← All transcripts

You Seriously Need to Try NetBird (RIGHT NOW) Transcript, AI Summary & Key Points

TechHut · yesterday · Science & Technology · 15:13 · EN

Watch on YouTube

AI Summary

NetBird provides free, open-source, self-hostable remote access infrastructure using WireGuard peer-to-peer connections, with relay servers as a fallback. Its newer features include Control Center draft mode, visual network and policy editing, routing peers, identity-based NetBird SSH, temporary exposure of local services, reverse proxying through a remote VPS, NetBird-only private services, local users with MFA, remote DNS, and ad blocking. NetBird also offers a cloud account for up to five users and, according to the transcript, approximately 100 devices for free. Planned or developing features include DNS-01 certificate authentication, improved proxy routing, proxy clusters, an agent network for AI access without API keys, and light mode.

Key Points

  • NetBird is free and open source across its clients, control plane, relay servers, signal services, and other components; a business license adds features such as high availability and IDP sync.
  • Control Center draft mode starts from the current peer view, lets users add infrastructure such as servers, and supports reviewing and deploying changes through the API.
  • A routing peer can run in an LXC, with a setup key and management URL used to connect it to a self-hosted NetBird installation. NetBird can also be installed directly on Proxmox.
  • Access policies can be created visually by dragging a user group onto a peer, adding posture checks, reviewing the proposed policy, and deploying it.
  • Networks can be edited visually by adding resources such as IP addresses and viewing users, devices, policies, and resources.
  • NetBird uses WireGuard for strict peer-to-peer connections and falls back to a relay server when a peer-to-peer connection cannot be established.
  • NetBird SSH authenticates users through their NetBird identity instead of an SSH key or password when enabled on the target peer and in the dashboard.
  • NetBird expose can publish a local development service, such as a project running on port 3000, through a temporary domain. The exposed service can be password-protected or require identity authentication, and its reverse-proxy instance disappears when the command stops.

Tools & resources

9 items

DNo. 4703
AIAINotes.us Tool

Dex

dexidp.io

Dex is an open-source federated OpenID Connect provider developed under the Cloud Native Computing Foundation. It sits between applications and identity sources such as LDAP, SAML, GitHub, Google, GitLab, Microsoft, and other OIDC providers, exposing those sources through a standard OIDC interface so applications do not need separate authentication integrations. Dex is distributed as a single Go binary, container, or Kubernetes deployment, with configuration, clients, storage, and connectors defined in YAML; it includes a login UI and supports Kubernetes single sign-on and local development through a mock connector. In the cited NetBird setup, Dex handles local-user authentication in the background.

Mentioned in
1 video
Kind
Other
LNo. 4700
AIAINotes.us Tool

LXC

In the AINotes directory

LXC is a lightweight container technology. In the cited setup, it runs a NetBird routing peer.

Mentioned in
1 video
Kind
Other
NNo. 4707
AIAINotes.us Tool

NetBird

Open source · netbirdio/netbird

NetBird is an open-source, WireGuard-based overlay networking and Zero Trust Network Access platform for connecting remote users, cloud and on-premises resources, edge devices, containers, and agents through peer-to-peer encrypted tunnels. Its agents manage WireGuard connections, obtain peer candidates through ICE and STUN, exchange connection information through a signaling service, and use a relay when direct connections fail. A centralized management service maintains network state, peer addresses, access policies, and configuration updates, while the admin interface supports identity-based access control, network segmentation, SSO, MFA, device posture checks, private DNS, routes, exit nodes, SSH, reverse proxying, activity logging, and integrations such as Terraform and Ansible. NetBird can run as a hosted cloud service or be self-hosted; its repository includes the client, management, signal, and relay components, with most code licensed under BSD-3-Clause and the management, signal, and relay directories under AGPLv3.

