[GH-ISSUE #4129] Issue with configuration of Netbird behind Traefik and Authentik #8771

Open
opened 2026-08-05 01:19:30 -04:00 by saavagebueno · 8 comments
Owner

Originally created by @buzzard10 on GitHub (Jul 9, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/4129

Describe the problem

I'm trying to configure Netbird behind Traefik on my VPS. I'm using Authentik as my OIDC. I've tried a lot of things and i think that i'm closed, but unfortunately i stacked in place where "everything is running", but i have white page and this error in logs:
2025-07-09T19:44:57Z WARN [context: GRPC, requestID: 50dcda0c-XXXXXXXXXXXXXXXX-daf2b1e40690, accountID: UNKNOWN, peerID: A4d+XXXXXXXXXXXXXXXXXXXXXXXXXXXCXSI=] management/server/grpcserver.go:486: failed logging in peer A4d+XXXXXXXXXXXXXXXXXXXXXXXXXXXCXSI=: no peer auth method provided, please use a setup key or interactive SSO login

Maybe i should adjust something to pass authentik via traefik? Idk.
When i'm, refreshing page, there is short orange netbird animation and then i'm stacked on white screen.

Expected behavior

It should show me a login screen.

Are you using NetBird Cloud?
No - i'm trying to configure selfhosted version on docker.

NetBird version

0.50.0

Is any other VPN software installed?

No

Originally created by @buzzard10 on GitHub (Jul 9, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/4129 **Describe the problem** I'm trying to configure Netbird behind Traefik on my VPS. I'm using Authentik as my OIDC. I've tried a lot of things and i think that i'm closed, but unfortunately i stacked in place where "everything is running", but i have white page and this error in logs: ```2025-07-09T19:44:57Z WARN [context: GRPC, requestID: 50dcda0c-XXXXXXXXXXXXXXXX-daf2b1e40690, accountID: UNKNOWN, peerID: A4d+XXXXXXXXXXXXXXXXXXXXXXXXXXXCXSI=] management/server/grpcserver.go:486: failed logging in peer A4d+XXXXXXXXXXXXXXXXXXXXXXXXXXXCXSI=: no peer auth method provided, please use a setup key or interactive SSO login``` Maybe i should adjust something to pass authentik via traefik? Idk. When i'm, refreshing page, there is short orange netbird animation and then i'm stacked on white screen. **Expected behavior** It should show me a login screen. **Are you using NetBird Cloud?** No - i'm trying to configure selfhosted version on docker. **NetBird version** `0.50.0` **Is any other VPN software installed?** No
saavagebueno added the triage-neededself-hosting labels 2026-08-05 01:19:30 -04:00
Author
Owner

@LukaDeka commented on GitHub (Jul 14, 2025):

Could you share more of your configuration and logs?

Also how are you setting the envs? Don't actually share them, just where you're getting the values from

<!-- gh-comment-id:3069189280 --> @LukaDeka commented on GitHub (Jul 14, 2025): Could you share more of your configuration and logs? Also how are you setting the envs? Don't actually share them, just where you're getting the values from
Author
Owner

@buzzard10 commented on GitHub (Jul 14, 2025):

Hello,
@LukaDeka i appreciate your assistance. So I've played a little bit and was managed to go further. I have some progress, now I've stucked on login screen, basically i have this error. Netbird connect to Authentik and then gets back and after a moment i have this error:

Image
<!-- gh-comment-id:3070063527 --> @buzzard10 commented on GitHub (Jul 14, 2025): Hello, @LukaDeka i appreciate your assistance. So I've played a little bit and was managed to go further. I have some progress, now I've stucked on login screen, basically i have this error. Netbird connect to Authentik and then gets back and after a moment i have this error: <img width="730" height="795" alt="Image" src="https://github.com/user-attachments/assets/05916f50-f4d3-4334-92d9-47838e1ef615" />
Author
Owner

@LukaDeka commented on GitHub (Jul 14, 2025):

I had the same issue a few days ago when I also set Netbird up.

Could you please check and send your /var/lib/netbird-mgmt/management.json and your env fields as well? Note that there are secrets in both files.

