mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-05 00:15:26 -04:00
Open
opened 2026-08-05 01:02:18 -04:00 by saavagebueno
·
91 comments
No Branch/Tag Specified
main
claude/agent-network-test-cases-p743vw
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2021 Q4
2021 Q4
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
2022 Q1
accessibility
accessibility
accessibility
acl
acl
acl
agent
agent
agent
agent
agent
agent
Android
Android
Android
Android
Android
Android
api
api
api
authentik
authentik
authentik
automation
automation
automation
azure
azure
azure
battery-usage
battery-usage
battery-usage
bug
cache
cache
cache
client
client
client
client-ui
client-ui
client-ui
cloud
cloud
cloud
cloud-only
cloud-only
cloud-only
cloudflare
cloudflare
cloudflare
community
community
community
compatibility
compatibility
compatibility
config-idp
config-idp
config-idp
config-issue
config-issue
config-issue
connection
connection
connection
contribution
contribution
contribution
coturn
coturn
coturn
cross-vpn
cross-vpn
cross-vpn
dashboard
dashboard
dashboard
data-usage
data-usage
data-usage
distribution
distribution
distribution
dns
dns
dns
docker
docker
docker
documentation
documentation
documentation
duplicate
duplicate
duplicate
enhancement
enhancement
event-stream
event-stream
event-stream
feature-request
feature-request
feature-request
freebsd
freebsd
freebsd
getting-started
getting-started
getting-started
go
go
go
good first issue
good first issue
good first issue
gui
gui
gui
help wanted
help wanted
help wanted
home-assistant
home-assistant
home-assistant
idp
idp
idp
inconsistency
inconsistency
inconsistency
integration
integration
integration
integrations
integrations
integrations
ios
ios
ios
ipv6
ipv6
ipv6
jwt
jwt
jwt
k8s
k8s
k8s
keycloak
keycloak
keycloak
linux
linux
linux
login
login
login
macos
macos
macos
management-service
management-service
management-service
Medium
Medium
Medium
missing-docs
missing-docs
missing-docs
mobile
mobile
mobile
moved-internal
moved-internal
moved-internal
needs-review
needs-review
needs-review
netbird-ui
netbird-ui
netbird-ui
networking
networking
networking
new-platform
new-platform
new-platform
nginx
nginx
nginx
notification
notification
notification
okta
okta
okta
openwrt
openwrt
openwrt
P2
P2
P2
packaging
packaging
packaging
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
peer-management
performance
performance
performance
postgres
postgres
postgres
posture-checks
posture-checks
posture-checks
psk
psk
psk
pull-request
question
question
question
refactor
refactor
refactor
relay
relay
relay
release
release
release
rfc
rfc
rfc
routes
routes
routes
security
security
security
security-improvement
security-improvement
security-improvement
security-related
security-related
security-related
self-hosting
self-hosting
self-hosting
server
server
server
signal
signal
signal
sleep-issue
sleep-issue
sleep-issue
ssh
ssh
ssh
ssl
ssl
ssl
status
status
status
store
store
store
synology
synology
synology
system-compatibility-issue
system-compatibility-issue
system-compatibility-issue
test-suite
test-suite
test-suite
third-party-integration
third-party-integration
third-party-integration
triage
triage
triage
triage
triage
triage
triage-needed
triage-needed
triage-needed
troubleshooting
troubleshooting
troubleshooting
UX
UX
UX
waiting-feedback
waiting-feedback
waiting-feedback
windows
windows
windows
wontfix
wontfix
wontfix
zitadel
zitadel
zitadel
Mirrored from GitHub Pull Request
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: DYNR/netbird#5276
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @mlsmaycon on GitHub (Sep 9, 2024).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/2566
Hello folks, this issue is open to any questions or problems regarding the new relay implementation.
@mlsmaycon commented on GitHub (Sep 9, 2024):
Status information to confirm relay usage:
@allroundtechie commented on GitHub (Sep 9, 2024):
Hi,
I have some questions about the new relay which are not clear to me.
If I take that literally this means that "only" the TURN part of coturn gets replaced but not the STUN part. Is this correct and the release only the first step to replace coturn completely or is the STUN part also already replaced with the new relay?
Can you enable TLS in the new relay and if yes how? Or is this something for a future release?
