Skip to content

Self-host NetBird

updated Sep 2026prices checked · Jul 2026Install verified on Ubuntu 26.04 · Jul 2026 · how we test
We earn commissions when you shop through the links below. Full disclosure →

An open-source WireGuard-based mesh VPN that connects your devices, servers, and clouds into a single private network with SSO and access controls — a self-hostable alternative to Tailscale and Twingate. The client is BSD-3-licensed; the self-hosted control-plane components (management, signal, relay, combined) are AGPL-3.0.

Key facts

LicenseBSD-3-Clause
StackGo
Min RAM2048 MB
Official imageyes
Difficulty
Our recommendation

Pick NetBird when you want the whole mesh — control plane, SSO and local users, access policies, DNS, routes, exit nodes and first-party clients for the major platforms — from one project you host yourself. The client is BSD-3-Clause; the `management/`, `signal/`, `relay/` and `combined/` directories you actually run are AGPL-3.0, per the LICENSE file. The quickstart script writes a complete compose stack, by default with Traefik and Let's Encrypt in front, and upstream's floor is a VM with 1 CPU and 2 GB of RAM. It is the most complete self-hosted alternative to Tailscale in this hub, and also the one with the most moving parts.

Follow the NetBird deploy guide →

What you need

  • Any VPS with at least 2048 MB of RAM
  • A domain you control — most self-hosted setups need HTTPS in front of them
  • About the better part of a day
Where to host itaffiliate disclosure
Hetzner Cloudrun it on
From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + US
Get Hetzner Cloud (opens in new tab)
Kamaterafree trial
From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + Asia
Start free on Kamatera → (opens in new tab)
DigitalOceanalso works on
From $6/mo · 1 vCPU / 1 GB / 25 GB · US + EU + Asia
Deploy on DigitalOcean → (opens in new tab)

Paid link — we earn a commission if you shop through it.

Install

Run these commands on your server:

# NetBird — self-hosted control plane (management, signal, relay, dashboard)
export NETBIRD_DOMAIN=netbird.example.com
# The script prompts for a reverse proxy and a Let's Encrypt email —
# run it at a real terminal, it reads /dev/tty and loops without one.
curl -fsSL https://github.com/netbirdio/netbird/releases/latest/download/getting-started.sh | bash
# Publishes 80 + 443/tcp (dashboard), 51820/udp (relay), 3478/udp (TURN).

What you take on

NetBird is a real multi-service deployment; its quickstart and self-hosting guide spell out what that costs:

non-negotiableUpstream's requirements are a public domain that already resolves to the VM, TCP 80 and 443 plus UDP 3478 reachable from the internet, Docker with the compose plugin, jq and curl. The 2 GB floor is upstream's figure ("at least 1CPU and 2GB of memory").
non-negotiableThe script deploys with no users: the first admin is created at /setup, which is "only accessible when no users exist". Local users come from an embedded Dex server, so an external IdP is optional — but if you forget the admin password with no second admin, the documented recovery is a new user via the API with another admin's token "or reset the database to start fresh".
non-negotiableThe architecture moved. New installs get a single netbird-server container configured by config.yaml; the older management + signal + relay + coturn layout with management.json needs the migration guide. Since 0.29 ports are consolidated behind 80/443, but any client older than 0.29 still needs the legacy ports (TCP 33073, 10000, 33080 and UDP 49152–65535) open.
non-negotiableSQLite is the default store; PostgreSQL is for concurrent access or HA; the JSON store was removed in 0.28. Backup is the generated config files plus the management store — the docs stop the netbird-server container and copy /var/lib/netbird out of it.
non-negotiableIt is pre-1.0 and fast: v0.79.0 shipped on 18 September 2026, and releases land most weeks. Behind your own reverse proxy it needs HTTP/2 and gRPC support, and Hetzner's stateless firewall and Oracle Cloud's default UDP rules both get their own troubleshooting sections.

An alternative to

Head-to-head

More self-hosted tools

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.