMs: secondary IPs and policy routing from cloud metadata |
| Netra | Next to netctl: eBPF network observability and emergency network control for Linux and Kubernetes |
Enterprise rollouts cover netctl together with netevd and cloud-netconfig. All projects: zyvorai.
netctl is free and open source under the Apache License 2.0 (see NOTICE): use, modify and run it for personal, lab and commercial production use at no charge. That does not change.
Zyvor Enterprise adds what production teams ask for: supported releases, deployment and upgrade guidance, priority incident triage, a named technical contact and 24x7 critical intake. Plans and terms: docs/SUBSCRIPTION-MODEL.md · Pricing · [email protected].