Mentioned in
3 videos
Kind
Other
NNo. 4705
AIAINotes.us Tool

NetBird Cloud

Open source · netbirdio/netbird

NetBird Cloud is the hosted version of NetBird, a WireGuard-based overlay network and Zero Trust Network Access platform for connecting remote users, cloud infrastructure, on-premises resources, edge devices, and private services without self-hosting the control plane. It provides centralized network management with identity-based access policies, user and group provisioning, network segmentation, DNS configuration, SSO and MFA, device-posture checks, activity logging, and API-based automation. NetBird uses peer-to-peer WireGuard connectivity and is designed to avoid traditional VPN gateways, firewall configuration, and exposed ports. NetBird Cloud is available alongside the open-source, BSD-3-licensed self-hosted edition and offers a free plan.

Mentioned in
1 video
Kind
Other
NNo. 4706
AIAINotes.us Tool

NetBird Self-Hosted

In the AINotes directory

NetBird Self-Hosted is an open-source deployment of NetBird, a zero-trust networking platform for creating private networks that connect directly to servers and other peers through WireGuard. Its self-hosting setup uses an installation script and can deploy Traefik with automatic TLS, built-in local-user authentication through an embedded Dex server, and an optional reverse-proxy service for exposing resources on the NetBird network. A NetBird client can also operate as a routing peer for services on a Docker subnet, while access policies, remote DNS, NetBird SSH, identity authentication, and service exposure are managed through the platform.

Mentioned in
1 video
Kind
Other
PNo. 4702
AIAINotes.us Tool

Pocket ID

pocket-id.org

Pocket ID is a self-hosted OpenID Connect and OAuth 2.0 identity provider that authenticates users with passkeys instead of passwords. It provides group-based access control, LDAP integration, SCIM provisioning, audit logs, a REST API for administration, and resource-specific OAuth tokens with configurable scopes. Applications and APIs can use Pocket ID for passwordless sign-in, while compatible AI applications and remote MCP servers can use it as an OAuth provider.

Mentioned in
1 video
Kind
Other
PNo. 4699
AIAINotes.us Tool

Proxmox

proxmox.com

Proxmox develops open-source server solutions, including Proxmox Virtual Environment, Proxmox Backup Server, Proxmox Mail Gateway, and Proxmox Datacenter Manager. Proxmox Virtual Environment provides a web interface for managing virtual machines and containers, software-defined storage and networking, high-availability clustering, and related data-center tools. The company also provides documentation, training, enterprise support, and implementation services.

Mentioned in
1 video
Kind
Other
TNo. 4704
AIAINotes.us Tool

TryHackMe

tryhackme.com

TryHackMe is a browser-based cybersecurity learning service with interactive rooms for practicing security concepts, including beginner exercises on finding and exploiting vulnerabilities. It also provides a learning roadmap and offers free learning alongside paid annual subscriptions.

Mentioned in
1 video
Kind
Other
WNo. 4701
AIAINotes.us Tool

WireGuard

wireguard.com

WireGuard is a cross-platform VPN tunnel and network interface for securely encapsulating IP packets over UDP. It uses a private key for each interface and public keys for peers; its Cryptokey Routing mechanism associates peers with allowed tunnel IP addresses, which select encrypted destinations when sending and act as an access-control check when receiving. The project uses cryptographic components including the Noise protocol framework, Curve25519, ChaCha20, Poly1305, BLAKE2, SipHash24, and HKDF. It is configured through the wg tool and ordinary system networking utilities, supports roaming between IP addresses, and is designed for use from embedded devices to backbone routers.

Mentioned in
1 video
Kind
Other

AI in practice

Used for

Links mentioned

🔒 Full analysis locked

Unlock more videos and the full analysis

A credit unlocks one video's full analysis for good — the build steps, the tools and how each was used, the methods behind every use case. Pro opens the whole library instead, and raises how many videos you can analyse a day.

Unlock full analysis — free

Transcript

Searchable transcript of You Seriously Need to Try NetBird (RIGHT NOW) — TechHut (15:13). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by TechHut. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:00 This right here is NetBird. It is by far one of the best, if not the very best, way for you to remotely access your infrastructure from anywhere you have an internet connection. Do I have an incredible bias in that statement? Absolutely, I do. But, what I can say that not many others can is that it is completely free and open source from the clients you install on your servers and your infrastructure to the whole entire control plane, relay servers, signal, and everything.

