Self-host NetBird
An open-source WireGuard-based mesh VPN that connects your devices, servers, and clouds into a single private network with SSO and access controls — a self-hostable alternative to Tailscale and Twingate. The client is BSD-3-licensed; the self-hosted control-plane components (management, signal, relay, combined) are AGPL-3.0.
Key facts
Pick NetBird when you want the whole mesh — control plane, SSO and local users, access policies, DNS, routes, exit nodes and first-party clients for the major platforms — from one project you host yourself. The client is BSD-3-Clause; the `management/`, `signal/`, `relay/` and `combined/` directories you actually run are AGPL-3.0, per the LICENSE file. The quickstart script writes a complete compose stack, by default with Traefik and Let's Encrypt in front, and upstream's floor is a VM with 1 CPU and 2 GB of RAM. It is the most complete self-hosted alternative to Tailscale in this hub, and also the one with the most moving parts.
Follow the NetBird deploy guide →What you need
- Any VPS with at least 2048 MB of RAM
- A domain you control — most self-hosted setups need HTTPS in front of them
- About the better part of a day
Paid link — we earn a commission if you shop through it.
Install
Run these commands on your server:
# NetBird — self-hosted control plane (management, signal, relay, dashboard)
export NETBIRD_DOMAIN=netbird.example.com
# The script prompts for a reverse proxy and a Let's Encrypt email —
# run it at a real terminal, it reads /dev/tty and loops without one.
curl -fsSL https://github.com/netbirdio/netbird/releases/latest/download/getting-started.sh | bash
# Publishes 80 + 443/tcp (dashboard), 51820/udp (relay), 3478/udp (TURN).What you take on
NetBird is a real multi-service deployment; its quickstart and self-hosting guide spell out what that costs: