Skip to content

netbird: rework server and include new component - #354032

Closed
PatrickDaG wants to merge 3 commits into
NixOS:masterfrom
PatrickDaG:fix-netbird
Closed

PatrickDaG wants to merge 3 commits into
NixOS:masterfrom
PatrickDaG:fix-netbird

Conversation

@PatrickDaG

Copy link
Copy Markdown
Contributor

This is a pretty hefty rework of the nixos netbird modules.

First of all I split the package into three because currently you cannot have the client installed without the server components coming with it, now it's three packages, a client, a client with gui and a server.
You still have the option to build a package containing everything but I don't think most people need that.

Secondly I wrote a basic test for the server, now we at least know if it starts, which it currently doesn't cause upstream introduced clashing ports for all server, that cannot be disabled.
I would love further testing but I think that would need actually logging in into the kanidm instance inside the testing framework, which is something for another day.
The test also currently depend on #353681.

Netbird is currently switching away from coturn in favour of their own relay implementation, which this pull adds.
Their communication towards whether coturn will be needed going forward is a bit confusing, but I'm pretty sure right now you need both their relay and coturn, maybe in a few updates we can remove coturn.

Lastly I reworked the nginx setup, realizing you don't necesarrily need it, apart from serving the dashboard.
I removed it from all services and the default setup should now work without it, but you have to forward and open all relevant ports, for the management, signal, coturn, dashboard and relay.

To make it easier for people using nginx as a reverse proxy I've added the proxy, module which is written and maintained completely by myself and has no affiliation to upstream netbird. I do plan on using this and think it's valuable to have even just as a documentation of nginx options to use with netbird, but I am scared that people have problems with this module and complain to upstream netbird. Don't really know what to do whether to include or not, feedback appreciated.

In general this isn't extensively tested yet, but I would be very happy if people help me test it.
It has to wait for branch off anyway because it contains a bunch of breaking changes.

Also should probably write more documentation especially regarding the proxy module.

Things done

  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandboxing enabled in nix.conf? (See Nix manual)
    • sandbox = relaxed
    • sandbox = true
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 24.11 Release Notes (or backporting 23.11 and 24.05 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
  • Fits CONTRIBUTING.md.

Add a 👍 reaction to pull requests you find important.

@github-actions github-actions Bot added 6.topic: nixos Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS 8.has: module (update) This PR changes an existing module in `nixos/` labels Nov 6, 2024
@ofborg ofborg Bot added the 8.has: package (new) This PR adds a new package label Nov 6, 2024
@ofborg
ofborg Bot requested review from a user and Saturn745 November 6, 2024 18:39
@ofborg ofborg Bot added 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. labels Nov 6, 2024
@wegank wegank added the 2.status: merge conflict This PR has merge conflicts with the target branch label Nov 10, 2024
@h7x4 h7x4 added 8.has: module (new) This PR adds a module in `nixos/` 8.has: tests This PR has tests labels Nov 11, 2024
Comment thread nixos/modules/services/networking/netbird/dashboard.nix Outdated
@PatrickDaG
PatrickDaG force-pushed the fix-netbird branch 2 times, most recently from d6f32bf to 67b0145 Compare November 12, 2024 18:33
@ofborg ofborg Bot removed the 2.status: merge conflict This PR has merge conflicts with the target branch label Nov 13, 2024
@ofborg
ofborg Bot requested review from a user and Saturn745 November 13, 2024 06:30
@Saturn745

Copy link
Copy Markdown
Member

Result of nixpkgs-review pr 354032 run on x86_64-linux 1

2 packages blacklisted:
  • nixos-install-tools
  • tests.nixos-functions.nixos-test
3 packages built:
  • netbird
  • netbird-server
  • netbird-ui

@ghost

ghost commented Nov 14, 2024

Copy link
Copy Markdown

Result of nixpkgs-review pr 354032 run on x86_64-linux 1
2 packages blacklisted:
nixos-install-tools tests.nixos-functions.nixos-test

3 packages built:
netbird netbird-server netbird-ui

Same here, also on x86_64-linux. :)

@TheRealGramdalf

TheRealGramdalf commented Nov 17, 2024 •

Copy link
Copy Markdown
Contributor

Fellow user of Kanidm/Netbird here. Can confirm that the server is non functional at the moment, again due to clashing ports. For now I'm going to have to override the signal/mgmt metrics port manually (by editing the systemd service), since there's currently no extraArgs setting or the like for the netbird components.
Edit: Turns out there's an extraOptions for the management server, but not the signal server. I fixed the port clash by adding

services.netbird.server.management.extraOptions = [ "--metrics-port=9091" ];

to my configuration.

...Is it worth creating a separate PR to fix that the port clash in the meantime?

Also please let me know if I can help with testing in any way.

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

Might be a good idea to put the extraOption in separate PR so they get merged sooner. I feel like this one still has quite the journey ahead.
You wanna do it? Else I can make one in a few days.

