mirror of
https://github.com/netbirdio/netbird.git
synced 2026-03-31 06:34:19 -04:00
Self Hosted quick install with Zitadel - Error 502 - openresty #868
Closed
opened 2025-11-20 05:18:55 -05:00 by saavagebueno
·
13 comments
No Branch/Tag Specified
main
feature/fleetdm
feat/byod-proxy
fix/pat-target-user-account-valdation
client-ipv6-android-ui
dependabot/go_modules/golang.org/x/image-0.38.0
client-ipv6-iptables
combined-migration-2
feature/use-local-keys-embedded
entire/checkpoints/v1
update-embedded-idp-user
mgmt-ipv6-addressing
crowdsec-integration
pcp-support
nat-pmp-upnp
refactor/unexport-getserverpublickey-add-healthcheck
fix/module-check-for-posturecheck-delete
client-ipv6-nftables
client-ipv6-routing
refactor/permissions-manager
feat/reseller-openapi-spec
client-ipv6-acl-usp
dependabot/go_modules/github.com/russellhaering/goxmldsig-1.6.0
fix-ssh-stop-deadlock
client-ipv6-ssh-netflow
client-ipv6-dns
client-ipv6-iface
proto-ipv6-overlay
dependabot/npm_and_yarn/proxy/web/picomatch-4.0.4
iptables-mangle-dnat-guard
fix/ssh-proxy-command-quoting
fix/userspace-native-firewall
dependabot/go_modules/filippo.io/edwards25519-1.1.1
dependabot/npm_and_yarn/proxy/web/multi-770cfcd984
dependabot/npm_and_yarn/proxy/web/rollup-4.60.0
dependabot/npm_and_yarn/proxy/web/flatted-3.4.2
chore/proxy-web-packages
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
nmap/cleanup
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
fix/policy-upd
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
dependabot/go_modules/github.com/pion/dtls/v3-3.0.11
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
local-dns-listener
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
dependabot/go_modules/github.com/quic-go/quic-go-0.57.0
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
fix/login-cmd-root-flags
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
feature/changeset
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
dependabot/go_modules/github.com/docker/docker-28.0.0incompatible
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2022 Q1
2022 Q1
accessibility
acl
agent
agent
Android
Android
api
authentik
automation
azure
battery-usage
bug
cache
client
client-ui
cloud
cloud-only
cloudflare
community
compatibility
config-idp
config-issue
connection
contribution
coturn
cross-vpn
dashboard
data-usage
distribution
dns
docker
documentation
duplicate
enhancement
enhancement
event-stream
feature-request
freebsd
getting-started
go
good first issue
gui
help wanted
home-assistant
idp
inconsistency
integration
integrations
ios
ipv6
jwt
k8s
keycloak
linux
login
macos
management-service
missing-docs
mobile
moved-internal
needs-review
netbird-ui
networking
new-platform
nginx
notification
okta
openwrt
packaging
peer-management
peer-management
peer-management
performance
postgres
posture-checks
psk
pull-request
question
refactor
relay
release
rfc
routes
security
security-related
self-hosting
server
signal
sleep-issue
ssh
ssl
status
store
synology
system-compatibility-issue
test-suite
third-party-integration
triage
triage-needed
troubleshooting
UX
waiting-feedback
windows
wontfix
zitadel
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
saavagebueno
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: SVI/netbird#868
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @HybridRCG on GitHub (May 10, 2024).
I run the install.
No issues on screen. tells met to go to my domain with this username and password.
I get error 502. Bad Gateway.
Doing a docker PS I see my management server is restarting.
logs for management container as follows. (i replaced my domain name. with example.com
2024-05-10T13:55:18Z INFO management/cmd/management.go:455: loading OIDC configuration from the provided IDP configuration endpoint https://example.com/.well-known/openid-configuration
<head></head>Error: failed reading provided config file: /etc/netbird/management.json: OIDC configuration request returned status 502 with response: <html>
502 Bad Gateway
openresty </html>
This duplicates over and over on every restart of management container.