Thanks in advance and also many thanks for your awesome work in building this great software stack!
@mlsmaycon commented on GitHub (Sep 9, 2024):
@landmass-deftly-reptile-budget:
rel://andrels://, whererelsis used for TLS connections. Like signal and management, the relay have Let's Encrypt support, and you can use the environment variables below to enable it:It also supports certificate files with:
Once this is done, add the exposed address to the
management.jsonfile and restart the file./relaypath prefix.@ismail0234 commented on GitHub (Sep 9, 2024):
Hello, I have 2 questions. I am undecided whether to upgrade or not.
@bryanjuho commented on GitHub (Sep 9, 2024):
Is it okay to update to 0.29.0 without actually running the new relay image and changing management.json?
@rudradevpal commented on GitHub (Sep 10, 2024):
For new relay to work is there any new openwrt package released?
@Marcus1Pierce commented on GitHub (Sep 10, 2024):
Is it okay to use same domain for management, signal, coturn and relay?
Example: If i use domain netbird.domain.com and i want to use this domain for all services but with different port is that okay?
@Zaunei commented on GitHub (Sep 10, 2024):
If I don't care about old clients, I can ignore TURN completely, right?
Otherwise, this sounds very promising, especially with Kubernetes, the port ranges of TURN have always made the setup a bit more complex. I will definitely give it a try and report back.
STUN will continue to be used in the future?
@WolfgangDpunkt commented on GitHub (Sep 10, 2024):
I have used the automatic setup script, so I am probably using the default values for ports, so what do I need to specify here for PORT in the compose file?
@ndziuba commented on GitHub (Sep 10, 2024):
It can be found in the setup.env file.
The default port is 33080
@MDMeridio001 commented on GitHub (Sep 10, 2024):
Hello,
Is it possible to run the relay behind nginx acting as a proxy? I have tried by adding the following to my nginx configuration file, but it results in clients recieving a 400 error when trying to establish a connection to the relay. A direct connection without nginx in front works perfectly fine.
@mvivaldi commented on GitHub (Sep 10, 2024):
try add these:
and delete the directive:
@mlsmaycon commented on GitHub (Sep 10, 2024):
@ismail0234 some of the benefits of the new relay over Coturn:
The main idea is to have a more efficient relay system for NetBird. Turn/Coturn is a really good system for short-term connections. As a connection via VPN usually lasts many hours or days, we need a more efficient system that can easily be scaled.
@mlsmaycon commented on GitHub (Sep 10, 2024):
Yes it is. You don't need to update or configure anything if you don't want. It should be fully compatible with older versions of the management.json file.
@mlsmaycon commented on GitHub (Sep 10, 2024):
We will look into updating the openwrt version.
@mlsmaycon commented on GitHub (Sep 10, 2024):
Yes it is possible.
@MDMeridio001 commented on GitHub (Sep 10, 2024):
I added them but I am still getting the same error. I don't know if it is of any help but this is what I added to the docker-compose.yml file:
And this is what I added to management.json:
@mlsmaycon commented on GitHub (Sep 10, 2024):
@MDMeridio001 it seems like you are using nginx for SSL termination too, in that case, try this:
and
@MDMeridio001 commented on GitHub (Sep 10, 2024):
I completely forgot I needed to add "rels://", thank you so much, it's working fine now.
@rgdev commented on GitHub (Sep 10, 2024):
Assuming a brand new deployment and all clients running 0.29+ where does coturn fit in the picture ? Can we just run coturn with
--stun-onlyif retrocompability is no concern ?@mlsmaycon commented on GitHub (Sep 10, 2024):
@rgdev With a new deployment, it is very likely that Coturn will only be used with mobile clients until we update them.
@Roeda commented on GitHub (Sep 10, 2024):
Excuse my confusion, but since you say that you still use STUN for peer discovery, and at the same time Coturn won’t be used when the mobile apps are updated. Does that mean that the STUN service is baked into the new Relay now (or the management service) ? (Would we be ultimately able to remove Coturn from docker compose and the management.json ?)