My issue was the ports and the env variables not being set correctly.

You can also check out my NixOS config. I left most of the fields as defaults:

https://github.com/LukaDeka/NixOS/blob/main/packages/netbird.nix

Also make sure to send systemctl status netbird-mgmt.

<!-- gh-comment-id:3070134007 --> @LukaDeka commented on GitHub (Jul 14, 2025): I had the same issue a few days ago when I also set Netbird up. Could you please check and send your `/var/lib/netbird-mgmt/management.json` and your env fields as well? Note that there are secrets in both files. My issue was the ports and the env variables not being set correctly. You can also check out my NixOS config. I left most of the fields as defaults: > https://github.com/LukaDeka/NixOS/blob/main/packages/netbird.nix Also make sure to send `systemctl status netbird-mgmt`.
Author
Owner

@buzzard10 commented on GitHub (Jul 14, 2025):

I have everything on docker :) in docker compose. I'm trying to find something weird, i found, recreated but nothings changed.

<!-- gh-comment-id:3070233396 --> @buzzard10 commented on GitHub (Jul 14, 2025): I have everything on docker :) in docker compose. I'm trying to find something weird, i found, recreated but nothings changed.
Author
Owner

@FlashGordon86 commented on GitHub (Aug 12, 2025):

Same problem here. I am using authelia but config should be similar.

<!-- gh-comment-id:3180906421 --> @FlashGordon86 commented on GitHub (Aug 12, 2025): Same problem here. I am using authelia but config should be similar.
Author
Owner

@rtgiskard commented on GitHub (Oct 21, 2025):

Hello, @LukaDeka i appreciate your assistance. So I've played a little bit and was managed to go further. I have some progress, now I've stucked on login screen, basically i have this error. Netbird connect to Authentik and then gets back and after a moment i have this error:
Image

same issue, struggled few days, just resolved!!
check here: https://github.com/netbirdio/netbird/issues/4679#issue-3538759562

<!-- gh-comment-id:3430309810 --> @rtgiskard commented on GitHub (Oct 21, 2025): > Hello, [@LukaDeka](https://github.com/LukaDeka) i appreciate your assistance. So I've played a little bit and was managed to go further. I have some progress, now I've stucked on login screen, basically i have this error. Netbird connect to Authentik and then gets back and after a moment i have this error: > <img alt="Image" width="730" height="795" src="https://private-user-images.githubusercontent.com/17282191/466088552-05916f50-f4d3-4334-92d9-47838e1ef615.png?jwt=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3NjEwOTY3NDEsIm5iZiI6MTc2MTA5NjQ0MSwicGF0aCI6Ii8xNzI4MjE5MS80NjYwODg1NTItMDU5MTZmNTAtZjRkMy00MzM0LTkyZDktNDc4MzhlMWVmNjE1LnBuZz9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTEwMjIlMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUxMDIyVDAxMjcyMVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPWNmNmQ4YmRhM2JmMDgyMjY3NWQ3MWI2ZmY1N2UzODEwZWQxZTBjMDhmY2FlMjAxOTUzODdmMTkyN2FhODFkM2EmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.3oT9K7Man0eXbWMztgp5-6ZYKI5rPTgJsxbb-m291h4"> same issue, struggled few days, just resolved!! check here: https://github.com/netbirdio/netbird/issues/4679#issue-3538759562
Author
Owner

@afonsofrancof commented on GitHub (Nov 20, 2025):

Hey! I still have this issue.
I am using caddy and have confirmed that everything seems to be working except this.
I always get that error when trying to add a device. The device says it logged in successfully but it won't connect.
I have checked basically everything and have no idea what to do.