00:28 There is a business license with things like high availability and IDP sync, but for a vast majority of people with a home lab or even small businesses, this community edition is going to have more than what you need. And of course, this isn't the very first time I've talked about NetBird. The whole reason for this video is since the last time, there have been so many feature additions, improvements, changes, just things worth highlighting as the NetBird engineering team has been absolutely going ham when it comes to

00:57 delivering features that the community wants. So, we're going to talk about that. We're going to talk about my setup, kind of give you a tour of what I have going on, sprinkling those new features and additions along the way. But, before all of that, we need to thank the sponsor of today's video. And that would be TryHackMe. I mean, not not me, the uh If you've ever wanted to actually learn security instead of just reading about it, TryHackMe is hands-on, everything runs in the browser, there's no VMs to build, no Kali

01:26 to install, nothing to break your own machine. Once you ever spent a Saturday trying to troubleshoot a hypervisor instead of the thing that you actually sat down to try to learn, you probably know why that matters. I've spent many of an hours trying to fix something with Proxmox I screwed up when I was experimenting. So, let me show you real quick here.

01:42 This is a room called Offensive Security Intro, free, beginner level. It drops you in front of a fake banking site and tells you to break in. I'll run DIRB against it, which just brute forces a site looking for pages that aren't linked anywhere. And would you look at that? There's images. What just nothing and then there's this, bank deposit. A page nobody meant for you to find that lets you add money into your own account.

02:06 That's the whole thing instead of reading about vulnerabilities, it actually puts you in one. There's over 1,100 rooms with a road map that tells you what to learn next. So, you're never really guessing what direction to go. Plenty of it is free. So, go ahead and poke around before actually paying anything. And if you do like it, you want premium, there's a link down below that will give you 30% off of their annual plan.

02:25 Do note, it's limited to one use and with that, let's get back into it. All right, so we are in Netbird here and the very first thing I want to highlight and this is a newer one is the control center. Before the control center just kind of give you a plain visualization, you really couldn't do much except for like click on policies for example and make edits that way.

02:45 But now we have draft mode. So, if I'm in a view like this, this is my peer view. So, for example, this right here is the current machine I'm recording this on. I have a few access policies associated with the user group I'm in allowing me to access a variety of resources. If I want to make edits to this, I can just click draft right here. We're going to start from the current view and look at that.

03:08 What we could do is click add down here and you could see all the different components. So, I can set up new infrastructure directly through here such as a server. So, actually if I did that real quick, let's just drag and drop the server right there. Obviously, it doesn't magically just install it on a server. I will demo this just by setting up a quick LXC with Netbird, which since it's an LXC, this is mostly going to be functioning as a routing peer.

03:34 So, in our shell, we just drop this in. Which if you need to set up a routing peer, this is the easy way to do it. You can also install the Netbird client directly onto Proxmox if that's what you're running. But there's a chance you might need to disable Netbird DNS as it may conflict with the DNS on Proxmox, but I haven't seen that issue come up in quite a while.

03:53 You have a command to install it, but what we're going to do real quick is just generate our setup key, which you can see right there. And we're going to go ahead and wait for this to finish up. And there we go. So, this is going to be a self-hosted installation. Grab my management URL, drop that on in. We're going to set this with a setup key. Go over here and copy that key, drop it on in.

04:15 Now it's going to connect to NetBird, and when it does, you can see that the peer is installed. So, if I continue, there we go. We have our peer. So, now I want to actually be able to access it. All I need to do is simply drag admin cuz I'm in the admin group, and boop, drop it into NetBird. It will fill in an access control policy for us. So, admin NetBird.

04:36 If this wasn't just a simple like routing peer, and it was actually going to have services on it, I can set like specific policies if I wanted to. Next, got posture checks, go next, admin to NetBird, add policy. And just like that, you can see the peer is added with a new policy. All we do, review and deploy. It's going to give us the what it's going to post through the API, so we can approve and deploy it.

05:01 And there we go. You can now see we have that admin to NetBird policy. And this goes beyond that, of course. We go over to networks, and we can start manipulating and doing things directly here. For example, on this home network, if I wanted to add a resource, I can do that through here just by inputting a IP address, go through, edit things. You could go down to user and see the user, the user devices, the policies, and all of the resources.