More eyes and people testing are always welcome. I'm just gonna run the new module while I work on this PR for a few weeks and see if anything comes up. Seems like right now the blocker for both of us is kanidm kanidm/kanidm#3217

@TheRealGramdalf

Copy link
Copy Markdown
Contributor

Might be a good idea to put the extraOption in separate PR so they get merged sooner. I feel like this one still has quite the journey ahead.
You wanna do it? Else I can make one in a few days.

Yeah, can do - I was thinking add an extraOption to signal, and potentially even adding my snippet above as the default for one of them so it works out of the box again?
Or would adding a dedicated metrics option be better?

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

I would say you could just add your snippet as the default and we can always switch to a dedicated option later, but thinking about it I'm not sure the newest update will work without the relay server packaged and setup so I'm not sure a new PR is worth it if it won't work anyway.

@TheRealGramdalf

Copy link
Copy Markdown
Contributor

...but thinking about it I'm not sure the newest update will work without the relay server packaged and setup so I'm not sure a new PR is worth it if it won't work anyway.

I'm on nixpkgs dc460ec76cbff0e66e269457d7b728432263166c, netbird v0.31.0, and my peers using setup keys (i.e. not depending on OIDC) are functioning just fine. #356512 was just merged though so I'm not sure if that changes things, the release notes don't seem to indicate anything however. I'll open a PR to add the snippet and hold off on a dedicated option for now, and I'll throw in an extraOptions to signal to make things easier in case things change down the line.

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

I'm on nixpkgs dc460ec76cbff0e66e269457d7b728432263166c, netbird v0.31.0, and my peers using setup keys (i.e. not depending on OIDC) are functioning just fine.

Oh nice. Wasn't sure how much they already depend on the relay.

I'll open a PR to add the snippet and hold off on a dedicated option for now, and I'll throw in an extraOptions to signal to make things easier in case things change down the line.

Sounds great.

I'll try and finish this one soon as well, now that the branchoff happened.

@TheRealGramdalf

Copy link
Copy Markdown
Contributor

PR opened, input would be appreciated @PatrickDaG

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm pretty sure there should be a way to supply this value externally instead of putting inside /nix/store

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

something like config.d/*.json directory merged recursively by jq before the start of the service could work

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

NetBird already natively supports loading this encryption key from a file, with DataStoreEncryptionKey._secret set to an arbitrary path.

nixos/netbird: introduce standalone proxy module
@nixpkgs-ci nixpkgs-ci Bot added 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. and removed 2.status: merge conflict This PR has merge conflicts with the target branch 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. labels Sep 5, 2025
@PatrickDaG

Copy link
Copy Markdown
Contributor Author

Rebased on master. Hope I didn't break anything. Should be ready again.

grpc_send_timeout 1d;
grpc_socket_keepalive on;
'';
locations."/relay".extraConfig = ''

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That doesn't seem right to always host relay on the same host as the control plane, I think it should be split into a different option that is possible to enable without the management/signal

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I see your point. However I intend the proxy module to be a easiest possible setup frontend, so people just have to enable a single option for hosting the complete stack. Anything beyond that I don't think we can anticipate what the setups look like.
What if they have the signal on another server? What if the api and dashboard aren't shared?

I would like to keep it as easy as possible and if people have more complicated setups, they can look at the configuration and adapt it to their needs.

But if a split is needed for this to be finally merged I can do it after the 25.11 release, it shouldn't be merged beforehand anyway.

@nazarewk nazarewk Oct 31, 2025 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we could easily make the specific pieces optional in follow-up PRs. Seems like it would be pretty much a bunch of default-on *.enable options combined with mkIfs

@nixpkgs-ci nixpkgs-ci Bot removed the 12.approvals: 1 This PR was reviewed and approved by one person. label Nov 6, 2025
@timoschirmer

Copy link
Copy Markdown

I just stumbled across this PR while trying to finally migrate my Netbird deployment to NixOS. The fact that the relay cannot be configured via the Netbird module is currently preventing me from doing so. Is there anything still preventing the merge, and/or is there a timeline for it? I would really appreciate seeing this implemented.

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

Just as an update. I don't use netbird anymore, and currently don't intend to switch back to it anytime soon, so my motivation to keep pushing this PR is limited. If anyone wants to adopt it I'd be more than happy to hand it over. I think it should be basically merge ready for now, so the only thing missing is someone willing to pester committers to get it over the line.

@TheRealGramdalf

Copy link
Copy Markdown
Contributor

Just as an update. I don't use netbird anymore, and currently don't intend to switch back to it anytime soon, so my motivation to keep pushing this PR is limited.

I'm curious, do you use something else or do you not need a self hosted VPN anymore? I'm not terribly happy with the multi-user situation in netbird right now, most features are only available on their cloud version.

If anyone wants to adopt it I'd be more than happy to hand it over. I think it should be basically merge ready for now, so the only thing missing is someone willing to pester committers to get it over the line.

Assuming I don't end up switching as well I could probably pick that up, but not sure when I'll have time. Is it mostly just resolving merge conflicts or does it need release notes and upgrade documentation as well?