Thank you very much for this new implementation it sounds cool and production friendly
@wehagy commented on GitHub (Sep 10, 2024):
I am updating
netbirdpackage againstopenwrt snapshotfor months, and I have no problem so far, in fact I have built the new version0.29.0and is working fine, and open a PR https://github.com/openwrt/packages/pull/24950, for now I just see the error2024-09-10T15:25:09-03:00 INFO [peer: [ REDACTED ]=] client/internal/peer/worker_relay.go:59: Relay is not supported by remote peer, probably because I'm not selfhosting, and from release notes:But I'm not backporting to
openwrt 23.05, one of my targets is supported only onopenwrt snapshot.And to be honest someone open a issue https://github.com/openwrt/packages/issues/24569#issuecomment-2246451384 on
openwrtrepo to backport a new version, I offered my help to the person if he could test it, but I got no response.@ismail0234 commented on GitHub (Sep 10, 2024):
@mlsmaycon Thanks for the explanation. Do you think about optimization on the api side? The api slows down after 200 peers connected to the system. After 500 peers, it slows down a lot. Each request takes more than 1-2 seconds.
In the test measurements I made, these are the response times returned from the api according to the number of peers connected to the system.
20 Peers: 200-300 ms
100 Peers 300-600 ms
200 Peers: 500-1000 ms
500 Peers: 1500-3000 ms
@mlsmaycon commented on GitHub (Sep 11, 2024):
Hey folks, we have a new release, 0.29.1. This release improves the relay with better authentication messages. To ensure your system is working properly, you should upgrade your relay and management servers before upgrading your clients.
@allroundtechie commented on GitHub (Sep 11, 2024):
Works like a charm, thanks!
@marcportabellaclotet-mt commented on GitHub (Sep 11, 2024):
Thanks for improving the relay functionality.
I can't find the relay repo in netbirdio github. Will it be private or closed source?
@allroundtechie commented on GitHub (Sep 11, 2024):
@marcportabellaclotet-mt
https://github.com/netbirdio/netbird/tree/main/relay
@ptpu commented on GitHub (Sep 11, 2024):
A short example for traefik which is working fine for me:
docker-compose.yml
relay.env
management.json
@pugnobellum commented on GitHub (Sep 11, 2024):
Relay compose file
management.json
netbird.subdomain.conf
I use SWAG reverse proxy which just bundles nginx and lets encrypt, my config files are above. I'm trying to add the new relay service. When I fire up my docker client/agent I get this error in the logs for it:
UPDATE: the current relay location I have now works.
@EdouardVanbelle commented on GitHub (Sep 11, 2024):
Good for me using traefik as a proxy (my config is similar to @ptpu's one )
@mlsmaycon according to your sample, I guess I can spawn multiple relay instances for redundancy reasons:
meaning can I have this case:
and you confirm that I cannot have this case:
relay.mydomainresolving to multiple IPs ?@mlsmaycon commented on GitHub (Sep 11, 2024):
Hey @EdouardVanbelle , you can have both, the first one means that the client will try both endpoints at the same time and use the one that responds first.
The second one implies a single node or a load balancer endpoint, in the first case, that should work fine, but for a LB, the nodes would need to expose their own addresses configured in the expose address configuration and it should either point directly to them or point to the LB with a Host routing rule to ensure that the traffic would go the correct node.
@mlsmaycon commented on GitHub (Sep 12, 2024):
@Roeda We are studying this option. We have two systems that can hold the stun role, signal and relay, which are both involved in the connection discovery, we will have a decision soon. But the idea of not having coturn in our self-hosted scripts and templates is something that will be applied after 2-3 major (v0.X.0) releases.
@mlsmaycon commented on GitHub (Sep 12, 2024):
Thanks for the contribution @wehagy. I've asked the user again if they have some time to test it out.
@mlsmaycon commented on GitHub (Sep 12, 2024):
@ismail0234 We are working on some optimization around our database access. It would be helpful if you can share the exact setup you have, VM size and database you are using, and the API calls you are using to measure it.
Another thing that might affect a self-hosted installation is if you have users in the system that got removed from your IDP, that would cause lots of IDP requests to fetch new data to be cached.
@ismail0234 commented on GitHub (Sep 12, 2024):
@mlsmaycon
I'm using the standard Netbird installation, I haven't made any extra settings, so I guess sqllite is used by default. Users connect to the network via setup-key. Is there a way to find out the database size?
