Read what conflux says, then do what it names
Conflux names the cause of almost every refusal, and the way out of most. This page is the reading guide: what conflux status reports, what each message means, and where to look when a machine is up and still reaches nothing.
Reading conflux status
Start here. sudo conflux status prints conflux's own state and anchorctl status beneath it. Conflux decides the mode, the taints it asked for, the IPv4, the subnets, the proxies, the exits, the medium, where the files live and when to renew. The anchor underneath decides everything else: every packet, every route, every credential check.
$ sudo conflux status conflux 1.0.0-pre (f47de0fac83d24489664ca15fc6a317ac9c9f683) linux/amd64 service active (systemd: conflux.service, enabled at boot) mode tun — interface anchor0 taint brhk-2mq9-tzva-6pjs-k4xe-nw7d-qf ipv4 10.128.0.1/24 anchor anchor6btpa3gn6w4stipba4hekzho7caw6srfyy5puvbz7mfanaiept5a credential valid until 2026-10-06T06:35:43Z (8d 4h) renewal failing since 2026-09-26T08:10:00Z: dial tcp: no route to host api https://api.veilnet.com.au telemetry none — nothing is exported until an endpoint is set
| Line | What it says |
|---|---|
taint | The set in conflux.json, which mirrors what the credential grants, or none: the realm's default compartment for an issued credential granting none. A member's Taints order may have moved the running anchor since, and that does not show here: anchor reports no live set locally. |
refused | The machine is configured for taints its credential does not grant, which every start refuses for good. It names the set granted and the set configured, and the way out. |
credential | valid until …, EXPIRED …, or none — nothing enrolled yet on a machine that has never reached the API. |
renewal | failing since … and the last error. While the credential is valid this is a warning, retried every minute. |
clock | How far the clock was from the API's at the last call, when more than a second. Past ten minutes it says to fix the clock. See Clock skew. |
forwarding | The networks this machine forwards for the realm. When a member's Subnets order replaced conflux.json's list, one line says whose order it was, with set by an order from anchor… at …, and that --subnet or --no-subnet sets it again. |
exit | Present only when this machine is an exit one way or the other. |
uplink | On a machine on a link, the reopen tally. See Uplink. |
binaries | stale after an upgrade, until sudo conflux start restarts onto the new build. |
The DATA column
sudo conflux peers lists each peer the anchor knows, and its DATA column says whether the two may exchange data. It is the first thing to check when two machines are up and cannot see each other, after giving them a minute: peers find each other by gossip, in fifteen to sixty seconds.
$ sudo conflux peers ANCHOR OVERLAY IPV4 HARDWARE STATE CONN DATA REACH RTT i46dpakhug fd80:c4b9:99ae:df9b:5261:d178:18f1:783c 10.128.0.2 ae:70:60:82:85:68 connected out*,in yes nat-cone 990µs s5g3oefl2s fd80:c4b9:99ae:a015:58f1:5b6e:b140:5e8e - 5a:f0:a9:da:4e:32 connected out no unknown 1.2ms
DATA noon a peer that should be reachable is taint separation, working as designed. Two anchors exchange data only if one carries every taint the other does, so{office,laptop}and{office,desktop}cannot talk. Compare both machines'taintlines character for character. A credential's taints never change, so a machine enrolled in the wrong one needs a new identity:sudo conflux uninstall --yes, thensudo conflux up --taintwith the right one. A member's Taints order may also have moved one of them, which status does not show.DATA noon every peer can also mean this machine is blocked. A block leaves the anchor running, outside its realm, and every member treats it as an outsider.sudo conflux blockson another member lists the blocks in force, and nothing on this machine needs doing once it is lifted.- A peer that is not listed at all has not been seen yet. If one machine has no peers, it has not reached the bootstrap node, which is a network problem rather than a conflux one.
- A peer that is
connected, showsDATA yesand an RTT, while every ping times out, is the host's routing table: nothing sends overlay addresses to the overlay interface. Check withip routeon Linux,netstat -rnon macOS orroute printon Windows. anchor installs those routes itself, so one routed elsewhere is worth reporting to anchor with that output.
EXPIRED
credential EXPIRED means renewal has been failing for longer than the credential had left, and the renewal line beneath it names the last error. A running anchor stays up with every handshake refused. A restarted one does not start at all, since anchor will not build an anchor on an expired credential, so the supervisor keeps retrying with a backoff up to thirty seconds, renewing first each time.
It recovers on its own once a renewal gets through. The renewal route works after expiry, so a machine that was off for a month renews on its next start and keeps its AnchorID and its address. Conflux never re-enrols to work around a failed renewal, because that would draw a new identity and orphan every peer. The exception is a fixed-term credential, which names nowhere to renew: once it has expired it has to be replaced, and the unit shows as failed until it is.
Errors and what they mean
The messages below are quoted as conflux prints them, with … where it names the value at fault. Most go on to say what to type next.
| Message | Cause | What to do |
|---|---|---|
nothing is running here | No daemon on the socket. | sudo conflux start if a configuration exists, otherwise conflux up or conflux proxy. |
… needs root | Every command that changes the machine needs it. On Windows it says … needs Administrator. | Run the command it names, flags and all, with sudo or from an elevated PowerShell. |
status exits 78 | The machine was never configured. | conflux up or conflux proxy. |
has not been given an IPv4 yet and there is no terminal to ask at | up or proxy in a script, on a machine never asked. | Pass --ipv4 ADDRESS or --no-ipv4. |
no port specs given, and nothing else to serve | conflux proxy with no spec, no --subnet and no --serve-exit. | Give it something to offer: a spec such as 8080=127.0.0.1:3000, or a network or an exit to route. |
"-add" is not one of conflux proxy's flags | anchorctl's proxy was meant. | sudo conflux anchorctl proxy -add … |
"-identity" is anchorctl's start | anchorctl's flags given to conflux start, which takes none. | sudo conflux anchorctl start … |
the service started but no anchor came up within 90s | The supervisor is running and the anchor is not. | The message names the log to read. Then see Service and logs. |
| Message | Cause | What to do |
|---|---|---|
is not a unicast address a host sends from | A loopback, link-local, multicast or broadcast IPv4. | Any address a host could send from is accepted. |
is inside 198.18.0.0/15 | anchor answers the IPv4 peers it translates for from that range, and will not send from it. | Pick an address outside it. |
a reverse proxy needs userspace mode | A proxy spec in a configuration whose mode is tun. | The modes are exclusive: run conflux proxy, or bind the service on the overlay address. |
taint … contains a comma | A comma-separated list passed to --taint. | Use --taint once per label. |
taint … has '@' | Or '+'. Those bind a forwarded network to compartments, as SUBNET@a+b, so no taint may hold them. Nor may a space or a character that does not print. | Pick a name without them. |
this machine's credential grants … | --taint or conflux.json names a set the credential does not grant. | Keep the taints it grants, or draw a new identity as the message says: conflux uninstall --yes, then conflux up --taint. |
subnet … is not a private network | A public prefix. | anchor forwards private networks only; reaching the internet is what an exit is for. |
subnet … has host bits set | 192.168.1.7/24, say. | Write the network, 192.168.1.0/24, which the message suggests. |
subnet … is bound to …, which this machine is not in | A SPEC@taint binding names a taint this machine's credential does not grant. | Bind only to the machine's own taints. A machine with none can bind nothing. |
the control socket path is N bytes | CONFLUX_DIR is too deep for a Unix socket. | Use a shorter one; the kernel's limit is 104 to 108 bytes. |
fd:3 adopts a descriptor … | --uplink fd:N. conflux's supervisor starts anchord with no descriptor to adopt. | Name the device, or drive anchor yourself with conflux anchorctl start -uplink fd:3. |
anchor has no way to open a link on Windows | --uplink on Windows. | An uplink is Unix only. |
| Message | Cause | What to do |
|---|---|---|
the anchor binaries were extracted to … but will not run from there | The filesystem is mounted noexec, SELinux refuses a binary labelled var_lib_t, or on Windows endpoint protection has quarantined it. | The message says which. For noexec, set CONFLUX_DIR to a filesystem that allows execution; for SELinux, run the semanage and restorecon commands it prints. On macOS, killed: 9 instead means the signature was rejected. |
… does not grant this anchor's taints | From anchord: the manifest names taints its chain does not commit to. The issuer's mistake, which no retry changes, so the supervisor gives up. | Ask the issuer for a new credential. |
this host will not give this process a TUN device | From anchord: no capability or device, the interface name held by another, or a host booted without IPv6, which every overlay address needs. | Grant the capability, pick another --interface, or run conflux proxy, which needs no interface and no IPv6 on the host. |
this host could not be set up to forward for the realm | From anchord, on Linux with an interface and --subnet or --serve-exit: no nft and no iptables with ipset, or a /proc/sys it cannot write. | Install one of them, or start the container with forwarding already on. A userspace router needs neither. |
this machine's clock is … away from the server's | The clock is more than ten minutes from the API's. | Fix NTP first; nothing connects until then. See Clock skew. |
the credential expired …, and anchor will not start on an expired one | conflux enrol given a credential past its expiry. | Get a fresh one from its issuer. |
the manifest says renewalAuth … and carries no renewalUrl | A document that says how to authenticate a renewal and not where to send one. | The issuer has to set it. |
Bootstrap failed: 5: Input/output error | macOS, on up or install after an uninstall. launchd reports most refusals as error 5, which names nothing. | Conflux enables the label before every bootstrap, so the cause is one of the others the message lists: the plist is not root-owned or is group- or world-writable, the job is already loaded (sudo launchctl bootout system/org.veilnet.conflux), or the executable it names is gone or on a volume not mounted yet. |
Uplink
On a machine with an uplink, conflux status shows the link and no underlay address. That is correct and not the fault: an anchor on a cable advertises no way to be reached, because a cable has none. When such a machine is up and reaches nothing, check in this order.
- Both ends are on the link. One link carries one peer, and both ends have to be brought up with --uplink; an anchor on a socket and one on a cable have no medium in common.
- The line speed is set, and matches, on both ends. A device opened without a speed is left as it is, so one configured elsewhere at 9600 stays there.
/dev/ttyUSB0:115200sets it. A handshake is twenty to thirty kilobytes, comfortable at 115200 and marginal at 9600 against a sixty-second idle timeout. - The machine was ever enrolled. Enrolment is an HTTPS call the link cannot carry, and one that has only seen the cable says
credential none — nothing enrolled yet. Bring it up once where it has the internet. - The credential has not lapsed. Renewal needs the same API, so a machine permanently on a cable stops being admitted thirty days after its last renewal, and status says
credential EXPIRED.
A link that ends is reopened
anchor does not reopen a device, so conflux watches it. A device that leaves the filesystem is acted on at once, and a link that has carried nothing for ninety seconds is treated as ended. Either way the anchor is rebuilt on it, with the identity unchanged, and repeated failures back off from one second to thirty. Status keeps the tally, because the anchor's own uptime resets on every reopen:
$ sudo conflux status uplink 7 reopens, last 2026-09-08T11:04:12Z
Seven reopens is a cable, a connector or a far end at fault, which conflux is papering over rather than fixing. A link that keeps reopening and never stays up usually has a far end that is not running: an idle link whose far end is switched off looks exactly like a dead one, and is restarted on the same ninety-second grace. The grace is that long because an anchor holding no connection redials every five seconds or so, a dial that never answers takes its whole 45-second timeout, and a handshake on the slowest line conflux accepts takes about 25. To force a reopen by hand, run sudo conflux start.
