mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-05 00:15:26 -04:00
Open
opened 2026-08-05 01:29:40 -04:00 by saavagebueno
·
6 comments
No Branch/Tag Specified
main
claude/agent-network-test-cases-p743vw
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#11429
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @MichaelUray on GitHub (Apr 25, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5989
Summary
cc @pappz — would value your input given the engine-side context from #5807 / netbirdio/android-client#152.
This is an RFC-style proposal to replace the two independent peer-connection flags (
NB_FORCE_RELAYandNB_ENABLE_EXPERIMENTAL_LAZY_CONN) with a singleconnection-modeenum that has four explicit values, including one new mode (p2p-dynamic) that combines an activity-triggered relay-first wake-up with a two-tier teardown (ICE first, then relay, then full idle) for bursty mobile/LTE access. Inactivity thresholds become explicit, configurable settings rather than a single env var.The companion proposal #5990 extends this with per-peer/per-group server-side override of both the mode and the thresholds.
This addresses the same use case as #5589 (mobile default flip) and #4103 (UI/CLI exposure of relay-only mode) with a broader mechanism. If maintainers agree this is the right direction, the original authors of #5589 / #4103 may want to consider whether their issues are still independently needed or can be closed in favor of this work.
Background
The peer-connection state machine in
client/internal/peer/conn.gois currently controlled by two independent settings whose effects overlap on the same code path:NB_FORCE_RELAY/EnvKeyNBForceRelay(peer/env.go)NB_ENABLE_EXPERIMENTAL_LAZY_CONN/LazyConnectionEnabled(lazyconn/env.go)Each has its own client-side and server-side toggles, and the precedence between them is asymmetric and undocumented (see conn_mgr.go:48-82). The recently closed android-client#152 (revert ForceRelay default to false on Android) made it visible that the binary
force-relayflag is too coarse for mobile defaults: turning it off costs battery on large meshes (eager ICE for unused peers, see #1354, #2138), turning it on prevents same-LAN P2P even when peers are in the same subnet (see #5589).Proposed solution
Single enum
connection-modewith four values:relay-forcedNB_FORCE_RELAY=trueskip-ICE branch inpeer/conn.go:188-203p2pworker_relay+worker_icein parallel; hot-swap to P2P on success (conn.go:421redirect packets from relayed conn to WireGuard). Both stay up indefinitely.p2p-lazyworker_relay+worker_ice. Afterrelay-idle-thresholdwithout traffic, the entire connection is torn down.client/internal/lazyconn/package as-isp2p-dynamic(new)worker_iceruns in parallel; once ICE succeeds, traffic hot-swaps to P2P. Two-tier teardown: afterp2p-idle-thresholdwithout traffic the ICE worker tears down (relay stays warm for fast resume); after a longerrelay-idle-thresholdwithout any traffic the relay also tears down, returning the peer to fully idle. Combinesp2p-lazy's zero-cost-when-truly-idle property with low-latency-on-first-packet for recently used peers.Why this new mode
p2p-dynamicaddresses two structural issues that the binaryForceRelayflag cannot resolve:p2p-lazywhen no peers are recently used (no per-peer transport traffic for unused peers), but first-packet latency to recently-used peers ≈ always-connected because the relay path is opened before ICE finishes negotiation.p2ponce the upgrade settles (~1s of relay-routed traffic at the start of each active session before the hot-swap; subsequent traffic is direct).DeactivatePeeris a no-op when the local manager is not in lazy mode (the lazy peer'sGO_IDLEsignal is silently ignored, so the eager side immediately reconnects).The two-tier teardown is the key shape: cost (mobile data + battery) scales with recently active peers rather than total reachable peers, while bursty access (e.g. tap a peer, use for a few minutes, idle, come back five minutes later) feels instant because the warm relay path resumes faster than a cold ICE re-negotiation. Mode resolution stays predictable; thresholds are an orthogonal config concern (next section).