I also don't know what an IDP is. JWT Group sync and User group propagation feature are also disabled. I do not use these features. Right now, I'm kicking all unconnected peers off the network every hour to keep the api running fast, so my problems are completely fixed. As the number of peers in the network increases, api calls become very slow and some calls return 0 http response.
The api calls I use are as follows;
Since Netbird does not share any information on the client side to find the id of the user in api calls, I need to match the netbird ip. For this, it is necessary to go through all peers and match the correct ip.
@mlsmaycon commented on GitHub (Sep 12, 2024):
@ismail0234 IDP is the identity provider (authentik, Zitadel, Google and others).
NetBird has an integration with the tool of your choice that mainly gets the user name and email and cache so that you can see them as human readable in the dashboard.
Something is really off about your performance. You can try disabling your IDP integration by updating the management.json and setting the following key to "none."
to
Then you can restart your management server and test. You will see users as IDs during this test.
Also, can you create a ticket for this problem so we can continue there?
@ismail0234 commented on GitHub (Sep 12, 2024):
@mlsmaycon Where do I create the ticket? Github or slack?
@mlsmaycon commented on GitHub (Sep 12, 2024):
@ismail0234 Github, but feel free to reach out on Slack for a faster iteration.
@ndziuba commented on GitHub (Sep 12, 2024):
For People that are using Caddy (based on the zitadel starter script)
Caddyfile:
relay.env
managment.json
docker-compose.yml
@pellz0r commented on GitHub (Sep 12, 2024):
I followed the above settings for Caddy (as I've used the Zitadel starter script once upon a time), but when a node with the latest client tries to connect I get the following:
2024-09-12T19:35:10Z DEBG client/internal/connect.go:176: connecting to the Management service netbird.mydomain.se:443
2024-09-12T19:35:10Z DEBG util/net/dialer_nonios.go:52: Dialing tcp netbird.mydomain.se:443
2024-09-12T19:35:10Z DEBG client/internal/connect.go:184: connected to the Management service netbird.mydomain.se:443
2024-09-12T19:35:11Z DEBG util/net/dialer_nonios.go:52: Dialing tcp netbird.mydomain.se:443
2024-09-12T19:35:11Z DEBG signal/client/grpc.go:81: connected to Signal Service: netbird.mydomain.se:443
2024-09-12T19:35:11Z INFO client/internal/connect.go:251: connecting to the Relay service(s): rels://netbird.mydomain.se:443/relay
2024-09-12T19:35:11Z DEBG relay/client/manager.go:93: starting relay client manager with [rels://netbird.mydomain.se:443/relay] relay servers
2024-09-12T19:35:11Z INFO [client_id: sha-WnVmoeH7RuspQpTopd/8RnZhD9vXJTf3J9VTglSeyGk=] relay/client/client.go:141: connecting to relay server: rels://netbird.mydomain.se:443/relay
2024-09-12T19:35:11Z DEBG util/net/dialer_nonios.go:52: Dialing tcp netbird.mydomain.se:443
2024-09-12T19:35:11Z ERRO relay/client/dialer/ws/ws.go:36: failed to dial to Relay server 'wss://netbird.mydomain.se:443/relay': failed to WebSocket dial: expected handshake response status code 101 but got 404
2024-09-12T19:35:11Z WARN relay/client/manager.go:130: Connection attempt failed: failed to connect to rels://netbird.mydomain.se:443/relay: failed to WebSocket dial: expected handshake response status code 101 but got 404
2024-09-12T19:35:11Z ERRO client/internal/connect.go:253: failed to connect to any relay server: all attempts failed
Not really sure what I'm missing
EDIT: Ah, I messed up and didn't pull / restart all the containers. :)
@1nerdyguy commented on GitHub (Sep 13, 2024):
To confirm:
With the new relay, I still need to have the Coturn instance for STUN at this time?
But I can deploy out multiple relay instances, update the config file accordingly, and it will use those?
@tienlq2011 commented on GitHub (Sep 16, 2024):
Could there be a guide to deploying them on Kubernetes? Thank you!