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

I'm curious, do you use something else or do you not need a self hosted VPN anymore? I'm not terribly happy with the multi-user situation in netbird right now, most features are only available on their cloud version.

I've switched to firezone. Their network model seems to fit my use-case better.

Assuming I don't end up switching as well I could probably pick that up, but not sure when I'll have time. Is it mostly just resolving merge conflicts or does it need release notes and upgrade documentation as well?

I think it should just be merge conflicts, as far as I can tell.

@RafaelKr

RafaelKr commented Jan 21, 2026 •

Copy link
Copy Markdown
Contributor

I'm not terribly happy with the multi-user situation in netbird right now, most features are only available on their cloud version.

@TheRealGramdalf Could you elaborate on what you mean with the multi-user situation? We're currently evaluating using netbird in an enterprise environment.

BTW with version 0.64.0 (released yesterday) coturn is not required anymore: https://github.com/netbirdio/netbird/releases/tag/v0.64.0

@schromp

schromp commented Jan 21, 2026

Copy link
Copy Markdown
Contributor

i have resolved the merge conflicts aswell as tested 0.63.0 yesterday. (going to do 0.64 today i guess)
Any way i can have access to this PR to update it or should i create a new one?

Btw ive been running netbird based on this PR for about 5 months now

@TheRealGramdalf

Copy link
Copy Markdown
Contributor

I'm not terribly happy with the multi-user situation in netbird right now, most features are only available on their cloud version.

@TheRealGramdalf Could you elaborate on what you mean with the multi-user situation? We're currently evaluating using netbird in an enterprise environment.

As far as I'm aware, the self hosted version does not allow you to sync permissions based on information from your IDP - it also seems like each user has their own network with their own individual peers, and I haven't found a way to link multiple accounts together so that user A can access peers from user B. Syncing permissions is available on the cloud version, not sure about multi-user networks.

@TheRealGramdalf

Copy link
Copy Markdown
Contributor

@RafaelKr Actually an update on this, I was just looking through the docs and it appears that group syncing is available on the self hosted version now. Not sure which release added that, though I'd guess 0.63.0 (when configuring IDPs via the dashboard was added). I'm not sure about the multi-user situation yet though, I'll have to check out the new version and see how it works out.

@timoschirmer

Copy link
Copy Markdown

@RafaelKr Actually an update on this, I was just looking through the docs and it appears that group syncing is available on the self hosted version now. Not sure which release added that, though I'd guess 0.63.0 (when configuring IDPs via the dashboard was added). I'm not sure about the multi-user situation yet though, I'll have to check out the new version and see how it works out.

I've been using netbird for around one and a half years now and group sync was already available when I started so definitely not a new thing. I'm not sure whether I understand you multi-user needs correctly but maybe single-account-mode is what you want: https://docs.netbird.io/selfhosted/selfhosted-guide#step-4-disable-single-account-mode-optional
All users are under one "account". They still have their separate logins, but all clients are connected in the same network.

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

i have resolved the merge conflicts aswell as tested 0.63.0 yesterday. (going to do 0.64 today i guess) Any way i can have access to this PR to update it or should i create a new one?

Btw ive been running netbird based on this PR for about 5 months now

Thanks @schromp , I don't think there is a way I can hand over this PR? So I think you'll have to open a new one.

@bct

bct commented Jan 26, 2026

Copy link
Copy Markdown
Contributor

This PR (schromp's clone) is working for me. With netbird-relay 0.64.1 (recently merged: #483538) coturn is not required at all. That seems to simplify things significantly.

My config (hacked together, can probably be simplified):
https://gist.github.com/bct/d860702d49540bdf34dff80f468fecea

@timoschirmer

Copy link
Copy Markdown

Is there any update on this PR or a new one? @schromp

@schromp

schromp commented Feb 19, 2026

Copy link
Copy Markdown
Contributor

Is there any update on this PR or a new one? @schromp

No i did not have time sadly.

#487367 got opened though

@PatrickDaG PatrickDaG mentioned this pull request Mar 24, 2026
13 tasks
@woile

woile commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

hey @PatrickDaG is it okay if I start new PR's based on your work? Since you are not using netbird anymore, I want to slowly start pushing one module at a time (starting with the relay).

I have to run everything on my configuration first to make sure it works. Any advice I should keep in mind?

@PatrickDaG

Copy link
Copy Markdown
Contributor Author

Absolutely, go for it. You might also want to look at #487367 and the people who commented, so you don't get in each others way.
I'll close this PR since I am pretty sure I will not come back to it, but if you or anyone can reuse parts, I'd be happy to know the work wasn't completely wasted.

It's been so long since I've run this stack, I don't remember much, sorry.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

2.status: merge conflict This PR has merge conflicts with the target branch 6.topic: nixos Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS 8.has: documentation This PR adds or changes documentation 8.has: module (new) This PR adds a module in `nixos/` 8.has: module (update) This PR changes an existing module in `nixos/` 8.has: package (new) This PR adds a new package 8.has: tests This PR has tests 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux.

Projects

None yet

Development

Successfully merging this pull request may close these issues.