mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-05 00:15:26 -04:00
[GH-ISSUE #5230] #NetBird...." jq: parse error: Invalid numeric literal at line 55, column 38 " PROBLEME #11006
Open
opened 2026-08-05 01:28:07 -04:00 by saavagebueno
·
0 comments
No Branch/Tag Specified
main
claude/agent-network-test-cases-p743vw
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
No Label
triage-needed
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#11006
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Bor-vi on GitHub (Feb 1, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5230
Hello,
I am currently blocked while setting up NetBird self-hosted.
The configure.sh script consistently fails with a jq parsing error, and despite extensive debugging, I am unable to determine the root cause or even which generated file is invalid.
I am opening this issue to ask for help, as I do not have a solution at this point.
Error message
jq: parse error: Invalid numeric literal at line 55, column 38
Architecture (important)
My setup is distributed across multiple VMs:
VMreverseproxy
Runs Nginx Proxy Manager (NPM)
Acts as the only public entry point
Handles HTTPS and forwards traffic to internal services
VMdatabase
Runs Authentik
Used as the OIDC Identity Provider
Exposes:
https://authentik/./application/o/netbird/.well-known/openid-configuration
VMnetbird
Runs NetBird (self-hosted)
This is where configure.sh is executed
All VMs communicate over the internal network.
The OIDC endpoint is reachable from VMnetbird.
Environment
OS: Linux (Debian-based)
Shell: bash
NetBird: self-hosted
IDP: Authentik (on a separate VM)
Reverse proxy: Nginx Proxy Manager (on a separate VM)
Tools installed and verified:
curl
jq
envsubst
What I have verified
The OpenID configuration endpoint is reachable from VMnetbird
The endpoint returns valid JSON
openid-configuration.json downloaded by the script is valid
setup.env and base.setup.env are sourced correctly
All required NETBIRD_* variables are present
The script progresses normally until the very end
Where the script fails
The failure happens at this line:
envsubst <management.json.tmpl | jq . > artifacts/management.json
At this point:
jq reports a JSON parse error
No file path is mentioned
No variable name is mentioned
The script exits immediately
The generated (invalid) JSON is not preserved, so it cannot be inspected
Why I am blocked
The script dynamically builds JSON using environment variables (for example NETBIRD_IDP_MGMT_EXTRA_CONFIG) and injects them into templates via envsubst.
If any environment variable:
expands to invalid JSON
is empty when JSON is expected
contains characters that break JSON
is interpreted as a number instead of a string
then the final JSON becomes invalid and jq fails.
However:
I cannot see the generated JSON
I cannot map the reported line/column to a specific file
I cannot identify which variable is responsible
At this stage, I do not know what is wrong, only that jq fails.
What I am asking for
I am not proposing a fix, because I don’t know the cause.
I am asking for help with one of the following:
How to identify which generated file is invalid
Which variable is expected to be valid JSON
Whether this setup (NetBird + Authentik behind NPM on separate VMs) requires specific configuration
Whether additional debug output can be enabled
Any guidance to help diagnose this properly would be greatly appreciated.
Why I opened this issue
I am currently blocked and cannot proceed without understanding where this error comes from.
The script fails in a way that is very hard to diagnose from a user perspective.
Thank you for your help.
Generated by ChatGPT
getting-started.sh
management.json
configure.sh
docker-compose.yml
-----------------------------------------------------------------------dashboard.env--------------------------------------------------------------------
Endpoints
NETBIRD_MGMT_API_ENDPOINT=https://netbird.borghini-v.fr
NETBIRD_MGMT_GRPC_API_ENDPOINT=https://netbird.borghini-v.fr
OIDC - using embedded IdP
AUTH_AUDIENCE=netbird-dashboard
AUTH_CLIENT_ID=netbird-dashboard
AUTH_CLIENT_SECRET=
AUTH_AUTHORITY=https://netbird.borghini-v.fr/oauth2
USE_AUTH0=false
AUTH_SUPPORTED_SCOPES=openid profile email groups
AUTH_REDIRECT_URI=/nb-auth
AUTH_SILENT_REDIRECT_URI=/nb-silent-auth
SSL
NGINX_SSL_PORT=443
Letsencrypt
LETSENCRYPT_DOMAIN=none
----------------------------------------------------------------------setup.env-------------------------------------------------------------
example file, you can copy this file to setup.env and update its values
Image tags
you can force specific tags for each component; will be set to latest if empty
NETBIRD_DASHBOARD_TAG=""
NETBIRD_SIGNAL_TAG=""
NETBIRD_MANAGEMENT_TAG=""
COTURN_TAG=""
NETBIRD_RELAY_TAG=""
Dashboard domain. e.g. app.mydomain.com
NETBIRD_DOMAIN="netbird.borghini-v.fr"
TURN server domain. e.g. turn.mydomain.com
if not specified it will assume NETBIRD_DOMAIN
NETBIRD_TURN_DOMAIN=""
TURN server public IP address
required for a connection involving peers in
the same network as the server and external peers
usually matches the IP for the domain set in NETBIRD_TURN_DOMAIN
NETBIRD_TURN_EXTERNAL_IP=""
-------------------------------------------
OIDC
e.g., https://example.eu.auth0.com/.well-known/openid-configuration
-------------------------------------------
NETBIRD_AUTH_OIDC_CONFIGURATION_ENDPOINT="https://authentik.borghini-v.fr/application/o/netbird/.well-known/openid-configuration"
The default setting is to transmit the audience to the IDP during authorization. However,
if your IDP does not have this capability, you can turn this off by setting it to false.
#NETBIRD_DASH_AUTH_USE_AUDIENCE=false
NETBIRD_AUTH_AUDIENCE=""
e.g. netbird-client
NETBIRD_AUTH_CLIENT_ID="dKKmWyuUmy18OjMGAmx5m58y9sbs80EMAkAw4kCx"
indicates the scopes that will be requested to the IDP
NETBIRD_AUTH_SUPPORTED_SCOPES="openid profile email offline_access api"
NETBIRD_AUTH_CLIENT_SECRET is required only by Google workspace.
NETBIRD_AUTH_CLIENT_SECRET=""
if you want to use a custom claim for the user ID instead of 'sub', set it here
NETBIRD_AUTH_USER_ID_CLAIM=""
indicates whether to use Auth0 or not: true or false
NETBIRD_USE_AUTH0="false"
if your IDP provider doesn't support fragmented URIs, configure custom
redirect and silent redirect URIs, these will be concatenated into your NETBIRD_DOMAIN domain.
NETBIRD_AUTH_REDIRECT_URI="/auth"
NETBIRD_AUTH_SILENT_REDIRECT_URI="/silent-auth"
Updates the preference to use id tokens instead of access token on dashboard
Okta and Gitlab IDPs can benefit from this
NETBIRD_TOKEN_SOURCE="idToken"
-------------------------------------------
OIDC Device Authorization Flow
-------------------------------------------
NETBIRD_AUTH_DEVICE_AUTH_PROVIDER="none"
NETBIRD_AUTH_DEVICE_AUTH_CLIENT_ID="dKKmWyuUmy18OjMGAmx5m58y9sbs80EMAkAw4kCx"
NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE="dKKmWyuUmy18OjMGAmx5m58y9sbs80EMAkAw4kCx"
Some IDPs requires different audience, scopes and to use id token for device authorization flow
you can customize here:
NETBIRD_AUTH_AUDIENCE="dKKmWyuUmy18OjMGAmx5m58y9sbs80EMAkAw4kCx"
NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE=$NETBIRD_AUTH_AUDIENCE
NETBIRD_AUTH_DEVICE_AUTH_SCOPE="openid"
NETBIRD_AUTH_DEVICE_AUTH_USE_ID_TOKEN=false
-------------------------------------------
OIDC PKCE Authorization Flow
-------------------------------------------
Comma separated port numbers. if already in use, PKCE flow will choose an available port from the list as an alternative
eg. 53000,54000
NETBIRD_AUTH_PKCE_REDIRECT_URL_PORTS="53000"
-------------------------------------------
IDP Management
-------------------------------------------
eg. zitadel, auth0, azure, keycloak
NETBIRD_MGMT_IDP="authentik"
Some IDPs requires different client id and client secret for management api
NETBIRD_IDP_MGMT_CLIENT_ID="dKKmWyuUmy18OjMGAmx5m58y9sbs80EMAkAw4kCx"
NETBIRD_IDP_MGMT_EXTRA_USERNAME="NetBird"
NETBIRD_IDP_MGMT_EXTRA_PASSWORD="thatsecret"
NETBIRD_AUTH_PKCE_DISABLE_PROMPT_LOGIN=true
NETBIRD_IDP_MGMT_CLIENT_SECRET=""
Required when setting up with Keycloak "https://<YOUR_KEYCLOAK_HOST_AND_PORT>/admin/realms/netbird"
NETBIRD_IDP_MGMT_EXTRA_ADMIN_ENDPOINT=
With some IDPs may be needed enabling automatic refresh of signing keys on expire
NETBIRD_MGMT_IDP_SIGNKEY_REFRESH=false
NETBIRD_IDP_MGMT_EXTRA_ variables. See https://docs.netbird.io/selfhosted/identity-providers for more information about your IDP of choice.
-------------------------------------------
Letsencrypt
-------------------------------------------
Disable letsencrypt
if disabled, cannot use HTTPS anymore and requires setting up a reverse-proxy to do it instead
NETBIRD_DISABLE_LETSENCRYPT=false
e.g. hello@mydomain.com
NETBIRD_LETSENCRYPT_EMAIL="contact@borghini-v.fr"
-------------------------------------------
Extra settings
-------------------------------------------
Disable anonymous metrics collection, see more information at https://netbird.io/docs/FAQ/metrics-collection
NETBIRD_DISABLE_ANONYMOUS_METRICS=false
DNS DOMAIN configures the domain name used for peer resolution. By default it is netbird.selfhosted
NETBIRD_MGMT_DNS_DOMAIN=netbird.selfhosted
Disable default all-to-all policy for new accounts
NETBIRD_MGMT_DISABLE_DEFAULT_POLICY=false
-------------------------------------------
Relay settings
-------------------------------------------
Relay server domain. e.g. relay.mydomain.com
if not specified it will assume NETBIRD_DOMAIN
NETBIRD_RELAY_DOMAIN=""
Relay server connection port. If none is supplied
it will default to 33080
should be updated to match TLS-port of reverse proxy when netbird is running behind reverse proxy
NETBIRD_RELAY_PORT=""
Management API connecting port. If none is supplied
it will default to 33073
should be updated to match TLS-port of reverse proxy when netbird is running behind reverse proxy
NETBIRD_MGMT_API_PORT="443"
Signal service connecting port. If none is supplied
it will default to 10000
should be updated to match TLS-port of reverse proxy when netbird is running behind reverse proxy
NETBIRD_SIGNAL_PORT="443"
-------------------------------------------------------setup.env.example----------------------------------------------------------
example file, you can copy this file to setup.env and update its values
Image tags
you can force specific tags for each component; will be set to latest if empty
NETBIRD_DASHBOARD_TAG=""
NETBIRD_SIGNAL_TAG=""
NETBIRD_MANAGEMENT_TAG=""
COTURN_TAG=""
NETBIRD_RELAY_TAG=""
Dashboard domain. e.g. app.mydomain.com
NETBIRD_DOMAIN=""
TURN server domain. e.g. turn.mydomain.com
if not specified it will assume NETBIRD_DOMAIN
NETBIRD_TURN_DOMAIN=""
TURN server public IP address
required for a connection involving peers in
the same network as the server and external peers
usually matches the IP for the domain set in NETBIRD_TURN_DOMAIN
NETBIRD_TURN_EXTERNAL_IP=""
-------------------------------------------
OIDC
e.g., https://example.eu.auth0.com/.well-known/openid-configuration
-------------------------------------------
NETBIRD_AUTH_OIDC_CONFIGURATION_ENDPOINT=""
The default setting is to transmit the audience to the IDP during authorization. However,
if your IDP does not have this capability, you can turn this off by setting it to false.
#NETBIRD_DASH_AUTH_USE_AUDIENCE=false
NETBIRD_AUTH_AUDIENCE=""
e.g. netbird-client
NETBIRD_AUTH_CLIENT_ID=""
indicates the scopes that will be requested to the IDP
NETBIRD_AUTH_SUPPORTED_SCOPES=""
NETBIRD_AUTH_CLIENT_SECRET is required only by Google workspace.
NETBIRD_AUTH_CLIENT_SECRET=""
if you want to use a custom claim for the user ID instead of 'sub', set it here
NETBIRD_AUTH_USER_ID_CLAIM=""
indicates whether to use Auth0 or not: true or false
NETBIRD_USE_AUTH0="false"
if your IDP provider doesn't support fragmented URIs, configure custom
redirect and silent redirect URIs, these will be concatenated into your NETBIRD_DOMAIN domain.