@1nerdyguy commented on GitHub (Sep 16, 2024):
To my understanding, it looks like it's just it's own container. So you'd just spin them up, map the port, and then update the management.json file and rebuild the containers
@rgdev commented on GitHub (Sep 16, 2024):
Relay on k8s (behind a ingress-nginx reverse since it's websockets) :
Ingress
Service
Deployment
The deployment references a
netbird-relay-authkeySecret you need to provide it with a key of your choice.@marcportabellaclotet-mt commented on GitHub (Sep 16, 2024):
Relay performance question...
I was testing netbird speed using direct connection (opening wg ports) and using relay, and it seems that there is a big performance penalty. Anyone have similars results?
Direct connection : 150Mbit speed
Using Relay: 30 Mbit speed.
I haven't a turn setup, so I can not compare.
@mlsmaycon commented on GitHub (Sep 16, 2024):
Hey @marcportabellaclotet-mt can you check with different MTU configurations for the NetBird interface on both ends of the connection?
Also, can you share which tool you used for the test?
@marcportabellaclotet-mt commented on GitHub (Sep 16, 2024):
I am using iperf and speedtest.
MTU is 1500 in both sides.
Relay app is deployed as a lxc container.
@1nerdyguy commented on GitHub (Sep 16, 2024):
@marcportabellaclotet-mt
Does the relay have adequate upload/download bandwidth? Since all traffic on a relayed connection flows 'through' it, you're limited by the download/upload of the relay. It may also impact the latency between clients, depending how far the relay is from their point of presence.
@marcportabellaclotet-mt commented on GitHub (Sep 16, 2024):
I am testing the relay service in the same network where netbird client is hostes, so there is no BW restriction.
My test setup is:
@mlsmaycon commented on GitHub (Sep 17, 2024):
@marcportabellaclotet-mt, the wireguard interface created by NetBird has an MTU of 1280, which can influence the performance and concurrent transfer of other peers' connections in the relay.
A good starting test could be to update your peer's MTU size to 1420 for the wt0 or utun100(macOS) interfaces and test again.
@marcportabellaclotet-mt commented on GitHub (Sep 17, 2024):
Thanks for answering @mlsmaycon . I will try some debug during the weekend.
@SamB-GB commented on GitHub (Sep 17, 2024):
Thanks @pugnobellum adding the /relay onto the proxy pass location fixed my issue.
@vampywiz17 commented on GitHub (Sep 18, 2024):
@mlsmaycon
It possible to use cloud hosted Netbird (free tier), but self hosted relay?
@drnkknt commented on GitHub (Sep 20, 2024):
@mlsmaycon
hi maycom, i want to confirm if running a relay service alongside Coturn will cause connection issues on the user client or maybe connection between service? Currently, many of my users are still using versions below 29
@thorstenkramm commented on GitHub (Sep 21, 2024):
Just if someone uses Caddy as reverse proxy, here is my config, that works fine with the relay container.
In the mangement.json I appended:
The part
is, of course, optional. I wanted to make the Management API and UI accessible for a known IP address only.
@drnkknt commented on GitHub (Sep 25, 2024):
thankyou @thorstenkramm
i can confirm this config is working if you using caddy, for me i prefer using relay instead of http://127.0.0.1 and change rel:// to rels:// in management.json
Caddyfile
docker-compose.yaml
management.json
relay.env
@daifeilail commented on GitHub (Sep 29, 2024):
I recommend continuing to use COTURN as the relay. COTURN can be further developed as needed to meet NETBIRD's requirements.
The reasons are as follows:
QoS Control Issues:
Merging all requests into a single TCP connection can make Quality of Service (QoS) difficult to manage effectively.
Complexity of Relay Networks:
The complexity of relay networks is influenced by factors such as firewalls and QoS. Proprietary protocols may encounter unusual issues, such as being blocked, in complex network environments.
Mature Telecom-Grade Solutions:
While many relay solutions exist, currently only TURN can be effectively deployed in telecom-grade solutions. Similar to VXLAN and EVPN, which require collaboration among various vendors to implement based on a standard, TURN stands out as the viable option for reliable relay networks.
Development of Low-Level Communication Protocols:
Developing low-level communication protocols requires many years of accumulation. I believe that adding features at the application layer is much more cost-effective than investing in technologies that may fail during the R&D phase.
@Spiritreader commented on GitHub (Sep 29, 2024):
What is the benefit of enabling TLS compared to leaving it off?