Tried restarting the server,
Ubuntu 24.04 and tried Ubuntu 22.4.
Updated all updates.
Fixed ip on Ubuntu server running on proxmox.
I use Nginx as on a diffrent container wich portforwards https > 192.168.1.1 , port 443 , with a Lets encrypt SSL through Cloudflare.
Please specify whether you use NetBird Cloud or self-host NetBird's control plane.
NetBird version
Self-hosted : latest
@mlsmaycon commented on GitHub (May 11, 2024):
Hello @HybridRCG can you please share the logs from the management service? you can get them with the following command:
docker compose logs management
@HybridRCG commented on GitHub (May 11, 2024):
Hi Thanks for the help!
This is some of the log file entries there. They are all identical a few seconds apart.
management-1 | Error: failed reading provided config file: /etc/netbird/management.json: OIDC configuration request returned status 502 with response: <html>
management-1 | <head></head>
management-1 |
management-1 |
502 Bad Gateway
management-1 |
openresty
management-1 |
management-1 | </html>
management-1 |
management-1 | 2024-05-11T09:54:53Z INFO management/cmd/management.go:455: loading OIDC configuration from the provided IDP configuration endpoint https://nb.groblers.co.uk/.well-known/openid-configuration
management-1 | Error: failed reading provided config file: /etc/netbird/management.json: OIDC configuration request returned status 502 with response: <html>
management-1 | <head></head>
management-1 |
management-1 |
502 Bad Gateway
management-1 |
openresty
management-1 |
management-1 | </html>
management-1 |
management-1 | 2024-05-11T09:55:07Z INFO management/cmd/management.go:455: loading OIDC configuration from the provided IDP configuration endpoint https://nb.groblers.co.uk/.well-known/openid-configuration
management-1 | Error: failed reading provided config file: /etc/netbird/management.json: OIDC configuration request returned status 502 with response: <html>
management-1 | <head></head>
management-1 |
management-1 |
502 Bad Gateway
management-1 |
openresty
management-1 |
management-1 | </html>
management-1 |
management-1 | 2024-05-11T09:55:33Z INFO management/cmd/management.go:455: loading OIDC configuration from the provided IDP configuration endpoint https://nb.groblers.co.uk/.well-known/openid-configuration
management-1 | Error: failed reading provided config file: /etc/netbird/management.json: OIDC configuration request returned status 502 with response: <html>
management-1 | <head></head>
management-1 |
management-1 |
502 Bad Gateway
management-1 |
openresty
management-1 |
management-1 | </html>
management-1 |
@mlsmaycon commented on GitHub (May 11, 2024):
It seems like there is an issue with either caddy or zitadel, can you please share all logs?
docker compose logs
@HybridRCG commented on GitHub (May 11, 2024):
logs :
WARN[0000] /home/hybrid/netbird/infrastructure_files/artifacts/docker-compose.yml:
versionis obsoletedashboard-1 | + LETSENCRYPT_DOMAIN=nb.groblers.co.uk
dashboard-1 | + LETSENCRYPT_EMAIL=riaangrobler@me.com
dashboard-1 | + NGINX_SSL_PORT=443
dashboard-1 | + '[' nb.groblers.co.uk-x == none-x ']'
dashboard-1 | + certbot -n --nginx --agree-tos --email riaangrobler@me.com -d nb.groblers.co.uk --https-port 443
dashboard-1 | NetBird latest version:
dashboard-1 | Saving debug log to /var/log/letsencrypt/letsencrypt.log
dashboard-1 | NetBird latest version:
dashboard-1 | Requesting a certificate for nb.groblers.co.uk
dashboard-1 |
dashboard-1 | Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
dashboard-1 | Domain: nb.groblers.co.uk
dashboard-1 | Type: unauthorized
dashboard-1 | Detail: 41.149.60.65: Invalid response from https://nb.groblers.co.uk/.well-known/acme-challenge/bXtOOWgctTOU2-SPDJfxqZpxz4vk32WcuHnek0A5g94: 404
dashboard-1 |
dashboard-1 | Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
dashboard-1 |
dashboard-1 | Some challenges have failed.