NETBIRD_AUTH_REDIRECT_URI="/peers"
NETBIRD_AUTH_SILENT_REDIRECT_URI="/add-peers"
Updates the preference to use id tokens instead of access token on dashboard
Okta and Gitlab IDPs can benefit from this
NETBIRD_TOKEN_SOURCE="idToken"
-------------------------------------------
OIDC Device Authorization Flow
-------------------------------------------
NETBIRD_AUTH_DEVICE_AUTH_PROVIDER="none"
NETBIRD_AUTH_DEVICE_AUTH_CLIENT_ID=""
Some IDPs requires different audience, scopes and to use id token for device authorization flow
you can customize here:
NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE=$NETBIRD_AUTH_AUDIENCE
NETBIRD_AUTH_DEVICE_AUTH_SCOPE="openid"
NETBIRD_AUTH_DEVICE_AUTH_USE_ID_TOKEN=false
-------------------------------------------
OIDC PKCE Authorization Flow
-------------------------------------------
Comma separated port numbers. if already in use, PKCE flow will choose an available port from the list as an alternative
eg. 53000,54000
NETBIRD_AUTH_PKCE_REDIRECT_URL_PORTS="53000"
-------------------------------------------
IDP Management
-------------------------------------------
eg. zitadel, auth0, azure, keycloak
NETBIRD_MGMT_IDP="none"
Some IDPs requires different client id and client secret for management api
NETBIRD_IDP_MGMT_CLIENT_ID=$NETBIRD_AUTH_CLIENT_ID
NETBIRD_IDP_MGMT_CLIENT_SECRET=""
Required when setting up with Keycloak "https://<YOUR_KEYCLOAK_HOST_AND_PORT>/admin/realms/netbird"
NETBIRD_IDP_MGMT_EXTRA_ADMIN_ENDPOINT=
With some IDPs may be needed enabling automatic refresh of signing keys on expire
NETBIRD_MGMT_IDP_SIGNKEY_REFRESH=false
NETBIRD_IDP_MGMT_EXTRA_ variables. See https://docs.netbird.io/selfhosted/identity-providers for more information about your IDP of choice.
-------------------------------------------
Letsencrypt
-------------------------------------------
Disable letsencrypt
if disabled, cannot use HTTPS anymore and requires setting up a reverse-proxy to do it instead
NETBIRD_DISABLE_LETSENCRYPT=false
e.g. hello@mydomain.com
NETBIRD_LETSENCRYPT_EMAIL=""
-------------------------------------------
Extra settings
-------------------------------------------
Disable anonymous metrics collection, see more information at https://netbird.io/docs/FAQ/metrics-collection
NETBIRD_DISABLE_ANONYMOUS_METRICS=false
DNS DOMAIN configures the domain name used for peer resolution. By default it is netbird.selfhosted
NETBIRD_MGMT_DNS_DOMAIN=netbird.selfhosted
Disable default all-to-all policy for new accounts
NETBIRD_MGMT_DISABLE_DEFAULT_POLICY=false
-------------------------------------------
Relay settings
-------------------------------------------
Relay server domain. e.g. relay.mydomain.com
if not specified it will assume NETBIRD_DOMAIN
NETBIRD_RELAY_DOMAIN=""
Relay server connection port. If none is supplied
it will default to 33080
should be updated to match TLS-port of reverse proxy when netbird is running behind reverse proxy
NETBIRD_RELAY_PORT=""
Management API connecting port. If none is supplied
it will default to 33073
should be updated to match TLS-port of reverse proxy when netbird is running behind reverse proxy
NETBIRD_MGMT_API_PORT=""
Signal service connecting port. If none is supplied
it will default to 10000
should be updated to match TLS-port of reverse proxy when netbird is running behind reverse proxy
NETBIRD_SIGNAL_PORT=""
-----------------------------------------------------------nginx.tmpl.conf----------------------------------------------------------------------------------
This template enables proxying netbird behind Nginx.
To modify this template for your own use,
change the ports for the services, set your
server_name (e.g. vpn.example.com) and insert
your own ssl certificates
upstream dashboard {
# insert the http port of your dashboard container here
server 127.0.0.1:8011;
}
upstream signal {
# insert the grpc port of your signal container here
server 127.0.0.1:10000;
}
upstream management {
# insert the grpc+http port of your management container here
server 127.0.0.1:8012;
}
upstream relay {
# insert the port of your relay container here
server 127.0.0.1:33080;
}
server {
# HTTP server config
listen 80;
server_name _;
}
server {
# HTTPS server config
listen 443 ssl http2;
server_name _;
}
---------------------------------------------------------------------turnserver.conf.tmpl---------------------------------------------------
Coturn TURN SERVER configuration file
Boolean values note: where a boolean value is supposed to be used,
you can use '0', 'off', 'no', 'false', or 'f' as 'false,
and you can use '1', 'on', 'yes', 'true', or 't' as 'true'
If the value is missing, then it means 'true' by default.
Listener interface device (optional, Linux only).
NOT RECOMMENDED.
#listening-device=eth0
TURN listener port for UDP and TCP (Default: 3478).
Note: actually, TLS & DTLS sessions can connect to the
"plain" TCP & UDP port(s), too - if allowed by configuration.
listening-port=3478
TURN listener port for TLS (Default: 5349).
Note: actually, "plain" TCP & UDP sessions can connect to the TLS & DTLS
port(s), too - if allowed by configuration. The TURN server
"automatically" recognizes the type of traffic. Actually, two listening
endpoints (the "plain" one and the "tls" one) are equivalent in terms of
functionality; but Coturn keeps both endpoints to satisfy the RFC 5766 specs.
For secure TCP connections, Coturn currently supports SSL version 3 and
TLS version 1.0, 1.1 and 1.2.
For secure UDP connections, Coturn supports DTLS version 1.
tls-listening-port=5349
Alternative listening port for UDP and TCP listeners;
default (or zero) value means "listening port plus one".
This is needed for RFC 5780 support
(STUN extension specs, NAT behavior discovery). The TURN Server
supports RFC 5780 only if it is started with more than one
listening IP address of the same family (IPv4 or IPv6).
RFC 5780 is supported only by UDP protocol, other protocols
are listening to that endpoint only for "symmetry".
#alt-listening-port=0
Alternative listening port for TLS and DTLS protocols.
Default (or zero) value means "TLS listening port plus one".
#alt-tls-listening-port=0
Some network setups will require using a TCP reverse proxy in front
of the STUN server. If the proxy port option is set a single listener
is started on the given port that accepts connections using the
haproxy proxy protocol v2.
(https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt)
#tcp-proxy-port=5555
Listener IP address of relay server. Multiple listeners can be specified.
If no IP(s) specified in the config file or in the command line options,
then all IPv4 and IPv6 system IPs will be used for listening.
#listening-ip=172.17.19.101
#listening-ip=10.207.21.238
#listening-ip=2607:f0d0:1002:51::4
Auxiliary STUN/TURN server listening endpoint.
Aux servers have almost full TURN and STUN functionality.
The (minor) limitations are:
1) Auxiliary servers do not have alternative ports and
they do not support STUN RFC 5780 functionality (CHANGE REQUEST).
2) Auxiliary servers also are never returning ALTERNATIVE-SERVER reply.
Valid formats are 1.2.3.4:5555 for IPv4 and [1:2::3:4]:5555 for IPv6.
There may be multiple aux-server options, each will be used for listening
to client requests.
#aux-server=172.17.19.110:33478
#aux-server=[2607:f0d0:1002:51::4]:33478
(recommended for older Linuxes only)
Automatically balance UDP traffic over auxiliary servers (if configured).
