用SSO、MFA和颗粒式访问控制将设备连接到一个安全的基于WireGuard的覆盖网络.
Start using NetBird at netbird.io
See Documentation
Join our Slack channel or our Community forum
🚀 We are hiring! Join us at https://netbird.io/careers
🤖 NetBird Agent Network (Beta)
Identity-aware access control for AI agents — keyless access to LLM APIs and private resources over the encrypted NetBird tunnel. See
agent-network/or read the docs at netbird.ai.
NetBird combines a configuration-free peer-to-peer private network and a centralized access control system in a single platform, making it easy to create secure private networks for your organization or home.
Connect. NetBird creates a WireGuard-based overlay network that automatically connects your machines over an encrypted tunnel, leaving behind the hassle of opening ports, complex firewall rules, VPN gateways, and so forth.
Secure. NetBird enables secure remote access by applying granular access policies while allowing you to manage them intuitively from a single place. Works universally on any infrastructure.
https://github.com/user-attachments/assets/10cec749-bb56-4ab3-97af-4e38850108d2
This is the quickest way to try self-hosted NetBird. It should take around 5 minutes to get started if you already have a public domain and a VM. Follow the Advanced guide with a custom identity provider for installations with different IdPs.
Infrastructure requirements:
Software requirements:
Steps
export NETBIRD_DOMAIN=netbird.example.com; curl -fsSL https://github.com/netbirdio/netbird/releases/latest/download/getting-started.sh | bashSee a complete architecture overview for details.
Note: The main branch may be in an unstable or even broken state during development.
For stable versions, see releases.
In November 2022, NetBird joined the StartUpSecure program sponsored by the Federal Ministry of Education and Research of the Federal Republic of Germany. Together with the CISPA Helmholtz Center for Information Security, NetBird brings security best practices and simplicity to private networking.
We build on open source technologies like WireGuard®, Pion ICE, and Rosenpass. We greatly appreciate the work these projects are doing, and we'd love it if you could support them too (e.g., by starring or contributing).
This repository is licensed under the BSD-3-Clause license, which applies to all parts of the repository except for the directories management/, signal/ and relay/. Those directories are licensed under the GNU Affero General Public License version 3.0 (AGPLv3). See the respective LICENSE files inside each directory.
WireGuard and the WireGuard logo are registered trademarks of Jason A. Donenfeld.
Netbird 反向代理 (traefik) 在后端导致 JavaScript 错误
Glibc DNS 解析器 (非 systemd) 无法将 CNAME 记录解析为本地 CGNAT IP
[ 严重错误 ] 使用不存在的用户调用 API 会导致系统运行速度过慢
在替换临时路由对端时 DNS 路由超时
管理员从对等网络映射中删除保存的名字服务器组
在自主托管的组合服务器上,使用 QUIC 中继与反向代理 (Traefik) — 是否正式不支持?
Linux: wt0 IP 上的嵌入式 DNS 解析器从不回答本地机器的查询(cross-peer 查询工作) – v0.78.1
IOS 上的 DNS 无法正常工作
反向代理: TLS 透传不工作
NetBird 路由和/或策略消失(由 `systemd-networkd` 删除)