signal-1 | 2024-05-11T06:03:10Z INFO signal/cmd/run.go:110: running gRPC backward compatibility server: [::]:10000
signal-1 | 2024-05-11T06:03:10Z INFO signal/cmd/run.go:132: running gRPC server: [::]:80
signal-1 | 2024-05-11T06:03:10Z INFO signal/cmd/run.go:135: signal server version 0.27.4
signal-1 | 2024-05-11T06:03:10Z INFO signal/cmd/run.go:136: started Signal Service
signal-1 | 2024-05-11T06:10:39Z INFO signal/cmd/run.go:110: running gRPC backward compatibility server: [::]:10000
signal-1 | 2024-05-11T06:10:39Z INFO signal/cmd/run.go:132: running gRPC server: [::]:80
signal-1 | 2024-05-11T06:10:39Z INFO signal/cmd/run.go:135: signal server version 0.27.4
signal-1 | 2024-05-11T06:10:39Z INFO signal/cmd/run.go:136: started Signal Service
dashboard-1 | Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
dashboard-1 | 2024-05-11 06:03:24,805 WARN received SIGINT indicating exit request
dashboard-1 | 2024-05-11 06:03:24,805 WARN received SIGINT indicating exit request
dashboard-1 | + LETSENCRYPT_DOMAIN=nb.groblers.co.uk
dashboard-1 | + LETSENCRYPT_EMAIL=riaangrobler@me.com
dashboard-1 | + NGINX_SSL_PORT=443
dashboard-1 | + '[' nb.groblers.co.uk-x == none-x ']'
dashboard-1 | + certbot -n --nginx --agree-tos --email riaangrobler@me.com -d nb.groblers.co.uk --https-port 443
dashboard-1 | NetBird latest version:
dashboard-1 | Saving debug log to /var/log/letsencrypt/letsencrypt.log
dashboard-1 | NetBird latest version:
dashboard-1 | Requesting a certificate for nb.groblers.co.uk
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:10:46 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03D\xC8{\x0By\x10y\xB3\xED\xB1\xB7\xA7\x1F\x05j\xB2R\x8A\x1D[j@\x90;\x03\xA6$\xB9\x92{?U\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:10:48 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03?w\xFC\xFE\x9Bv6i" 400 150 "-" "-" "-"
dashboard-1 |
dashboard-1 | Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
dashboard-1 | Domain: nb.groblers.co.uk
dashboard-1 | Type: unauthorized
dashboard-1 | Detail: 41.149.60.65: Invalid response from https://nb.groblers.co.uk/.well-known/acme-challenge/WX7bdhcXbhNji0JqnWAWEntbWirZsuzB0FhfebNp4c8: 404
dashboard-1 |
dashboard-1 | Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
dashboard-1 |
dashboard-1 | Some challenges have failed.
dashboard-1 | Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:10:53 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03\xAB\xB4\xC7\xEC\x8E\xC0D]\xBCJ\xD9\x8F\xD3\xAB\xBA<\x0EN>\xF9\x0B\xCC\xCD/+\xD5Y\x13\xC2\x09\x8F\xBB\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:11:02 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03e'J\x84\xFB\xEA\xE7\xF4\xA6K\xE7\xF4\x02\x89\xBB;\xD5\x1EE\xD7\x82\x9B;d`G/\xE5\x072\xD9\xB0\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:11:11 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03L\xAE\xA0\xE0\x9C\xF8-\x01\x04U\xF9\x88\x87\xAF\x06hI\xF4\x1F\xBB\xE0\x1C\xE3\xB6w\xA19&t\xED\xB2l\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:11:18 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03\xD3\xF2\xA7" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:59:54 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03\xE0@\xE1\x0C\xB1\x03{\x02\x9De\xFB?\xF9{IU}" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:06:59:54 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03\xA2\xE2J\x9C&\x1C\xCE\xC3%M;\xE9\xBC\xFCkF\xEB.