The load balancing is using the ALTERNATE-SERVER mechanism.
The TURN client must support 300 ALTERNATE-SERVER response for this
functionality.
#udp-self-balance
Relay interface device for relay sockets (optional, Linux only).
NOT RECOMMENDED.
#relay-device=eth1
Relay address (the local IP address that will be used to relay the
packets to the peer).
Multiple relay addresses may be used.
The same IP(s) can be used as both listening IP(s) and relay IP(s).
If no relay IP(s) specified, then the turnserver will apply the default
policy: it will decide itself which relay addresses to be used, and it
will always be using the client socket IP address as the relay IP address
of the TURN session (if the requested relay address family is the same
as the family of the client socket).
#relay-ip=172.17.19.105
#relay-ip=2607:f0d0:1002:51::5
For Amazon EC2 users:
TURN Server public/private address mapping, if the server is behind NAT.
In that situation, if a -X is used in form "-X " then that ip will be reported
as relay IP address of all allocations. This scenario works only in a simple case
when one single relay address is be used, and no RFC5780 functionality is required.
That single relay address must be mapped by NAT to the 'external' IP.
The "external-ip" value, if not empty, is returned in XOR-RELAYED-ADDRESS field.
For that 'external' IP, NAT must forward ports directly (relayed port 12345
must be always mapped to the same 'external' port 12345).
In more complex case when more than one IP address is involved,
that option must be used several times, each entry must
have form "-X <public-ip/private-ip>", to map all involved addresses.
RFC5780 NAT discovery STUN functionality will work correctly,
if the addresses are mapped properly, even when the TURN server itself
is behind A NAT.
By default, this value is empty, and no address mapping is used.
external-ip=193.224.22.37
#OR:
#external-ip=60.70.80.91/172.17.19.101
#external-ip=60.70.80.92/172.17.19.102
$TURN_EXTERNAL_IP_CONFIG
Number of the relay threads to handle the established connections
(in addition to authentication thread and the listener thread).
If explicitly set to 0 then application runs relay process in a
single thread, in the same thread with the listener process
(the authentication thread will still be a separate thread).
If this parameter is not set, then the default OS-dependent
thread pattern algorithm will be employed. Usually the default
algorithm is optimal, so you have to change this option
if you want to make some fine tweaks.
In the older systems (Linux kernel before 3.9),
the number of UDP threads is always one thread per network listening
endpoint - including the auxiliary endpoints - unless 0 (zero) or
1 (one) value is set.
#relay-threads=0
Lower and upper bounds of the UDP relay endpoints:
(default values are 49152 and 65535)
min-port=$TURN_MIN_PORT
max-port=$TURN_MAX_PORT
Uncomment to run TURN server in 'normal' 'moderate' verbose mode.
By default the verbose mode is off.
#verbose
Uncomment to run TURN server in 'extra' verbose mode.
This mode is very annoying and produces lots of output.
Not recommended under normal circumstances.
#Verbose
Uncomment to use fingerprints in the TURN messages.
By default the fingerprints are off.
fingerprint
Uncomment to use long-term credential mechanism.
By default no credentials mechanism is used (any user allowed).
lt-cred-mech
This option is the opposite of lt-cred-mech.
(TURN Server with no-auth option allows anonymous access).
If neither option is defined, and no users are defined,
then no-auth is default. If at least one user is defined,
in this file, in command line or in usersdb file, then
lt-cred-mech is default.
#no-auth
TURN REST API flag.
(Time Limited Long Term Credential)
Flag that sets a special authorization option that is based upon authentication secret.
This feature's purpose is to support "TURN Server REST API", see
"TURN REST API" link in the project's page
https://github.com/coturn/coturn/
This option is used with timestamp:
usercombo -> "timestamp:userid"
turn user -> usercombo
turn password -> base64(hmac(secret key, usercombo))
This allows TURN credentials to be accounted for a specific user id.
If you don't have a suitable id, then the timestamp alone can be used.
This option is enabled by turning on secret-based authentication.
The actual value of the secret is defined either by the option static-auth-secret,
or can be found in the turn_secret table in the database (see below).
Read more about it:
- https://tools.ietf.org/html/draft-uberti-behave-turn-rest-00
- https://www.ietf.org/proceedings/87/slides/slides-87-behave-10.pdf
Be aware that use-auth-secret overrides some parts of lt-cred-mech.
The use-auth-secret feature depends internally on lt-cred-mech, so if you set
this option then it automatically enables lt-cred-mech internally
as if you had enabled both.
Note that you can use only one auth mechanism at the same time! This is because,
both mechanisms conduct username and password validation in different ways.
Use either lt-cred-mech or use-auth-secret in the conf
to avoid any confusion.
#use-auth-secret
'Static' authentication secret value (a string) for TURN REST API only.
If not set, then the turn server
will try to use the 'dynamic' value in the turn_secret table
in the user database (if present). The database-stored value can be changed on-the-fly
by a separate program, so this is why that mode is considered 'dynamic'.
#static-auth-secret=north
Server name used for
the oAuth authentication purposes.
The default value is the realm name.
server-name=stun.wiretrustee.com
Flag that allows oAuth authentication.
#oauth
'Static' user accounts for the long term credentials mechanism, only.
This option cannot be used with TURN REST API.
'Static' user accounts are NOT dynamically checked by the turnserver process,
so they can NOT be changed while the turnserver is running.
#user=username1:key1
#user=username2:key2
OR:
user=$TURN_USER:$TURN_PASSWORD
#user=username2:password2
Keys must be generated by turnadmin utility. The key value depends
on user name, realm, and password:
Example:
$ turnadmin -k -u ninefingers -r north.gov -p youhavetoberealistic
Output: 0xbc807ee29df3c9ffa736523fb2c4e8ee
('0x' in the beginning of the key is what differentiates the key from
password. If it has 0x then it is a key, otherwise it is a password).
The corresponding user account entry in the config file will be:
#user=ninefingers:0xbc807ee29df3c9ffa736523fb2c4e8ee
Or, equivalently, with open clear password (less secure):
#user=ninefingers:youhavetoberealistic
SQLite database file name.
The default file name is /var/db/turndb or /usr/local/var/db/turndb or
/var/lib/turn/turndb.
#userdb=/var/db/turndb
PostgreSQL database connection string in the case that you are using PostgreSQL
as the user database.
This database can be used for the long-term credential mechanism
and it can store the secret value for secret-based timed authentication in TURN REST API.
See http://www.postgresql.org/docs/8.4/static/libpq-connect.html for 8.x PostgreSQL
versions connection string format, see
http://www.postgresql.org/docs/9.2/static/libpq-connect.html#LIBPQ-CONNSTRING
for 9.x and newer connection string formats.
#psql-userdb="host= dbname= user= password= connect_timeout=30"
MySQL database connection string in the case that you are using MySQL
as the user database.
This database can be used for the long-term credential mechanism
and it can store the secret value for secret-based timed authentication in TURN REST API.
Optional connection string parameters for the secure communications (SSL):
ca, capath, cert, key, cipher
(see http://dev.mysql.com/doc/refman/5.1/en/ssl-options.html for the
command options description).
Use the string format below (space separated parameters, all optional):
mysql-userdb="host=mysql dbname=coturn user=coturn password=thatsecret port=3306 connect_timeout=10 read_timeout=10"
If you want to use an encrypted password in the MySQL connection string,
then set the MySQL password encryption secret key file with this option.
Warning: If this option is set, then the mysql password must be set in "mysql-userdb" in an encrypted format!
If you want to use a cleartext password then do not set this option!
This is the file path for the aes encrypted secret key used for password encryption.
#secret-key-file=/path/
MongoDB database connection string in the case that you are using MongoDB
as the user database.
This database can be used for long-term credential mechanism
and it can store the secret value for secret-based timed authentication in TURN REST API.
Use the string format described at http://hergert.me/docs/mongo-c-driver/mongoc_uri.html
#mongo-userdb="mongodb://[username:password@]host1[:port1][,host2[:port2],...[,hostN[:portN]]][/[database][?options]]"
Redis database connection string in the case that you are using Redis
as the user database.
This database can be used for long-term credential mechanism
and it can store the secret value for secret-based timed authentication in TURN REST API.
Use the string format below (space separated parameters, all optional):
#redis-userdb="ip= dbname= password= port= connect_timeout="
Redis status and statistics database connection string, if used (default - empty, no Redis stats DB used).
This database keeps allocations status information, and it can be also used for publishing
and delivering traffic and allocation event notifications.
The connection string has the same parameters as redis-userdb connection string.
Use the string format below (space separated parameters, all optional):
#redis-statsdb="ip= dbname= password= port= connect_timeout="
The default realm to be used for the users when no explicit
origin/realm relationship is found in the database, or if the TURN
server is not using any database (just the commands-line settings
and the userdb file). Must be used with long-term credentials
mechanism or with TURN REST API.
Note: If the default realm is not specified, then realm falls back to the host domain name.
If the domain name string is empty, or set to '(None)', then it is initialized as an empty string.
realm=wiretrustee.com
This flag sets the origin consistency
check. Across the session, all requests must have the same
main ORIGIN attribute value (if the ORIGIN was
initially used by the session).
#check-origin-consistency
Per-user allocation quota.
default value is 0 (no quota, unlimited number of sessions per user).
This option can also be set through the database, for a particular realm.
#user-quota=0
Total allocation quota.
default value is 0 (no quota).
This option can also be set through the database, for a particular realm.
#total-quota=0
Max bytes-per-second bandwidth a TURN session is allowed to handle
(input and output network streams are treated separately). Anything above
that limit will be dropped or temporarily suppressed (within
the available buffer limits).
This option can also be set through the database, for a particular realm.
#max-bps=0
Maximum server capacity.
Total bytes-per-second bandwidth the TURN server is allowed to allocate
for the sessions, combined (input and output network streams are treated separately).
bps-capacity=0
Uncomment if no UDP client listener is desired.
By default UDP client listener is always started.
#no-udp
Uncomment if no TCP client listener is desired.
By default TCP client listener is always started.
#no-tcp
Uncomment if no TLS client listener is desired.
By default TLS client listener is always started.
#no-tls
Uncomment if no DTLS client listener is desired.
By default DTLS client listener is always started.
#no-dtls
Uncomment if no UDP relay endpoints are allowed.
By default UDP relay endpoints are enabled (like in RFC 5766).
#no-udp-relay
Uncomment if no TCP relay endpoints are allowed.
By default TCP relay endpoints are enabled (like in RFC 6062).
#no-tcp-relay
Uncomment if extra security is desired,
with nonce value having a limited lifetime.
The nonce value is unique for a session.
Set this option to limit the nonce lifetime.
Set it to 0 for unlimited lifetime.
It defaults to 600 secs (10 min) if no value is provided. After that delay,
the client will get 438 error and will have to re-authenticate itself.
#stale-nonce=600
Uncomment if you want to set the maximum allocation
time before it has to be refreshed.
Default is 3600s.
#max-allocate-lifetime=3600
Uncomment to set the lifetime for the channel.
Default value is 600 secs (10 minutes).
This value MUST not be changed for production purposes.
#channel-lifetime=600
Uncomment to set the permission lifetime.
Default to 300 secs (5 minutes).
In production this value MUST not be changed,
however it can be useful for test purposes.
#permission-lifetime=300
Certificate file.
Use an absolute path or path relative to the
configuration file.
Use PEM file format.
cert=/etc/coturn/certs/cert.pem
Private key file.
Use an absolute path or path relative to the
configuration file.
Use PEM file format.
pkey=/etc/coturn/private/privkey.pem
Private key file password, if it is in encoded format.
This option has no default value.
#pkey-pwd=...
Allowed OpenSSL cipher list for TLS/DTLS connections.
Default value is "DEFAULT".
#cipher-list="DEFAULT"
CA file in OpenSSL format.
Forces TURN server to verify the client SSL certificates.
By default this is not set: there is no default value and the client
certificate is not checked.
Example:
#CA-file=/etc/ssh/id_rsa.cert
Curve name for EC ciphers, if supported by OpenSSL
library (TLS and DTLS). The default value is prime256v1,
if pre-OpenSSL 1.0.2 is used. With OpenSSL 1.0.2+,
an optimal curve will be automatically calculated, if not defined
by this option.
#ec-curve-name=prime256v1
Use 566 bits predefined DH TLS key. Default size of the key is 2066.
#dh566
Use 1066 bits predefined DH TLS key. Default size of the key is 2066.
#dh1066
Use custom DH TLS key, stored in PEM format in the file.
Flags --dh566 and --dh2066 are ignored when the DH key is taken from a file.
#dh-file=
Flag to prevent stdout log messages.
By default, all log messages go to both stdout and to
the configured log file. With this option everything will
go to the configured log only (unless the log file itself is stdout).
#no-stdout-log
Option to set the log file name.
By default, the turnserver tries to open a log file in
/var/log, /var/tmp, /tmp and the current directory
(Whichever file open operation succeeds first will be used).
With this option you can set the definite log file name.
The special names are "stdout" and "-" - they will force everything
to the stdout. Also, the "syslog" name will force everything to
the system log (syslog).
In the runtime, the logfile can be reset with the SIGHUP signal
to the turnserver process.
log-file=stdout
Option to redirect all log output into system log (syslog).
syslog
This flag means that no log file rollover will be used, and the log file
name will be constructed as-is, without PID and date appendage.
This option can be used, for example, together with the logrotate tool.
#simple-log
Option to set the "redirection" mode. The value of this option
will be the address of the alternate server for UDP & TCP service in the form of
[:]. The server will send this value in the attribute
ALTERNATE-SERVER, with error 300, on ALLOCATE request, to the client.
Client will receive only values with the same address family
as the client network endpoint address family.
See RFC 5389 and RFC 5766 for the description of ALTERNATE-SERVER functionality.
The client must use the obtained value for subsequent TURN communications.
If more than one --alternate-server option is provided, then the functionality
can be more accurately described as "load-balancing" than a mere "redirection".
If the port number is omitted, then the default port
number 3478 for the UDP/TCP protocols will be used.
Colon (:) characters in IPv6 addresses may conflict with the syntax of
the option. To alleviate this conflict, literal IPv6 addresses are enclosed
in square brackets in such resource identifiers, for example:
[2001:db8:85a3:8d3:1319:8a2e:370:7348]:3478 .
Multiple alternate servers can be set. They will be used in the
round-robin manner. All servers in the pool are considered of equal weight and
the load will be distributed equally. For example, if you have 4 alternate servers,
then each server will receive 25% of ALLOCATE requests. A alternate TURN server
address can be used more than one time with the alternate-server option, so this
can emulate "weighting" of the servers.
Examples:
#alternate-server=1.2.3.4:5678
#alternate-server=11.22.33.44:56789
#alternate-server=5.6.7.8
#alternate-server=[2001:db8:85a3:8d3:1319:8a2e:370:7348]:3478
Option to set alternative server for TLS & DTLS services in form of
:. If the port number is omitted, then the default port
number 5349 for the TLS/DTLS protocols will be used. See the previous
option for the functionality description.
Examples:
#tls-alternate-server=1.2.3.4:5678
#tls-alternate-server=11.22.33.44:56789
#tls-alternate-server=[2001:db8:85a3:8d3:1319:8a2e:370:7348]:3478
Option to suppress TURN functionality, only STUN requests will be processed.
Run as STUN server only, all TURN requests will be ignored.
By default, this option is NOT set.
#stun-only
Option to hide software version. Enhance security when used in production.
Revealing the specific software version of the agent through the
SOFTWARE attribute might allow them to become more vulnerable to
attacks against software that is known to contain security holes.
Implementers SHOULD make usage of the SOFTWARE attribute a
configurable option (https://tools.ietf.org/html/rfc5389#section-16.1.2)
no-software-attribute
Option to suppress STUN functionality, only TURN requests will be processed.
Run as TURN server only, all STUN requests will be ignored.
By default, this option is NOT set.
#no-stun
This is the timestamp/username separator symbol (character) in TURN REST API.
The default value is ':'.
rest-api-separator=:
Flag that can be used to allow peers on the loopback addresses (127.x.x.x and ::1).
This is an extra security measure.
(To avoid any security issue that allowing loopback access may raise,
the no-loopback-peers option is replaced by allow-loopback-peers.)
Allow it only for testing in a development environment!
In production it adds a possible security vulnerability, so for security reasons
it is not allowed using it together with empty cli-password.
#allow-loopback-peers
Flag that can be used to disallow peers on well-known broadcast addresses (224.0.0.0 and above, and FFXX:*).
This is an extra security measure.
#no-multicast-peers
Option to set the max time, in seconds, allowed for full allocation establishment.
Default is 60 seconds.
#max-allocate-timeout=60
Option to allow or ban specific ip addresses or ranges of ip addresses.
If an ip address is specified as both allowed and denied, then the ip address is
considered to be allowed. This is useful when you wish to ban a range of ip
addresses, except for a few specific ips within that range.
This can be used when you do not want users of the turn server to be able to access
machines reachable by the turn server, but would otherwise be unreachable from the
internet (e.g. when the turn server is sitting behind a NAT)
Examples:
denied-peer-ip=83.166.64.0-83.166.95.255
allowed-peer-ip=83.166.68.45
File name to store the pid of the process.
Default is /var/run/turnserver.pid (if superuser account is used) or
/var/tmp/turnserver.pid .
pidfile="/var/tmp/turnserver.pid"
Require authentication of the STUN Binding request.
By default, the clients are allowed anonymous access to the STUN Binding functionality.
#secure-stun
Mobility with ICE (MICE) specs support.
#mobility
Allocate Address Family according
If enabled then TURN server allocates address family according the TURN
Client <=> Server communication address family.
(By default Coturn works according RFC 6156.)
!!Warning: Enabling this option breaks RFC6156 section-4.2 (violates use default IPv4)!!
#keep-address-family
User name to run the process. After the initialization, the turnserver process
will attempt to change the current user ID to that user.
#proc-user=
Group name to run the process. After the initialization, the turnserver process
will attempt to change the current group ID to that group.
#proc-group=
Turn OFF the CLI support.
By default it is always ON.
See also options cli-ip and cli-port.
no-cli
#Local system IP address to be used for CLI server endpoint. Default value
is 127.0.0.1.
cli-ip=127.0.0.1
CLI server port. Default is 5766.
cli-port=5766
CLI access password. Default is empty (no password).
For the security reasons, it is recommended that you use the encrypted
form of the password (see the -P command in the turnadmin utility).
Secure form for password 'qwerty':
#cli-password=thatsecret
Or insecure form for the same password:
cli-password=thatsecret
Enable Web-admin support on https. By default it is Disabled.
If it is enabled it also enables a http a simple static banner page
with a small reminder that the admin page is available only on https.
#web-admin
Local system IP address to be used for Web-admin server endpoint. Default value is 127.0.0.1.
#web-admin-ip=127.0.0.1
Web-admin server port. Default is 8080.
#web-admin-port=8080
Web-admin server listen on STUN/TURN worker threads
By default it is disabled for security reasons! (Not recommended in any production environment!)
#web-admin-listen-on-workers
Server relay. NON-STANDARD AND DANGEROUS OPTION.
Only for those applications when you want to run
server applications on the relay endpoints.
This option eliminates the IP permissions check on
the packets incoming to the relay endpoints.
#server-relay
Maximum number of output sessions in ps CLI command.
This value can be changed on-the-fly in CLI. The default value is 256.
#cli-max-output-sessions
Set network engine type for the process (for internal purposes).