If I understand this correctly the purpose of the relay is to relay wireguard traffic, which is encrypted already and the relay server endpoints are statically configured via
management.jsonSo other than somebody hijacking your DNS to point to a malicious relay while at the same time having stolen the relay secret, why should I enable TLS?
@PeterWang-dev commented on GitHub (Oct 2, 2024):
Same question here. A self-host-able DERP like relay server is very critical for low latency access.
@Roeda commented on GitHub (Oct 6, 2024):
I wonder essentially the same, what a the recommendation to best secure the Relay service. Normally we put the management cluster behind a Reverse Proxy/API gateway + waf & API protection (with support for grpc). but this configuration will increase latency and create problems for Relay trafic.
so what needs to be protected in the relay service, and what is the official recommendation for security layers to add in production ?
@mlsmaycon
any input guys is welcome. thank you very much in advance
@thorstenkramm commented on GitHub (Oct 15, 2024):
Problem: Relayed connections not working
Problem
I have two peers, both on Debian 12 Linux with Netbird version 0.30.1
Problem started to appear with version 0.29, but I wouldn't say it started directly after the update to 0.30.
Both peers show
But there is no working connection between the peers. No ping. No nothing.
The connection worked flawlessly for weeks with connection type P2P. Suddenly, the P2P stopped functioning.
I'm not aware of changes to the firewall or the routing.
What makes me wonder is the connection status to the management host.
I have a couple of other peers. They are all connected via P2P and all works flawlessly.
The management host is an MS Azure VM.
Relay appears to be the latest version, too. (No
versionoption available)Caddy reverse proxy
It all runs behind a caddy reverse proxy.
Questions
How to investigate further
Is the status of the management host
[turn:door1.az.example.net:3478?transport=udp] is Unavailable, reason: allocate: attribute not foundsomething I should worry about?Firewall is open. Turn server is listening.
Any help is much appreciated.
@marcportabellaclotet-mt commented on GitHub (Oct 16, 2024):
Back to the stun topic, is it planned to remove the stun requirement in the future, to make the deployment simpler? Will relay service be able to manage the p2p discovery by itself?
@rudradevpal commented on GitHub (Oct 20, 2024):
@wehagy can you please let me know where can i find Latest openwrt packages
@wehagy commented on GitHub (Oct 21, 2024):
@rudradevpal you can find the most up-to-date
netbirdpackages foropenwrtusing the snapshot version ofopenwrt. Probably, but I haven't tested it and I might be wrong, you can download the latest.ipkpackage of netbird from theopenwrt snapshotrepository and install it on the stable version ofopenwrt.@benniekiss commented on GitHub (Nov 9, 2024):
I'm experiencing issues with proxying the relay service with caddy, but I am able to do so with nginx, and I was wondering if anyone had configuration advice.
The relay service is using self signed certificates, so the Caddyfile looks like this:
And I'm getting this consistently in my logs -- both caddy and the relay service
@ghost commented on GitHub (Jan 7, 2025):
Would it be possible to get in touch with you via Discord or something similar? I’m still having issues with Traefik and Netbird and would be very grateful if you could share your complete configuration (regarding the compose file) with me.
@Djjvb commented on GitHub (Jan 16, 2025):
It has become a blur for me, since I have no IT background (willing to learn). followed the Jim's Garage video and the official netbird documentation. But:
So now I am lost. I can't follow the Jim's garage video and files no more due to the relay. And the official installation seem to not be consistent with the github files. And have had no succes fixing it myself with limited knowledge (and chatgpt has not much input to help). To begin I have 2 questions:
@alexdellabruna commented on GitHub (Feb 12, 2025):
Hi, I'm trying to setup new relay on a self-hosted installation, but I'm not able to get it work.
The current config doesn't have Coturn integrated.
Netbird status output:
From the client.log I get:
This is my actual config:
The management points STUN and TURN to
rels://netbird.domain.com:443/relayAll the deployment is behind Nginx Ingress Controller
Does the new version still need Coturn? If that's the case, what is the relay current scope?
@1nerdyguy commented on GitHub (Feb 12, 2025):
Yes, you need Coturn still.
Relay is used by clients who can support it. Android, for example, does not.
@Roeda commented on GitHub (Feb 23, 2025):
Hello @mlsmaycon ,
any news on the relay feature development progress ?
