[GH-ISSUE #1783] Have unaccepted peers in UI, setup key option to only let client into network after additional approval in Dashboard/API #3177

Open
opened 2026-08-05 00:51:02 -04:00 by saavagebueno · 4 comments
Owner

Originally created by @ipsecguy on GitHub (Apr 1, 2024).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/1783

When installing netbird on devices that are installed by different entities it would be helpful to have a process step of "accepting" a device into a network.

In my use-case linux based devices are inastalled and moved out in the field and can be remotely installed by different people/companies (entities). Handing out setup keys should not enable the entities to have the devices automatically become part of the network. This should only happen after approval in the UI.

Two lists are needed: unapproved device waiting for approval, or - when not approved for any reason - a parking list of devices that are - after initial review - not accepted at this time. Not that no human interaction on the devices is possible after they were initially installed.

Alternative would include to create a setup key on acceptance of the device, but at that time the device is not in the hands of the initial entity any more and also no setup key can be entered afterwards.

A similar model is used by Saltstack/Salt Project and Zerotier (or some other managed VPN).

Originally created by @ipsecguy on GitHub (Apr 1, 2024). Original GitHub issue: https://github.com/netbirdio/netbird/issues/1783 When installing netbird on devices that are installed by different entities it would be helpful to have a process step of "accepting" a device into a network. In my use-case linux based devices are inastalled and moved out in the field and can be remotely installed by different people/companies (entities). Handing out setup keys should not enable the entities to have the devices automatically become part of the network. This should only happen after approval in the UI. Two lists are needed: unapproved device waiting for approval, or - when not approved for any reason - a parking list of devices that are - after initial review - not accepted at this time. Not that no human interaction on the devices is possible after they were initially installed. Alternative would include to create a setup key on acceptance of the device, but at that time the device is not in the hands of the initial entity any more and also no setup key can be entered afterwards. A similar model is used by Saltstack/Salt Project and Zerotier (or some other managed VPN).
saavagebueno added the feature-request label 2026-08-05 00:51:02 -04:00
Author
Owner

@braginini commented on GitHub (Apr 3, 2024):

This feature is already available in the NetBird cloud and is called Peer Approval:
https://docs.netbird.io/how-to/approve-peers

Or did I mistundertand you?

We haven't planned it for the self-hosted version.

<!-- gh-comment-id:2034072360 --> @braginini commented on GitHub (Apr 3, 2024): This feature is already available in the NetBird cloud and is called Peer Approval: https://docs.netbird.io/how-to/approve-peers Or did I mistundertand you? We haven't planned it for the self-hosted version.
Author
Owner

@ipsecguy commented on GitHub (Apr 3, 2024):

You are right. Embarrassing :-)

<!-- gh-comment-id:2034724835 --> @ipsecguy commented on GitHub (Apr 3, 2024): You are right. Embarrassing :-)
Author
Owner

@dp466 commented on GitHub (Jan 29, 2025):

This feature is already available in the NetBird cloud and is called Peer Approval: https://docs.netbird.io/how-to/approve-peers

Or did I mistundertand you?

We haven't planned it for the self-hosted version.

is it planned for the SelfHosted Version ?
Also, the roadmap seem abandoned if its not updated it should be removed

<!-- gh-comment-id:2622955843 --> @dp466 commented on GitHub (Jan 29, 2025): > This feature is already available in the NetBird cloud and is called Peer Approval: https://docs.netbird.io/how-to/approve-peers > > Or did I mistundertand you? > > We haven't planned it for the self-hosted version. is it planned for the SelfHosted Version ? Also, the roadmap seem abandoned if its not updated it should be removed
Author
Owner

@MichalisDBA commented on GitHub (Feb 8, 2025):

Will Peer Approval come to self-hosted version? Sorry but this is a major security issue not having it also on self-hosted version. You can have other things behind a paywall.

<!-- gh-comment-id:2644719188 --> @MichalisDBA commented on GitHub (Feb 8, 2025): Will Peer Approval come to self-hosted version? Sorry but this is a major security issue not having it also on self-hosted version. You can have other things behind a paywall.
Sign in to join this conversation.
No Label feature-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#3177