#ne=[1|2|3]
Do not allow an TLS/DTLS version of protocol
#no-tlsv1
#no-tlsv1_1
#no-tlsv1_2
-------------------------------------------------------------management.json.tmpl----------------------------------------------------------------------
{
"Stuns": [
{
"Proto": "udp",
"URI": "stun:$TURN_DOMAIN:3478",
"Username": "",
"Password": null
}
],
"TURNConfig": {
"Turns": [
{
"Proto": "udp",
"URI": "turn:$TURN_DOMAIN:3478",
"Username": "$TURN_USER",
"Password": "$TURN_PASSWORD"
}
],
"CredentialsTTL": "12h",
"Secret": "secret",
"TimeBasedCredentials": false
},
"Relay": {
"Addresses": ["$NETBIRD_RELAY_ENDPOINT"],
"CredentialsTTL": "24h",
"Secret": "$NETBIRD_RELAY_AUTH_SECRET"
},
"Signal": {
"Proto": "$NETBIRD_SIGNAL_PROTOCOL",
"URI": "$NETBIRD_DOMAIN:$NETBIRD_SIGNAL_PORT",
"Username": "",
"Password": null
},
"ReverseProxy": {
"TrustedHTTPProxies": [],
"TrustedHTTPProxiesCount": 0,
"TrustedPeers": [
"0.0.0.0/0"
]
},
"DisableDefaultPolicy": $NETBIRD_MGMT_DISABLE_DEFAULT_POLICY,
"Datadir": "",
"DataStoreEncryptionKey": "$NETBIRD_DATASTORE_ENC_KEY",
"StoreConfig": {
"Engine": "$NETBIRD_STORE_CONFIG_ENGINE"
},
"HttpConfig": {
"Address": "0.0.0.0:$NETBIRD_MGMT_API_PORT",
"AuthIssuer": "$NETBIRD_AUTH_AUTHORITY",
"AuthAudience": "$NETBIRD_AUTH_AUDIENCE",
"AuthKeysLocation": "$NETBIRD_AUTH_JWT_CERTS",
"AuthUserIDClaim": "$NETBIRD_AUTH_USER_ID_CLAIM",
"CertFile":"$NETBIRD_MGMT_API_CERT_FILE",
"CertKey":"$NETBIRD_MGMT_API_CERT_KEY_FILE",
"IdpSignKeyRefreshEnabled": $NETBIRD_MGMT_IDP_SIGNKEY_REFRESH,
"OIDCConfigEndpoint":"$NETBIRD_AUTH_OIDC_CONFIGURATION_ENDPOINT"
},
"IdpManagerConfig": {
"ManagerType": "$NETBIRD_MGMT_IDP",
"ClientConfig": {
"Issuer": "$NETBIRD_AUTH_AUTHORITY",
"TokenEndpoint": "$NETBIRD_AUTH_TOKEN_ENDPOINT",
"ClientID": "$NETBIRD_IDP_MGMT_CLIENT_ID",
"ClientSecret": "$NETBIRD_IDP_MGMT_CLIENT_SECRET",
"GrantType": "client_credentials"
},
"ExtraConfig": $NETBIRD_IDP_MGMT_EXTRA_CONFIG,
"Auth0ClientCredentials": null,
"AzureClientCredentials": null,
"KeycloakClientCredentials": null,
"ZitadelClientCredentials": null
},
"DeviceAuthorizationFlow": {
"Provider": "$NETBIRD_AUTH_DEVICE_AUTH_PROVIDER",
"ProviderConfig": {
"Audience": "$NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE",
"AuthorizationEndpoint": "",
"Domain": "$NETBIRD_AUTH0_DOMAIN",
"ClientID": "$NETBIRD_AUTH_DEVICE_AUTH_CLIENT_ID",
"ClientSecret": "",
"TokenEndpoint": "$NETBIRD_AUTH_TOKEN_ENDPOINT",
"DeviceAuthEndpoint": "$NETBIRD_AUTH_DEVICE_AUTH_ENDPOINT",
"Scope": "$NETBIRD_AUTH_DEVICE_AUTH_SCOPE",
"UseIDToken": $NETBIRD_AUTH_DEVICE_AUTH_USE_ID_TOKEN,
"RedirectURLs": null
}
},
"PKCEAuthorizationFlow": {
"ProviderConfig": {
"Audience": "$NETBIRD_AUTH_PKCE_AUDIENCE",
"ClientID": "$NETBIRD_AUTH_CLIENT_ID",
"ClientSecret": "$NETBIRD_AUTH_CLIENT_SECRET",
"Domain": "",
"AuthorizationEndpoint": "$NETBIRD_AUTH_PKCE_AUTHORIZATION_ENDPOINT",
"TokenEndpoint": "$NETBIRD_AUTH_TOKEN_ENDPOINT",
"Scope": "$NETBIRD_AUTH_SUPPORTED_SCOPES",
"RedirectURLs": [$NETBIRD_AUTH_PKCE_REDIRECT_URLS],
"UseIDToken": $NETBIRD_AUTH_PKCE_USE_ID_TOKEN,
"DisablePromptLogin": $NETBIRD_AUTH_PKCE_DISABLE_PROMPT_LOGIN,
"LoginFlag": $NETBIRD_AUTH_PKCE_LOGIN_FLAG
}
}
}
---------------------------------------------------------------------------base.setup.env-----------------------------------------------------------
Most settings are being done automatically with the sourced variables from setup.env, but you can edit if you need some customization
Management API
Management API port
NETBIRD_MGMT_API_PORT=${NETBIRD_MGMT_API_PORT:-33073}
Management API endpoint address, used by the Dashboard
NETBIRD_MGMT_API_ENDPOINT=https://$NETBIRD_DOMAIN:$NETBIRD_MGMT_API_PORT
Management Certificate file path. These are generated by the Dashboard container
NETBIRD_LETSENCRYPT_DOMAIN=$NETBIRD_DOMAIN
NETBIRD_MGMT_API_CERT_FILE="/etc/letsencrypt/live/$NETBIRD_LETSENCRYPT_DOMAIN/fullchain.pem"
Management Certificate key file path.
NETBIRD_MGMT_API_CERT_KEY_FILE="/etc/letsencrypt/live/$NETBIRD_LETSENCRYPT_DOMAIN/privkey.pem"
By default Management single account mode is enabled and domain set to $NETBIRD_DOMAIN, you may want to set this to your user's email domain
NETBIRD_MGMT_SINGLE_ACCOUNT_MODE_DOMAIN=$NETBIRD_DOMAIN
NETBIRD_MGMT_DNS_DOMAIN=${NETBIRD_MGMT_DNS_DOMAIN:-netbird.selfhosted}
NETBIRD_MGMT_IDP_SIGNKEY_REFRESH=${NETBIRD_MGMT_IDP_SIGNKEY_REFRESH:-false}
NETBIRD_MGMT_DISABLE_DEFAULT_POLICY=${NETBIRD_MGMT_DISABLE_DEFAULT_POLICY:-false}
Signal
NETBIRD_SIGNAL_PROTOCOL="http"
NETBIRD_SIGNAL_PORT=${NETBIRD_SIGNAL_PORT:-10000}
Relay
NETBIRD_RELAY_DOMAIN=${NETBIRD_RELAY_DOMAIN:-$NETBIRD_DOMAIN}
NETBIRD_RELAY_PORT=${NETBIRD_RELAY_PORT:-33080}
NETBIRD_RELAY_ENDPOINT=${NETBIRD_RELAY_ENDPOINT:-rel://$NETBIRD_RELAY_DOMAIN:$NETBIRD_RELAY_PORT}
Relay auth secret
NETBIRD_RELAY_AUTH_SECRET=
Turn
TURN_DOMAIN=${NETBIRD_TURN_DOMAIN:-$NETBIRD_DOMAIN}
NETBIRD_TURN_EXTERNAL_IP=${NETBIRD_TURN_EXTERNAL_IP}
Turn credentials
User
TURN_USER=self
Password. If empty, the configure.sh will generate one with openssl
TURN_PASSWORD=
Min port
TURN_MIN_PORT=${TURN_MIN_PORT:-49152}
Max port
TURN_MAX_PORT=${TURN_MAX_PORT:-65535}
VOLUME_PREFIX="netbird-"
MGMT_VOLUMESUFFIX="mgmt"
SIGNAL_VOLUMESUFFIX="signal"
LETSENCRYPT_VOLUMESUFFIX="letsencrypt"
NETBIRD_AUTH_DEVICE_AUTH_PROVIDER="none"
NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE=${NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE:-$NETBIRD_AUTH_AUDIENCE}
NETBIRD_AUTH_DEVICE_AUTH_SCOPE=${NETBIRD_AUTH_DEVICE_AUTH_SCOPE:-openid}
NETBIRD_AUTH_DEVICE_AUTH_USE_ID_TOKEN=${NETBIRD_AUTH_DEVICE_AUTH_USE_ID_TOKEN:-false}
NETBIRD_DISABLE_ANONYMOUS_METRICS=${NETBIRD_DISABLE_ANONYMOUS_METRICS:-false}
NETBIRD_TOKEN_SOURCE=${NETBIRD_TOKEN_SOURCE:-accessToken}
PKCE authorization flow
NETBIRD_AUTH_PKCE_REDIRECT_URL_PORTS=${NETBIRD_AUTH_PKCE_REDIRECT_URL_PORTS:-"53000"}
NETBIRD_AUTH_PKCE_USE_ID_TOKEN=${NETBIRD_AUTH_PKCE_USE_ID_TOKEN:-false}
NETBIRD_AUTH_PKCE_DISABLE_PROMPT_LOGIN=${NETBIRD_AUTH_PKCE_DISABLE_PROMPT_LOGIN:-false}
NETBIRD_AUTH_PKCE_LOGIN_FLAG=${NETBIRD_AUTH_PKCE_LOGIN_FLAG:-0}
NETBIRD_AUTH_PKCE_AUDIENCE=$NETBIRD_AUTH_AUDIENCE
Dashboard
The default setting is to transmit the audience to the IDP during authorization. However,
if your IDP does not have this capability, you can turn this off by setting it to false.
NETBIRD_DASH_AUTH_USE_AUDIENCE=${NETBIRD_DASH_AUTH_USE_AUDIENCE:-true}
NETBIRD_DASH_AUTH_AUDIENCE=$NETBIRD_AUTH_AUDIENCE
Store config
NETBIRD_STORE_CONFIG_ENGINE=${NETBIRD_STORE_CONFIG_ENGINE:-"sqlite"}
Image tags
NETBIRD_DASHBOARD_TAG=${NETBIRD_DASHBOARD_TAG:-"latest"}
NETBIRD_SIGNAL_TAG=${NETBIRD_SIGNAL_TAG:-"latest"}
NETBIRD_MANAGEMENT_TAG=${NETBIRD_MANAGEMENT_TAG:-"latest"}
COTURN_TAG=${COTURN_TAG:-"latest"}
NETBIRD_RELAY_TAG=${NETBIRD_RELAY_TAG:-"latest"}
exports
export NETBIRD_DOMAIN
export NETBIRD_TURN_DOMAIN
export NETBIRD_AUTH_CLIENT_ID
export NETBIRD_AUTH_CLIENT_SECRET
export NETBIRD_AUTH_AUDIENCE
export NETBIRD_AUTH_AUTHORITY
export NETBIRD_USE_AUTH0
export NETBIRD_AUTH_SUPPORTED_SCOPES
export NETBIRD_AUTH_JWT_CERTS
export NETBIRD_LETSENCRYPT_EMAIL
export NETBIRD_MGMT_API_PORT
export NETBIRD_MGMT_API_ENDPOINT
export NETBIRD_LETSENCRYPT_DOMAIN
export NETBIRD_MGMT_API_CERT_FILE
export NETBIRD_MGMT_API_CERT_KEY_FILE
export NETBIRD_AUTH_DEVICE_AUTH_PROVIDER
export NETBIRD_AUTH_DEVICE_AUTH_CLIENT_ID
export NETBIRD_AUTH_OIDC_CONFIGURATION_ENDPOINT
export NETBIRD_AUTH_REDIRECT_URI
export NETBIRD_AUTH_SILENT_REDIRECT_URI
export TURN_DOMAIN
export TURN_USER
export TURN_PASSWORD
export TURN_MIN_PORT
export TURN_MAX_PORT
export VOLUME_PREFIX
export MGMT_VOLUMESUFFIX
export SIGNAL_VOLUMESUFFIX
export LETSENCRYPT_VOLUMESUFFIX
export NETBIRD_DISABLE_ANONYMOUS_METRICS
export NETBIRD_MGMT_SINGLE_ACCOUNT_MODE_DOMAIN
export NETBIRD_MGMT_DNS_DOMAIN
export NETBIRD_MGMT_IDP_SIGNKEY_REFRESH
export NETBIRD_SIGNAL_PROTOCOL
export NETBIRD_SIGNAL_PORT
export NETBIRD_AUTH_USER_ID_CLAIM
export NETBIRD_AUTH_DEVICE_AUTH_AUDIENCE
export NETBIRD_TOKEN_SOURCE
export NETBIRD_AUTH_DEVICE_AUTH_SCOPE
export NETBIRD_AUTH_DEVICE_AUTH_USE_ID_TOKEN
export NETBIRD_AUTH_PKCE_AUTHORIZATION_ENDPOINT
export NETBIRD_AUTH_PKCE_USE_ID_TOKEN
export NETBIRD_AUTH_PKCE_DISABLE_PROMPT_LOGIN
export NETBIRD_AUTH_PKCE_LOGIN_FLAG
export NETBIRD_AUTH_PKCE_AUDIENCE
export NETBIRD_DASH_AUTH_USE_AUDIENCE
export NETBIRD_DASH_AUTH_AUDIENCE
export NETBIRD_STORE_CONFIG_ENGINE
export NETBIRD_DASHBOARD_TAG
export NETBIRD_SIGNAL_TAG
export NETBIRD_MANAGEMENT_TAG
export COTURN_TAG
export NETBIRD_TURN_EXTERNAL_IP
export NETBIRD_RELAY_DOMAIN
export NETBIRD_RELAY_PORT
export NETBIRD_RELAY_ENDPOINT
export NETBIRD_RELAY_AUTH_SECRET
export NETBIRD_RELAY_TAG
export NETBIRD_MGMT_DISABLE_DEFAULT_POLICY
Deployment Method
Docker
Version
Latest