@himekifee commented on GitHub (Mar 29, 2025):
Is it possible to force use a relay for a peer? Currently, my local machine to a remote node uses
Connection type: P2Pbut the connection quality is really bad. My relay server has good connectivity to both nodes so I would like to prefer to use relay instead of P2P. Setting one of the nodes to globally only use relay is also acceptable if specifying a single peer connection to use relay is not feasible.@papaj-na-wrotkach commented on GitHub (Apr 18, 2025):
I am wondering if the relay binary could support setting auth secret from a file (the
NB_AUTH_SECRETvariable). It would be cool if we could use Docker secrets to store the auth secret. Many images on Docker Hub support it by having a_FILEsuffixed version of every variable (or most of them).Authentik does it another way - there are no additional variables. It checks if the variable value starts with
env://orfile://and treats them as URLs to the value.file://reads the value from specified file andenv://binds the value to the value of another variable. If it does not start with any of them, Authentik treats it as a simple value.@iamspido commented on GitHub (Jun 29, 2025):
QUIC Support with Traefik Reverse Proxy - Need Help
Hi everyone,
I'm trying to get QUIC working with NetBird relay behind a Traefik reverse proxy. The relay works perfectly with WebSocket/HTTPS, but QUIC connections are failing.
Current Setup
Error Messages
What I've Tried
Attempt 1: UDP routing through Traefik
Traefik configuration:
Relay labels:
Attempt 2: Direct UDP port mapping
Relay configuration:
Current Status
netstat -ulnp | grep :443shows docker-proxy listeningQuestions
NB_EXPOSED_ADDRESSformat required for QUIC?Any help or working configurations would be greatly appreciated!
Environment:
ghcr.io/netbirdio/relay:0.49.0v3.4.3@berkant commented on GitHub (Aug 16, 2025):
Is there a way to fall back to the old TURN-based setup? I have just found myself in a very peculiar spot where I have to rely on TURN for connectivity and new Relay system wouldn't work.
@mrwsl commented on GitHub (Aug 21, 2025):
Periodically, I have disconnects from netbird peers that I am connected to via SSH. When I check
netbird status -dAI can see that the relay is not available from time to time:The logs show:
After that, the client reconnects to the relay. I was unable to find anything related in other issues so I wonder if someone has a similar problem?
@Sonlis commented on GitHub (Aug 30, 2025):
Exact same problem as @mrwsl, my linux client disconnects and reconnects to relay almost every second due to the following:
And every second, from the netbird relay container:
Having the relay container behind nginx or directly publishing its port and listening to incoming connections delivers the same results.
EDIT: I realised I had 2 instances of netbird running, and I am honestly not too sure how which got installed.
I disabled and stop netbird@main, and since no more problem with relay.
@mrwsl commented on GitHub (Aug 31, 2025):
@Sonlis Thanks for sharing your solution. It also fixed my constant reconnecting.
@linkpad commented on GitHub (Sep 5, 2025):
Same as @Sonlis I had 2 instances of netbird running and got the disconnects to relay really often.
I disabled and stopped netbird@main service and the issue is gone.
I installed netbird through the install script
curl -fsSL https://pkgs.netbird.io/install.sh | shon Manjaro (arch linux).Another issue I had (probably not related to the relay), is DNS resolution inside docker container was only working for peers configured in netbird. Forcing docker to read resolv.conf live fixed the issue :
Stop Docker:
sudo systemctl stop dockerPoint Docker to the live config:
ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.confStart Docker again:
sudo systemctl start docker@IvaskevychYuriy commented on GitHub (Sep 25, 2025):
With new ability to configure MTU on the client (I'm running 0.56.1 & also tried 0.58.1 on Ubuntu Server 24.04) I did increased MTU - currently to 1340 for example.
But now clients do not even attempt to connect via QUIC - Websockets only. Message from logs:
"MTU 1340 exceeds default (1280), forcing WebSocket transport to avoid DATAGRAM frame size issues"- coming from https://github.com/netbirdio/netbird/blob/main/shared/relay/client/client.go#L302Why is there a hard restriction on 1280 MTU for QUIC? I usually see the exact opposite - for example from Tailscale where people set MTU even to 1350 to get some sites working with QUIC over VPN: https://github.com/tailscale/tailscale/issues/2633
@fede843 commented on GitHub (Oct 1, 2025):
Hi @iamspido have you find a way around this? I am in the same situation here.