\x89L2#D\x0F\x8C\x1E\xA4\x9C\xF6=\xB6\x9D\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:07:00:03 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03\xB4\x83Y\x97\x95r8V\xE1\x1C\xD7[o4\x1A24u\x0BZr\xA0\xB1E\xE5\x1Eu\xD2\x22\x0EB\x95\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:07:00:05 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03#\xEC3\xDD\x9F\x06w,d^X\xCB\xFC\xE6\x09\xE5\xDBT\xC5\xB8\x1A\xFC\x22\x12J9[>utt\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:07:00:07 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03B\xBF\xABNJP\xF6\xA4\xEBW\xA5\xA1\xEB\x9C2:F\x90*|'1\x00\x0F\xC2\xEC5&\x97~\xE8!\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:07:00:07 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03J\xBD\x03\xE2;\x9E\xC3\xD5\xC6RP\x09\xDA[\x04\xC1m\x15/b\xEA\xABr\x86\x1F\xE2\xE3@\xBE\x17\x0F\x1F\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
dashboard-1 | 192.168.1.3 - - [11/May/2024:07:00:49 +0000] "\x16\x03\x01\x00\xB7\x01\x00\x00\xB3\x03\x03\xCC\x11&Z\x06\x1D\xEF\xE8\xA3\xDE\x9E\xF8\x1E\xFD\xDClV\x0F:\x9D)?\xED\x1F@R\x96\x9A\xD3!\x8A@\x00\x008\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0'\x00g\xC0" 400 150 "-" "-" "-"
@mrcxs commented on GitHub (May 11, 2024):
I'm also having issues with 502 when I'm building.
management-1 | 2024-05-11T14:14:17Z INFO management/server/telemetry/app_metrics.go:177: enabled application metrics and exposing on http://0.0.0.0:8081 management-1 | 2024-05-11T14:14:17Z INFO management/server/store.go:95: using SQLite store engine management-1 | 2024-05-11T14:14:17Z INFO management/server/migration/migration.go:114: Table for peer.Peer does not exist, no migration needed management-1 | 2024-05-11T14:14:17Z INFO management/server/migration/migration.go:114: Table for peer.Peer does not exist, no migration needed management-1 | 2024-05-11T14:14:17Z INFO management/cmd/management.go:161: update config with activity store key@HybridRCG commented on GitHub (May 13, 2024):
Not sure why you would hijack a thread if the symptoms of your problem is not the same as mine?
Apart from the 502 the errors are totally diffrent. :)
@mrcxs commented on GitHub (May 13, 2024):
Nothing to do, he fixed it himself, and the next day he was able to access normally.
@HybridRCG commented on GitHub (May 13, 2024):
Ah ok.
Any insight ne my problem? :)
Just as a side note... If i use the self hosting quick option... Zitadel does not install if my nginx is pointing to https://ip:443 , Zitadel only installs if Nginx is pointing to http://IP:80.
I get this after the install with nginx on : http:IP/80..
You can access the NetBird dashboard at https://nb.groblers.co.uk
I can obviously not go to http , so trying to go provided adress gives me 502 gateway error.
@zoechi commented on GitHub (Sep 20, 2024):
I installed using NixOS and I saw the same error.
In my case it was a network issue and I had the same errors in the log as #2576
@nazarewk commented on GitHub (Apr 28, 2025):
Hello @HybridRCG,
We're currently reviewing our open issues and would like to verify if this problem still exists in the latest NetBird version.
Could you please confirm if the issue is still there?
We may close this issue temporarily if we don't hear back from you within 2 weeks, but feel free to reopen it with updated information.
Thanks for your contribution to improving the project!
@mlsmaycon commented on GitHub (Jun 1, 2025):
closing issue due to no recent feedback. Feel free to open a new one if the issue persist or reopen if this was a feature request.
@disarticulate commented on GitHub (Jul 20, 2025):
just installed via https://docs.netbird.io/selfhosted/selfhosted-quickstart
Can login, but it stalls at https://x/peers with 503
@disarticulate commented on GitHub (Jul 20, 2025):
I resolved this by editting the docker-compose.yaml and adding a custom resolv.conf file: