Skip to main content

NFT000 - nft Command Not Available

Agent error code #NFT000 indicates that the agent could not run the nft binary on the host it is running on. The nftables backend drives the kernel ruleset by shelling out to nft, so without that binary no grant can be applied.

The agent reports this when it runs nft --version and the command does not exist or will not start. It is raised by Validate connection on the knoc, and by the capability probe the agent runs when it registers with the server, which is why the nftables option can be missing from the knoc wizard on a host that has not installed the package.

Two neighboring outcomes have their own reports. An nft that is installed but does not answer in time is reported as a timeout rather than as this code, and an nft that runs while the set listing fails is #NFT400.

Common causes include:

  • The nftables package is not installed on the agent host
  • nft is installed outside the PATH the agent process was started with
  • The agent runs in a minimal container image that omits the userspace tools

Steps to Resolve

Install the nftables Userspace Tools

  1. On Debian or Ubuntu, run sudo apt install nftables
  2. On RHEL, Rocky or Alma, run sudo dnf install nftables
  3. Confirm the binary responds: nft --version

Check the Agent's PATH

The agent resolves nft against the PATH its own process inherited from the service manager, not the one in your login shell.

  1. Find the binary: command -v nft. It is normally /usr/sbin/nft, and /sbin/nft on hosts that do not merge sbin
  2. If it sits in a directory the service PATH does not include, add the directory in the unit file or symlink the binary into one that is already there
  3. Restart the agent so it picks up the change

Ask knocker What the Host Has

On the agent host:

knocker status nftables

The first line reports whether nft was found, and the command prints the next step for whatever it finds missing.

Confirm the Backend Type Suits the Host

The nftables backend manages named sets in the kernel ruleset. A host that filters with iptables and ipset should be configured as an IPSet knoc instead. See the backends chapter.