Help: How to control users with specific roles in ZITADEL using Netbird? #2043

Open
opened 2025-11-20 06:11:45 -05:00 by saavagebueno · 2 comments
Owner

Originally created by @Cikaros on GitHub (Jul 5, 2025).

How can I assign Netbird usage rights to users by granting them specific roles in ZITADEL?

Assume there are two users, a and b, in ZITADEL. I want user a to be able to log in to Netbird, but not allow user b to log in to Netbird. How can this be achieved?

Originally created by @Cikaros on GitHub (Jul 5, 2025). How can I assign Netbird usage rights to users by granting them specific roles in ZITADEL? Assume there are two users, a and b, in ZITADEL. I want user a to be able to log in to Netbird, but not allow user b to log in to Netbird. How can this be achieved?
saavagebueno added the triage-needed label 2025-11-20 06:11:45 -05:00
Author
Owner

@Cikaros commented on GitHub (Jul 6, 2025):

@pappz @mlsmaycon Excuse me, does the current Netbird support this function? ( I haven't found any relevant instructions in any document)

@Cikaros commented on GitHub (Jul 6, 2025): @pappz @mlsmaycon Excuse me, does the current Netbird support this function? ( I haven't found any relevant instructions in any document)
Author
Owner

@laweschan commented on GitHub (Jul 8, 2025):

you are asking product about zitadel but put in question in netbird .....

in your question, "user a" belong to project "netbird", and also belong to default organization.
if "user b" not belong to project "netbird", then he should not grant any access... so you can create new organization in zitadel, create new application and new project, user will not cross unless grant.

however, zitadel in older version not support multiple organization setting in self-hosted, but it work in updated release, at least I'm using netbird + zitadel v3.3.0

here also has another solutions:
-user a and user b under same organization, hence netbird can discover it
-user a has been assign to zitadel roles, and that roles also preset ACL in netbird
-user b has not assign to zitadel roles, or that roles not setup any ACL in netbird
-in such case, even user b can still login into netbird, in won't grant resources

@laweschan commented on GitHub (Jul 8, 2025): you are asking product about zitadel but put in question in netbird ..... in your question, "user a" belong to project "netbird", and also belong to default organization. if "user b" not belong to project "netbird", then he should not grant any access... so you can create new organization in zitadel, create new application and new project, user will not cross unless grant. however, zitadel in older version not support multiple organization setting in self-hosted, but it work in updated release, at least I'm using netbird + zitadel v3.3.0 here also has another solutions: -user a and user b under same organization, hence netbird can discover it -user a has been assign to zitadel roles, and that roles also preset ACL in netbird -user b has not assign to zitadel roles, or that roles not setup any ACL in netbird -in such case, even user b can still login into netbird, in won't grant resources
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#2043