05:27 So, it just gives you a really nice way to actually map out and visualize your networks. And we're now going a step beyond visualization, actually build out your remote access infrastructure directly in a visual way, which is cool. So, of course, NetBird is a VPN. It uses WireGuard on the back end to establish strict peer-to-peer connections. It has a relay server for some reason a peer-to-peer connection can't be established.

05:52 So, a primary use case is that peer-to-peer connectivity. And you could see I have a lot of different peers and things I can access directly through here. And kind of an example of that, let's make sure we are up and running. You can see I'm connected. So, if I wanted to, for example, get this Unraid machine and I wanted to SSH into it through WireGuard, I could use either this NetBird IP address or the DNS name, but I'm going to grab IP address, SSH root into my Unraid box.

06:19 There we go. And you can see it's waiting for authentication. Since I have NetBird SSH enabled, it automatically authenticated me and let me in. And that is because I enabled NetBird SSH on both the peer that I'm connecting to and the settings within my dashboard. So, instead of authenticating with either an SSH key or a password, it authenticated with my identity associated with NetBird.

06:43 Now, while I'm in the terminal, one thing that I use more than I thought I would is the exposed functionality. Let's CD into a project, maybe our site techhut.tv, npm run dev. There we go, starting on port 3000. Now, let's say I wanted to quickly share this with like a temporary link, functionality similar to like a Cloudflare tunnel or ngrok, something like that.

07:08 I wanted to share this local project without like having to like spin it up on Vercel or deploy it in some container somewhere or set up like a dedicated instance in your reverse proxy. We could just run NetBird expose and then the actual port we want to expose. In this case, it's 3000. Boom, just like that. You could see we got a IP address there. Well, not an IP, a domain.

07:32 Bam. And then it is going to load up the website. So, now technically that link is accessible to anybody. If I went ahead and added some variables and whatnot, I could go ahead and like password protect it, add a pin code, link it up so you have to authenticate your identity and so forth. And it's part of our reverse proxy, so if I actually go over here to the reverse proxy two services, you're actually going to see that temporary service that is spun up right here for that instance.

08:00 And if I go ahead and hit control C to stop exposing the service, you will notice in here that proxy instance will automatically go away. Which then we could kind of get into the reverse proxy. I did talk about this a little bit in the last video. We've added a couple features that are pretty nice. For example, if I go to my Jellyfin and I edit this service, you can see it right here.

08:20 Running a reverse proxy like this is a very beneficial because instead of actually having to open up ports on my router, what I do is I have my instance of self-hosted NetBird running on a remote VPS. So, between that VPS and my home infrastructure, there's WireGuard peer-to-peer connection, no ports opened, and I have ports open on the VPS. So, that's where the proxy is hosted.

08:44 So, it just kind of adds a layer of protection. Something is similar to like enabling the proxy mode in like Cloudflare DNS. It hides your IP, but then there's that added benefit of the encrypted WireGuard connection, which then you can really isolate to specific services such as for my authentication service, I actually have that in a Docker network.

09:03 So, if we go over to network routing, networks, this Headscale Docker network, I have the subnet for that Docker LAN being exposed. It's in a stack. So, then if something happened where somebody even got into this specific resource, they would be isolated to that Docker network. So, the one routing peer is that Docker container within that Docker network, and I have three services in the reverse proxy associated with it, including my authentication, a little branding thing that I have, and my analytics system.

09:34 The only problem I run into doing it this way is something happens to that stack, uh container stalls out, something weird happens, it kind of screws up everything. So, I think in the couple months since I've had it set up this way, I've had like two instances where I like lost a couple hours of like uh analytic tracking because something happened something got disconnected and I had to go in and restart it.

09:55 So, there is cons to setting it up this way. But, for example, if I go to services and go to this actual like the authentication, which is just Pocket ID, uh if I edit it, you can see we have the internal Docker IP address there as the HTTPS target. We have a domain, uh no authentication here because for this it needs to be public. But, of course, you can set up access control if you'd like to and you have advanced settings.

