mirror of
https://github.com/netbirdio/docs.git
synced 2026-10-10 23:59:04 +02:00
Add an external relays guide for commercial-license deployments (#992)
* docs: add an external relays guide for commercial-license deployments On NetBird Enterprise the relay's shared secret is also the traffic-flow receiver's secret. The community guide tells readers to generate a new secret, which on Enterprise leaves peers connected while traffic event logging stops. Add a standalone Enterprise page that reuses the existing secret, reads it from config.yaml, and ends with a check that the receiver is still accepting events. Correct the community guide: - Relay hosts need 443/tcp, 443/udp and 3478/udp, not port 80: the relay obtains its certificate with the TLS-ALPN-01 challenge on 443. Publish 443/udp in the compose file too, for QUIC. - Apply a config.yaml change with `docker compose restart netbird-server`, and a docker-compose.yml port change with `docker compose up -d`. - Treat the config.yaml example as an addition to the server block, which also holds auth, reverseProxy and store. - Keep server.authSecret. Setting relays.addresses turns off the embedded relay and STUN server, with no way to keep the embedded relay alongside. - Relay choice is a latency race, a client can hold more than one relay connection, and either transport can win. - STUN status is not a failover signal, and a secret mismatch is best seen in the relay host's log. - Describe the startup log, the /relay response, and a certificate request that hangs rather than errors. - Make the proxy and supplied-certificate sections complete: the relay's own configuration behind a proxy, what the proxy must do, what the trusted-proxy headers affect, how to apply changes, and the pitfalls of supplied certificates, including private CAs. - chmod 600 relay.env, and apply later relay.env changes with `docker compose up -d`. List the new page under Commercial License as "External Relays (Licensed)" and link it from the scaling guide. * docs: clarify the receiver's log level, the firewall that restricts a published relay port, and the leftover Let's Encrypt sign * docs: qualify the Step 1 traffic events check by the receiver's log level * docs: cover migrated and no-traffic-flow deployments on the external relays page, and separate the two secret mismatches * docs: name the QUIC form of the relay's secret-mismatch reason * docs: read the active server configuration in Step 2, cover a stale receiver secret in Step 8, and separate what each receiver check proves
This commit is contained in:
@@ -598,6 +598,10 @@ export const docsNavigation = [
|
||||
title: 'High Availability',
|
||||
href: '/selfhosted/maintenance/scaling/high-availability',
|
||||
},
|
||||
{
|
||||
title: 'External Relays (Licensed)',
|
||||
href: '/selfhosted/enterprise/external-relays',
|
||||
},
|
||||
{
|
||||
title: 'Grafana Dashboard',
|
||||
href: '/selfhosted/enterprise/grafana-dashboard',
|
||||
|
||||
Reference in New Issue
Block a user