Inactivity thresholds — explicit settings, configurable per scope
Two explicit thresholds replace today's single
NB_LAZY_CONN_INACTIVITY_THRESHOLDenv var:p2p-idle-thresholdp2p-dynamicrelay-idle-thresholdp2p-lazy,p2p-dynamicBoth thresholds are configurable independently and follow the same source hierarchy as the mode itself (covered in the companion proposal): account default → per-group → per-peer override, with explicit client-side override on top. Ship reasonable defaults, let admins / power users tune.
relay-forcedandp2pare unaffected by either threshold — those modes are explicitly always-on by design.NB_LAZY_CONN_INACTIVITY_THRESHOLDcontinues to work as a backwards-compat alias forrelay-idle-threshold(see backwards compatibility below).Phased rollout — no default changes in this proposal
This proposal explicitly does NOT change any default mode for any platform. The new mode ships as an opt-in choice alongside the existing three behaviors (preserved via the backwards-compat mapping below). Once the implementation is in users' hands and field telemetry exists for the new mode's real-world behavior (battery, latency, edge cases), a follow-up discussion can decide whether to make it the new universal default — ideally a single default across all platforms rather than continuing today's mobile-vs-non-mobile split.
This phasing avoids relitigating the default-flip question while the new mechanism is unproven.
Backwards compatibility
Existing knobs continue to work and map to the new enum, with deprecation notices in
--helptext and docs:NB_FORCE_RELAY=true→connection-mode=relay-forcedNB_FORCE_RELAY=false(or unset) +NB_ENABLE_EXPERIMENTAL_LAZY_CONN=true→connection-mode=p2p-lazy--enable-lazy-connection→--connection-mode=p2p-lazySettings.LazyConnectionEnabled=true→ equivalent to setting account-levelconnection-mode=p2p-lazyNB_LAZY_CONN_INACTIVITY_THRESHOLD→ backwards-compat alias forrelay-idle-thresholdNo env-var or CLI removal in this change; deprecate in this minor, remove no earlier than next major.
Settings-source precedence (client-side)
Replace the current asymmetric "client-ON locks server out, client cannot opt-out of server-ON" with a single explicit precedence (applies to both the mode and the thresholds):
follow-serverto clear a local override)Each layer is allowed to set any of the four modes (not just enable/disable) and to override either threshold independently, so a power-user can explicitly opt out of an account-wide setting in either direction (today not possible).
Server-side per-peer/per-group resolution that produces the value sent to the client is covered in the companion proposal.
Implementation notes
Most pieces already exist:
relay-forced: existing skip-ICE branch inpeer/conn.go:188.p2p: existing default code path.p2p-lazy: existingclient/internal/lazyconn/package with one threshold (relay-idle-threshold).p2p-dynamic: new — but reuseslazyconn/activity/for the activity-detector andlazyconn/inactivity/managerfor the tear-downs. The novel pieces are: (a) opening the relay path in parallel with ICE on the activity trigger so the first user packet flows immediately over relay, and (b) adding a second timer to the per-peer inactivity manager so the ICE worker can be torn down independently of the relay path.Subnet-router peers stay always-on via the existing
ExcludePeermechanism. Rosenpass remains mutually exclusive withp2p-lazyandp2p-dynamic(same constraint as today, conn_mgr.go:66). Mobile clients drop their ad-hoc UI for ForceRelay and adopt a single mode-picker; the existing AndroidEnvKeyNBLazyConn/EnvKeyNBInactivityThresholdexports inclient/android/env_list.goare already in place for the gomobile binding.Related issues
p2p-dynamicwhich gives same-LAN P2P without the eager-ICE battery cost.ForceRelay=truemobile default).@MichaelUray commented on GitHub (May 1, 2026):
Phase 1 PRs gepostet:
relay-forced,p2p,p2p-lazy), backwards-compat-mapping aller alten Flags, neue Source-Precedence (env > config > server-pushed).p2p-dynamicist proto/DB-mäßig reserviert, daemon-seitig pass-through bis Phase 2.relay-forcedundp2p-dynamicbleiben in Phase 1 admin-only.Konsolidierung gegenüber dem RFC: Beim Implementation-Brainstorm wurden