10:19 Just anything you'd expect out of like a normal reverse proxy is here. Now, private services is cool for example, things like Image and Nextcloud. You can see it right here, Netbird only access. So, what this does is it still filters through the VPS and the external proxy, but to actually access the service, you need to be running the Netbird client.

10:39 Now, you might say, "Why not just access it through the Netbird IP or the DNS name?" Well, sometimes services require you to use HTTPS and it's just prettier. So, this is nice if I want to run a service through the proxy anyways, really make it secure by being authenticated through whatever identity provider you set up in Netbird. And you can see that right here if I go authentication, Netbird only access, admins are the only ones who can access it.

11:02 So, life is good. Which, speaking of, uh thing that we also added since our last video is local multi-factor authentication. So, you can probably tell or I've said a couple times that I have Pocket ID set up as my identity provider, but you don't need to even use an identity provider, you can just use uh local users, which is a simple username password, but now you can enable multi-factor authentication.

11:25 So, it's actually pretty secure. In the background, it's using Dex for all the local users and things like that. So, if you want to follow the DEX project, that's a really good one to take a look at. It has been working really good. And if this is like your first introduction to NetBird, I do recommend you watch my other videos, but there's other things you could do.

11:42 Like here under name servers, I have a DNS server, and if I go ahead and enable this, even if I'm out on the road, I'm somewhere completely different, and I have the NetBird client running, I'm connected to this network, it will use my home's DNS server. And that's really helpful because then you can run the same ad blocker everywhere. You don't need to have like dedicated software on your uh browser extensions, on your phone, whatever to actually block ads.

12:08 And this is actually a way to set up a ad blocker without actually having to change anything in your router because you could forward traffic from NetBird or using the NetBird client to that DNS server. There's just so many features and so many ways you could go about setting this up just to kind of build out your perfect home infrastructure, remote connectivity solution.

12:30 It's ridiculous. And even though the benefits are ridiculous, it is not perfect, and we're working every day to try to make it as perfect as possible. Some things that we need that are being either actively worked on or looked at is certificate authentication with like DNS-01. That would be nice, being able to use like a Cloudflare API key instead of just basic Let's Encrypt.

12:50 And then that would enable us to do other things in the future such as actually being able to route traffic a little bit differently through the proxy. For example, right now if I'm at home and I want to upload something to Nextcloud, if I only use the NetBird proxy, it's going to upload to the VPS and then back to my server. So, it's a whole extra jump that doesn't need to be there.

13:11 But that kind of fun functionality is being looked at and something I'm really really pushing for. And there's a whole bunch of other things too such as clusters. You can spin up an actual proxy node on separate machines. So, if you want uh a proxy node in Europe and one in Asia, you can associate services with different locations and even have some redundancy for certain services that support that.

13:35 Agent network is another new one for most home labbers. There's really not much reason to use this. This is like a business AI tool. So, instead of like handing out API keys to users and employees, you can authenticate with just your NetBird whatever IDP you're using and have access to AI without an API key which is pretty handy. And really that those are some of the big changes.

13:57 One thing that I'm personally working on, flashbang warning, Jojo byam, is light mode which in some scenarios I prefer. We're primarily putting this together for people who just see light mode things better and using it in or outside now is possible. Everything on NetBird right now is dark, so having some light is good. Granted, there are tons of disagreements with that statement.

14:18 And of course in this video I didn't cover everything. You have CrowdSec for example built into the reverse proxy to kind of help bot or lower bot traffic, things like that. There's just so much that you could do and we've been working really hard to make this like the best product possible. So, I wanted to give a quick moment on this channel to shout out some of those changes and the work that has been going on behind the scenes with this product.

14:44 Again, open source, self-hostable on your own infrastructure. If you don't want to self-host, you don't have to. There's a cloud account up to five users for free. I believe it's 100 devices. But with all that, I mentioned will be linked down below and please go to the NetBird YouTube channel and subscribe there. Try to get out at least a video a week. So, if you want to see more of my ugly dome, that is a great place to do so. And with all that, I do hope you have an absolutely beautiful day.