<!-- gh-comment-id:3560851417 --> @afonsofrancof commented on GitHub (Nov 20, 2025): Hey! I still have this issue. I am using caddy and have confirmed that everything seems to be working except this. I always get that error when trying to add a device. The device says it logged in successfully but it won't connect. I have checked basically everything and have no idea what to do.
Author
Owner

@Slurpgeit commented on GitHub (Dec 14, 2025):

Hiya,

I've been at this for a couple of hours too, but I managed to get it working. I'll share my config and things I had to change for it to work. I started using configure.sh as the instructions said but I migrated it to a simple folder with the following files:

.
├── docker-compose.yml
├── management.json
└── turnserver.conf

1 directory, 3 files

One thing I had to change was in management.json. For Signal I had to set the protocol to https:

    "Signal": {
        "Proto": "https",
        "URI": "netbird.domain.nl:443",
        "Username": "",
        "Password": ""
    },

Other than that management.json and turnserver.conf are unchanged from how they were generated with configure.sh. Obviously make sure that all keys, ids and passwords match :).

My docker-compose.yaml looks like this:

x-default: &default
  extra_hosts:
  - "${AUTHENTIK_DOMAIN}:192.168.50.2" # I do this to prevent issues with dns resolution, vlans, firewalls etc.
  restart: 'unless-stopped'
  logging:
    driver: 'json-file'
    options:
      max-size: '500m'
      max-file: '2'

services:
  # UI dashboard
  dashboard:
    <<: *default
    image: netbirdio/dashboard:latest
    environment:
      # Endpoints
      NETBIRD_MGMT_API_ENDPOINT: https://${NB_DOMAIN}:443
      NETBIRD_MGMT_GRPC_API_ENDPOINT: https://${NB_DOMAIN}:443
      # OIDC
      AUTH_AUDIENCE: ${NB_CLIENT_ID}
      AUTH_CLIENT_ID: ${NB_CLIENT_ID}
      AUTH_AUTHORITY: https://${AUTHENTIK_DOMAIN}/application/o/${AUTHENTIK_NB_SLUG}/
      USE_AUTH0: false
      AUTH_SUPPORTED_SCOPES: openid profile email offline_access api
      AUTH_REDIRECT_URI: /auth
      AUTH_SILENT_REDIRECT_URI: /silent-auth
      NETBIRD_TOKEN_SOURCE: accessToken
    labels:
      traefik.enable: true
      traefik.http.routers.netbird-dashboard.tls: true
      traefik.http.routers.netbird-dashboard.rule: Host(`${NB_DOMAIN}`)
      traefik.http.routers.netbird-dashboard.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-dashboard.loadbalancer.server.port: 80

  # Signal
  signal:
    <<: *default
    image: netbirdio/signal:latest
    volumes:
      - netbird-signal:/var/lib/netbird
    labels:
      traefik.enable: true
      # WS Proxy Signal
      traefik.http.routers.netbird-wsproxy-signal.tls: true
      traefik.http.routers.netbird-wsproxy-signal.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/ws-proxy/signal`)
      traefik.http.routers.netbird-wsproxy-signal.service: netbird-wsproxy-signal
      traefik.http.routers.netbird-wsproxy-signal.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-wsproxy-signal.loadbalancer.server.port: 80
      # Signal
      traefik.http.routers.netbird-signal.tls: true
      traefik.http.routers.netbird-signal.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/signalexchange.SignalExchange/`)
      traefik.http.routers.netbird-signal.service: netbird-signal
      traefik.http.routers.netbird-signal.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-signal.loadbalancer.server.port: 10000
      traefik.http.services.netbird-signal.loadbalancer.server.scheme: h2c

  # Relay
  relay:
    <<: *default
    image: netbirdio/relay:latest
    environment:
      NB_LOG_LEVEL: info
      NB_LISTEN_ADDRESS: :33080
      NB_EXPOSED_ADDRESS: rels://${NB_DOMAIN}:443/relay
      NB_AUTH_SECRET: ${NB_AUTH_SECRET}
    labels:
      traefik.enable: true
      traefik.http.routers.netbird-relay.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/relay`)
      traefik.http.routers.netbird-relay.tls: true
      traefik.http.routers.netbird-relay.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-relay.loadbalancer.server.port: 33080

  # Management
  management:
    <<: *default
    image: netbirdio/management:latest
    depends_on:
      - dashboard
    volumes:
        - netbird-mgmt:/var/lib/netbird
        - ./management.json:/etc/netbird/management.json
    command: [
      "--port", "33073",
      "--log-file", "console",
      "--log-level", "info",
      "--disable-anonymous-metrics=${NB_DISABLE_METRICS}",
      "--single-account-mode-domain=${NB_DOMAIN}",
      "--dns-domain=${NB_LOCAL_DOMAIN}"
    ]
    labels:
      traefik.enable: true
      # API
      traefik.http.routers.netbird-api.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/api`)
      traefik.http.routers.netbird-api.tls: true
      traefik.http.routers.netbird-api.service: netbird-api
      traefik.http.routers.netbird-api.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-api.loadbalancer.server.port: 33073
      # WS Proxy management
      traefik.http.routers.netbird-wsproxy-mgmt.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/ws-proxy/management`)
      traefik.http.routers.netbird-wsproxy-mgmt.tls: true
      traefik.http.routers.netbird-wsproxy-mgmt.service: netbird-wsproxy-mgmt
      traefik.http.routers.netbird-wsproxy-mgmt.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-wsproxy-mgmt.loadbalancer.server.port: 33073
      # Management
      traefik.http.routers.netbird-management.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/management.ManagementService/`)
      traefik.http.routers.netbird-management.tls: true
      traefik.http.routers.netbird-management.service: netbird-management
      traefik.http.routers.netbird-management.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT}
      traefik.http.services.netbird-management.loadbalancer.server.port: 33073
      traefik.http.services.netbird-management.loadbalancer.server.scheme: h2c
      
  # Coturn
  coturn:
    <<: *default
    image: coturn/coturn:latest
    domainname: ${NB_DOMAIN}
    volumes:
      - ./turnserver.conf:/etc/turnserver.conf:ro
    network_mode: host
    command:
      - -c /etc/turnserver.conf

volumes:
  netbird-mgmt:
  netbird-signal:

The .env file is:

# Authentik
AUTHENTIK_DOMAIN="authentik.domain.nl"
AUTHENTIK_NB_SLUG="netbird"

# Netbird
NB_DOMAIN="netbird.domain.nl"
NB_LOCAL_DOMAIN="domain.local"
NB_CLIENT_ID="<client_id>"
NB_AUTH_SECRET="<auth secret>" # make sure this matches Relay -> Secret in management.json
NB_DISABLE_METRICS="false"

# Traefik
TRAEFIK_TLS_ENTRYPOINT="websecure"

After starting the stack I also had to go into the web UI and set the custom internal domain under Settings -> Networks -> DNS Domain. Also obviously make all required port forwards. For setting up Authentik I used the official instructions without changes.

For Traefik I use cloudflare dns with wildcard certificates in another container. That means I can re-use that certificate here:

services:
  traefik:
    image: traefik:v3
    network_mode: host
    restart: unless-stopped
    command:
      - --api.dashboard=true
      - --api.insecure=false
      - --providers.docker=true
      - --providers.docker.exposedByDefault=false
      - --entrypoints.web.address=:80
      - --entryPoints.websecure.address=:443
      - --certificatesresolvers.le.acme.storage=/etc/traefik/acme.json
      - --certificatesresolvers.le.acme.dnsChallenge.provider=cloudflare
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - traefik:/etc/traefik
    environment:
      - CF_API_EMAIL=${CF_API_EMAIL}
      - CF_DNS_API_TOKEN=${CF_DNS_API_TOKEN}
    labels:
      - traefik.enable=true
      # Wildcard certificate
      - traefik.http.routers.traefik.tls.certresolver=le
      - traefik.http.routers.traefik.tls.domains[0].main=domain.nl
      - traefik.http.routers.traefik.tls.domains[0].sans=*.domain.nl
      # Single router for secure Traefik dashboard
      - traefik.http.routers.traefik.rule=Host(`traefik.domain.nl`)
      - traefik.http.routers.traefik.entrypoints=websecure
      - traefik.http.routers.traefik.tls=true
      - traefik.http.routers.traefik.service=api@internal
      - traefik.http.services.api.loadbalancer.server.port=8080
volumes:
  traefik:

If you don't already have something like this you'd also need to add labels to the netbird containers to ensure it gets the proper certificate.