p2p-dynamicundp2p-dynamic-lazyzu einem einzelnenp2p-dynamic-Mode mit zwei orthogonalen Timeouts (p2p_timeout,relay_timeout,0= disabled) zusammengeführt. Das RFC schlug 5 Modes vor, die Implementation hat 4. Begründung: weniger mentaler Overhead, eine einzige Mode-Achse, Verhalten orthogonal über klar benannte Threshold-Werte konfigurierbar. Die zwei Timeouts gelten mode-übergreifend (relay_timeoutwirkt inp2p-lazyundp2p-dynamic,p2p_timeoutnur inp2p-dynamic). Falls die Maintainer den 5-Mode-Aufbau bevorzugen, kann das in einem follow-up-Commit getrennt werden.Hardware-tested auf einer produktiven NetBird-Instanz mit 32 connected peers über 12 OpenWrt-Router-Versionen (22.03 bis 25.12), Windows 10/11, Debian 13, Android 12/14, iOS 26.3.1: Cutover ohne Disconnect, zwei Mode-Wechsel (
p2p-lazy<->p2pvia API) ohne Disconnect, 8-Min-Monitor zeigt zero peer-count drift. Backwards-compat-Vertrag hält: alte Daemons sehen weiterhin nur den altenlazy_connection_enabled-Boolean, der viatoPeerConfiggemapped wird.Phase 2 (
p2p-dynamicdaemon-Implementierung -- decoupledworker_relay/worker_iceOnNewOffer-Registrierung, two-tier inactivity manager,DeactivatePeer-no-op-Fix) und Phase 3 (= #5990, per-peer/per-group Resolution) folgen in eigenen PRs.@MichaelUray commented on GitHub (May 6, 2026):
@mlsmaycon
I think there was no dedicated discussion section available for me on this Github repository when I opened this issues here for a discussion.
Not sure if it makes sense to open a Github discussion with a duplication of this issue here.
@mlsmaycon commented on GitHub (May 7, 2026):
@MichaelUray Thanks for putting this proposal together — it’s an interesting direction. That said, I think it’s missing some context around how the current modes already behave today. Let me walk through the existing modes and some of the decisions behind them:
Default mode (workstations)
By default, peers establish a relay connection while simultaneously attempting to create a direct connection. Once a direct connection succeeds, traffic switches over to it, while the relay path remains available as a failover if the ICE/direct connection drops. In this mode, peers exchange health checks at short intervals, which are data-transfer-hungry and consume power too.
Force relay mode
In this mode, ICE/direct connection attempts are skipped and only relay connections are used. This is currently the default behavior on mobile clients because it helps reduce battery and data usage. Users can disable it at any time directly on the client side. On workstation clients, this mode exists mainly through explicitly defined environment variables and is generally intended for testing/debugging scenarios.
Lazy connection mode
Lazy connections can be enabled both on the client side (on both peers) and on the management side. In this mode, connections are established only when WireGuard detects actual traffic/activity. Once triggered, peers establish either a relayed or direct P2P connection, which remains active until it has been idle for one hour. After that, the connection is torn down and peers return to waiting for the next activity trigger. During active periods, health checks are still exchanged at short intervals.
We’re currently moving toward enabling lazy connections by default for new accounts. With some improvements already planned around health checks, we may also be able to disable forced relay mode on mobile devices in the coming weeks.
Regarding the proposal itself and the implementation:
While the idea is interesting, I’m concerned it could introduce additional complexity and make configuration synchronization between peers harder to reason about. One thing we could explore instead is reducing the idle timeout in lazy mode from 1 hour down to something like 15–30 minutes.
The PRs around these changes are also becoming fairly large. Ideally, I’d expect changes in this area to follow the existing lazy connection patterns more closely — for example, by adding smaller configuration knobs for relay forcing or idle timing — rather than introducing a broader behavioral shift. Right now, it feels like the implementation is drifting a bit outside the current design context.