Windows
- Every command that changes the machine needs an elevated PowerShell, and says
… needs Administratorwithout one. conflux upneedswintun.dll, which conflux fetches the first time a TUN machine needs it and again at any start that finds it missing, after an upgrade say. Offline, it says what to do by hand, and names the way round it.
conflux: a network interface on Windows needs wintun.dll, and it could not be fetched: …
Download wintun-0.14.1.zip from https://www.wintun.net and put
bin\amd64\wintun.dll at:
C:\ProgramData\conflux\bin\998ece52739a7c74\wintun.dll
Or run "conflux proxy PORT=BACKEND", which needs no interface at all- The archive is checked against a pinned SHA-256, and a mismatch aborts, printing both digests. Userspace mode needs no driver, so on a machine where Wintun cannot be installed,
conflux proxyis a complete way to use the overlay. - When the extracted binaries will not run, conflux names endpoint protection as the likely cause. Compare the digests
conflux versionprints with the release notes, and if an exclusion is needed, the directory is%ProgramData%\conflux\bin. - Conflux gives
%ProgramData%\confluxto SYSTEM and Administrators, and refuses a directory another account made there first, saying which. Remove it and run the command again as Administrator. --uplinkis refused: anchor has no way to open a link on Windows.- The service is
conflux, displayed asVeilNet Conflux, and has no console, so it writes what it and anchord say to%ProgramData%\conflux\logs\conflux.log.
Service and logs
| Platform | Read the last fifty lines |
|---|---|
| Linux | journalctl -u conflux -n 50 |
| macOS, FreeBSD | tail -n 50 /var/log/conflux.log |
| OpenBSD | grep conflux /var/log/daemon | tail -n 50 |
| Windows | Get-Content -Tail 50 "C:\ProgramData\conflux\logs\conflux.log" |
A start that times out names the right one for the machine. When the service starts and the anchor does not, stop the service and run the supervisor in the foreground. anchord's own lines are prefixed anchord:, so its reason for a refusal is printed in its own words.
$ sudo systemctl stop conflux $ sudo conflux serve --foreground
How the supervisor restarts
- A failed start is retried with a backoff up to thirty seconds, which is what lets a
--subnetwhose interface is not up yet come right at boot. - What no retry changes stops the supervisor after three attempts, with exit 70: a configuration or manifest conflux refuses, taints the credential does not grant among them, a credential expired with nowhere to renew it, one for a realm tree other than the one these binaries are pinned to, a TUN the host will not give, a host that will not be set up to forward, and an argument anchorctl refuses. Nothing to start at all is exit 78. systemd and Windows leave the service down on either, and launchd starts it again after its throttle interval.
- Anything else it stops on, such as an extraction onto a full disk, exits 1, which a service manager restarts.
- While it runs, it asks the daemon every thirty seconds whether it still holds an anchor, every ten through the link watcher on an uplink, and rebuilds it if not. A rebuild refused for good three times in a row, as after a
conflux.jsonedited into one that will not build, makes the watcher give up and say so in the log. The service stays up holding no anchor untilsudo conflux startor a reboot. - A blocked anchor is not rebuilt. A block leaves it running, outside its realm, and rebuilding it would change nothing.
Clock skew
Three separate things break on a bad clock, and only one of them says so.
- A credential starts at the moment its issuer signs it, and anchor refuses one that starts more than ten minutes after its own clock says now. A machine ten minutes slow cannot start on a credential it has just been issued or renewed, and the refusal names the credential rather than the clock.
- anchor's handshake tag rotates hourly and a peer accepts one epoch either side, so two machines two hours apart cannot connect at all. The symptom is a TLS alert that looks exactly like a wrong realm.
- A clock weeks fast makes a current credential look expired, and one a year slow makes an expired one look fine.
So conflux compares the API's Date header with the local clock on every call, records the skew, and refuses to bring a machine up when it exceeds ten minutes, anchor's own allowance and the tightest of the three, naming NTP. The measurement is taken on the calls that reach the API, enrolling and renewing. A start whose credential is current makes none, unless the last measurement was over the limit, in which case it renews to measure again rather than trust a figure from before the clock was fixed. conflux status prints the last skew when it is more than a second.
$ sudo timedatectl set-ntp true $ sudo conflux start