@iamspido commented on GitHub (Oct 1, 2025):
Hey @fede843, unfortunately, I haven’t found a solution or workaround for this yet.
@fede843 commented on GitHub (Oct 1, 2025):
Hi @lixmal @iamspido
yeap, I've working on this the whole morning. QUIC wants to terminate the TLS by itself.
I was able to set it up without the proxy, just using straight let's encrypt certs.
I guess you can still try to split WS behind the proxy, which it works just fine, and the QUIC udp straight to the container. But it is making things complicated.
For the moment I decided to leave an extra port open for this. We'll see how it goes.
Thanks!
@lixmal commented on GitHub (Oct 1, 2025):
@IvaskevychYuriy
Your example is for QUIC running via the overlay network. Increasing wireguard interface MTU there makes sense to allow QUIC datagrams to carry whatever other protocol is encapsulated.
However, in our case QUIC is used for the underlay, it encapsulates wireguard packets. So increasing the wireguard MTU will make wireguard packets bigger, which means they might exceed QUIC capacity (not configurable at the moment) and/or physical MTU.
That's how the layers look in an example if you'd use QUIC in both overlay and underlay (from inner to outer layers):
HTTPS -> QUIC -> UDP -> IP -> Wireguard [MTU here]-> QUIC -> UDP -> IP [MTU here again]-> ...
@fede843 @iamspido
The URL looks incorrect; there shouldn't even be a path. Please note that NetBird uses plain QUIC (with custom next proto), not http/3 (see layer example above)!
That means you cannot use an http proxy, you'll need a L4 proxy or expose the port directly.
Edit: had to resubmit the comment, had an issue
@IvaskevychYuriy commented on GitHub (Oct 1, 2025):
@lixmal thanks for the details! So basically, with
netbird up --mtu <X>I'm just setting cap on "Wireguard [MTU here]" part. Then the question would be: can this limit (1280) be also configurable?The use case is that an overlay network with just 1280 MTU can have some limitations (as seen from linked Tailscale issue). But when I'm in environment where I control the client and I know that my interface is capable of 1500 MTU then when I want to use QUIC relay I can expect the inner (Netbird overlay) network to carry
1500 - QUIC overhead, so low 1400 fornetbird up --mtu 14XX.Does this make sense?
@vespersio commented on GitHub (Oct 24, 2025):
I ran into the same issue and found that the QUIC relay requires a valid TLS certificate and key to work properly. After configuring the relay with proper TLS settings, the connection started working. Here is the working docker-compose snippet for the relay:
Important note:
To use QUIC, the relay must be accessible via a hostname with valid TLS certs. Using the relay’s FQDN works for me when setting it in management.json like this:
rels://vpn.example.com:443After applying this configuration, the relay started working correctly with QUIC.
@devopskupryk commented on GitHub (Nov 10, 2025):
Hi,
Is it possible to specify multiple relays?
I've specified two relays in my config:
Вut netbird status -d shows only the first one:
@fede843 commented on GitHub (Nov 10, 2025):
I think based on latency that is the one the client picks up. From the pool chooses the "closest" one.
@devopskupryk commented on GitHub (Nov 11, 2025):
No. I've checked with peer which is near tech second relay. It also sees only the first relay.
One more question.
Do I have to install coturn (stun and turn) if I going to use the new relay?
@fede843 commented on GitHub (Nov 11, 2025):
@devopskupryk about the relay not sure how can I help. Don't know of any CLI command to debug that.
About Coturn, STUN is needed to determine the public IP, that I understand is a mandatory component. TURN we opted to not deploy it. We are using only the new relay system. There might be some nasty LAN/Firewall scenarios where a peer cannot connect, and in those you might need TURN, but we have not seen it, so decided to kept it simple.
I think the plan is eventually to keep only the new relay around.
@devopskupryk commented on GitHub (Nov 11, 2025):
@fede843,
thanks for your replay.
@mlsmaycon,
could you please clarify situation regarding new relay and coturn (stun and turn)?
From what I understand, your new relays replace TURN part of the coturn server, but what about the STUN part?
Do I still have to install coturn for STUN functionality?