For the time being, we’d be very happy to accept a smaller contribution around a dedicated “force relay” flag, since that is already something planned internally. However, accepting a much larger behavioral change would be difficult while we’re focused on stabilization work for the 1.0 release, as it would increase overall risk quite a bit.
@MichaelUray commented on GitHub (May 7, 2026):
@mlsmaycon Thanks for the context. I understand the concern that this looks like a broader behavioral shift, so let me explain the reasoning.
Why a separate
p2p-dynamicmodeThe main reason I modeled this as a new opt-in mode rather than changing
p2p-lazyis compatibility and operational clarity:p2pkeeps its current relay+ICE behavior, unchanged.p2p-lazykeeps its existing single-tier lazy model.p2p_dynamicget capability-gated downgrade to existingp2p-lazy(already wired throughSupportedFeatures+LegacyLazyFallback).This means mixed-version accounts stay predictable: each peer's behavior follows a mode label it understands, with no in-place semantic drift on existing modes.
To address the configuration-synchronization concern specifically: the intention is that the management server resolves one effective mode and the effective timers per peer, and clients expose both the configured and effective values in status/debug output. So when debugging a connection, the question is not "which combination of flags happened to win?", but "what effective mode did this peer receive, and which fallback/capability decision was applied?"
This also fits the direction you mentioned — lazy-by-default for new accounts, and dropping force-relay as the mobile default in the coming weeks.
p2p-dynamicis intended to complement that direction, not compete with it.A peer in this mode without recent activity uses the same idle/no per-peer connection state as lazy mode; the difference is what happens during the active phase for peers the user is actually using.
What the new lifecycle adds
The motivation isn't "lazy with a shorter timeout" — it's an extra state in the active phase, aimed at bursty mobile/LTE (limited data volume) access patterns:
The two intended differences from existing lazy:
For mobile/LTE users with many reachable peers but only a few recently used ones, the goal is that cost (mobile data + battery) scales with recently active peers, not total reachable peers, while still preserving fast first access for recently used peers.
Initial hardware tests in my mixed mobile/LTE-style setup with 20+ accessible peers suggested promising reductions in idle and recently-active peer overhead, while still allowing fast reconnection to recently used peers.
Curious to hear your thoughts about it.
@MichaelUray commented on GitHub (May 25, 2026):
@mlsmaycon
did you actually get a chance to look through my further explanations in my comment above?
I realize that reply and the issue body together covered a lot at once, and the timeline now has quite a few linked items between then and now — so it's possible the actual value got buried. Putting the concrete improvements into a short list might help:
p2p-dynamic: relay stays warm briefly after ICE/P2P teardown, enabling fast-path P2P re-attach when a peer becomes active again. This is the key behavioral difference from existing lazy mode and is targeted at mobile/LTE access patterns where users have many reachable peers but only a few recently used ones.p2p_timeout,relay_timeout), both server-pushed and mode-agnostic — replacing the single 1h hardcoded timeout in existing lazy mode with configurable, tunable per-account settings.SupportedFeaturesand downgraded to existingp2p-lazyviaLegacyLazyFallback. Existing accounts and clients aren't affected unless they explicitly enroll in the new mode label. No in-place semantic drift on existing modes.p2p-lazy↔p2pvia API) did not interrupt active sessions.The reasoning for modeling this as a new opt-in label instead of changing existing modes is in my 2026-05-07 reply — I won't repeat it here, but the short version is: each peer stays in exactly one labeled mode, capability-gated for backwards compatibility, with a single effective resolution per peer that the client surfaces in status. That keeps mixed-version operation predictable.
Since the 2026-05-07 reply, the work has continued:
lastActiveupdate and could stay stuck in inactivity tracking.GO_IDLEfrom a legacy lazy-mode peer (e.g. v0.51.2) could trigger an unintended ICE-detach + guard-retry-exhaustion cycle on newer clients, leaving the tunnel relay-only until the next manual reconnect.main.Thanks for taking the time.
Michael
@RMTT commented on GitHub (Jun 24, 2026):
Is possible to make connection-mode a policy option? For example, when adding policy from source peer A to destination peer B, use
relay-forced.