Hope it helps!

<!-- gh-comment-id:3651794745 --> @Slurpgeit commented on GitHub (Dec 14, 2025): Hiya, I've been at this for a couple of hours too, but I managed to get it working. I'll share my config and things I had to change for it to work. I started using configure.sh as the instructions said but I migrated it to a simple folder with the following files: ```shell . ├── docker-compose.yml ├── management.json └── turnserver.conf 1 directory, 3 files ``` One thing I had to change was in **management.json**. For **Signal** I had to set the protocol to https: ```json "Signal": { "Proto": "https", "URI": "netbird.domain.nl:443", "Username": "", "Password": "" }, ``` Other than that **management.json** and **turnserver.conf** are unchanged from how they were generated with configure.sh. Obviously make sure that all keys, ids and passwords match :). My **docker-compose.yaml** looks like this: ```yaml x-default: &default extra_hosts: - "${AUTHENTIK_DOMAIN}:192.168.50.2" # I do this to prevent issues with dns resolution, vlans, firewalls etc. restart: 'unless-stopped' logging: driver: 'json-file' options: max-size: '500m' max-file: '2' services: # UI dashboard dashboard: <<: *default image: netbirdio/dashboard:latest environment: # Endpoints NETBIRD_MGMT_API_ENDPOINT: https://${NB_DOMAIN}:443 NETBIRD_MGMT_GRPC_API_ENDPOINT: https://${NB_DOMAIN}:443 # OIDC AUTH_AUDIENCE: ${NB_CLIENT_ID} AUTH_CLIENT_ID: ${NB_CLIENT_ID} AUTH_AUTHORITY: https://${AUTHENTIK_DOMAIN}/application/o/${AUTHENTIK_NB_SLUG}/ USE_AUTH0: false AUTH_SUPPORTED_SCOPES: openid profile email offline_access api AUTH_REDIRECT_URI: /auth AUTH_SILENT_REDIRECT_URI: /silent-auth NETBIRD_TOKEN_SOURCE: accessToken labels: traefik.enable: true traefik.http.routers.netbird-dashboard.tls: true traefik.http.routers.netbird-dashboard.rule: Host(`${NB_DOMAIN}`) traefik.http.routers.netbird-dashboard.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-dashboard.loadbalancer.server.port: 80 # Signal signal: <<: *default image: netbirdio/signal:latest volumes: - netbird-signal:/var/lib/netbird labels: traefik.enable: true # WS Proxy Signal traefik.http.routers.netbird-wsproxy-signal.tls: true traefik.http.routers.netbird-wsproxy-signal.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/ws-proxy/signal`) traefik.http.routers.netbird-wsproxy-signal.service: netbird-wsproxy-signal traefik.http.routers.netbird-wsproxy-signal.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-wsproxy-signal.loadbalancer.server.port: 80 # Signal traefik.http.routers.netbird-signal.tls: true traefik.http.routers.netbird-signal.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/signalexchange.SignalExchange/`) traefik.http.routers.netbird-signal.service: netbird-signal traefik.http.routers.netbird-signal.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-signal.loadbalancer.server.port: 10000 traefik.http.services.netbird-signal.loadbalancer.server.scheme: h2c # Relay relay: <<: *default image: netbirdio/relay:latest environment: NB_LOG_LEVEL: info NB_LISTEN_ADDRESS: :33080 NB_EXPOSED_ADDRESS: rels://${NB_DOMAIN}:443/relay NB_AUTH_SECRET: ${NB_AUTH_SECRET} labels: traefik.enable: true traefik.http.routers.netbird-relay.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/relay`) traefik.http.routers.netbird-relay.tls: true traefik.http.routers.netbird-relay.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-relay.loadbalancer.server.port: 33080 # Management management: <<: *default image: netbirdio/management:latest depends_on: - dashboard volumes: - netbird-mgmt:/var/lib/netbird - ./management.json:/etc/netbird/management.json command: [ "--port", "33073", "--log-file", "console", "--log-level", "info", "--disable-anonymous-metrics=${NB_DISABLE_METRICS}", "--single-account-mode-domain=${NB_DOMAIN}", "--dns-domain=${NB_LOCAL_DOMAIN}" ] labels: traefik.enable: true # API traefik.http.routers.netbird-api.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/api`) traefik.http.routers.netbird-api.tls: true traefik.http.routers.netbird-api.service: netbird-api traefik.http.routers.netbird-api.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-api.loadbalancer.server.port: 33073 # WS Proxy management traefik.http.routers.netbird-wsproxy-mgmt.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/ws-proxy/management`) traefik.http.routers.netbird-wsproxy-mgmt.tls: true traefik.http.routers.netbird-wsproxy-mgmt.service: netbird-wsproxy-mgmt traefik.http.routers.netbird-wsproxy-mgmt.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-wsproxy-mgmt.loadbalancer.server.port: 33073 # Management traefik.http.routers.netbird-management.rule: Host(`${NB_DOMAIN}`) && PathPrefix(`/management.ManagementService/`) traefik.http.routers.netbird-management.tls: true traefik.http.routers.netbird-management.service: netbird-management traefik.http.routers.netbird-management.entrypoints: ${TRAEFIK_TLS_ENTRYPOINT} traefik.http.services.netbird-management.loadbalancer.server.port: 33073 traefik.http.services.netbird-management.loadbalancer.server.scheme: h2c # Coturn coturn: <<: *default image: coturn/coturn:latest domainname: ${NB_DOMAIN} volumes: - ./turnserver.conf:/etc/turnserver.conf:ro network_mode: host command: - -c /etc/turnserver.conf volumes: netbird-mgmt: netbird-signal: ``` The **.env** file is: ```shell # Authentik AUTHENTIK_DOMAIN="authentik.domain.nl" AUTHENTIK_NB_SLUG="netbird" # Netbird NB_DOMAIN="netbird.domain.nl" NB_LOCAL_DOMAIN="domain.local" NB_CLIENT_ID="<client_id>" NB_AUTH_SECRET="<auth secret>" # make sure this matches Relay -> Secret in management.json NB_DISABLE_METRICS="false" # Traefik TRAEFIK_TLS_ENTRYPOINT="websecure" ``` After starting the stack I also had to go into the web UI and set the custom internal domain under **Settings** -> **Networks** -> **DNS Domain**. Also obviously make all required port forwards. For setting up Authentik I used the official instructions without changes. For Traefik I use cloudflare dns with wildcard certificates in another container. That means I can re-use that certificate here: ```yaml services: traefik: image: traefik:v3 network_mode: host restart: unless-stopped command: - --api.dashboard=true - --api.insecure=false - --providers.docker=true - --providers.docker.exposedByDefault=false - --entrypoints.web.address=:80 - --entryPoints.websecure.address=:443 - --certificatesresolvers.le.acme.storage=/etc/traefik/acme.json - --certificatesresolvers.le.acme.dnsChallenge.provider=cloudflare volumes: - /var/run/docker.sock:/var/run/docker.sock:ro - traefik:/etc/traefik environment: - CF_API_EMAIL=${CF_API_EMAIL} - CF_DNS_API_TOKEN=${CF_DNS_API_TOKEN} labels: - traefik.enable=true # Wildcard certificate - traefik.http.routers.traefik.tls.certresolver=le - traefik.http.routers.traefik.tls.domains[0].main=domain.nl - traefik.http.routers.traefik.tls.domains[0].sans=*.domain.nl # Single router for secure Traefik dashboard - traefik.http.routers.traefik.rule=Host(`traefik.domain.nl`) - traefik.http.routers.traefik.entrypoints=websecure - traefik.http.routers.traefik.tls=true - traefik.http.routers.traefik.service=api@internal - traefik.http.services.api.loadbalancer.server.port=8080 volumes: traefik: ``` If you don't already have something like this you'd also need to add labels to the netbird containers to ensure it gets the proper certificate. Hope it helps!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#8771