Add an external relays guide for commercial-license deployments (#992)

* docs: add an external relays guide for commercial-license deployments

On NetBird Enterprise the relay's shared secret is also the traffic-flow
receiver's secret. The community guide tells readers to generate a new
secret, which on Enterprise leaves peers connected while traffic event
logging stops. Add a standalone Enterprise page that reuses the existing
secret, reads it from config.yaml, and ends with a check that the receiver
is still accepting events.

Correct the community guide:
- Relay hosts need 443/tcp, 443/udp and 3478/udp, not port 80: the relay
  obtains its certificate with the TLS-ALPN-01 challenge on 443. Publish
  443/udp in the compose file too, for QUIC.
- Apply a config.yaml change with `docker compose restart netbird-server`,
  and a docker-compose.yml port change with `docker compose up -d`.
- Treat the config.yaml example as an addition to the server block, which
  also holds auth, reverseProxy and store.
- Keep server.authSecret. Setting relays.addresses turns off the embedded
  relay and STUN server, with no way to keep the embedded relay alongside.
- Relay choice is a latency race, a client can hold more than one relay
  connection, and either transport can win.
- STUN status is not a failover signal, and a secret mismatch is best seen
  in the relay host's log.
- Describe the startup log, the /relay response, and a certificate request
  that hangs rather than errors.
- Make the proxy and supplied-certificate sections complete: the relay's
  own configuration behind a proxy, what the proxy must do, what the
  trusted-proxy headers affect, how to apply changes, and the pitfalls of
  supplied certificates, including private CAs.
- chmod 600 relay.env, and apply later relay.env changes with
  `docker compose up -d`.

List the new page under Commercial License as "External Relays (Licensed)"
and link it from the scaling guide.

* docs: clarify the receiver's log level, the firewall that restricts a published relay port, and the leftover Let's Encrypt sign

* docs: qualify the Step 1 traffic events check by the receiver's log level

* docs: cover migrated and no-traffic-flow deployments on the external relays page, and separate the two secret mismatches

* docs: name the QUIC form of the relay's secret-mismatch reason

* docs: read the active server configuration in Step 2, cover a stale receiver secret in Step 8, and separate what each receiver check proves
This commit is contained in:
Jack Carter
2026-09-25 19:33:40 +02:00
committed by GitHub
parent 0d44d0b7ba
commit 2d02cd4940
4 changed files with 725 additions and 38 deletions
+4
View File
@@ -598,6 +598,10 @@ export const docsNavigation = [
title: 'High Availability',
href: '/selfhosted/maintenance/scaling/high-availability',
},
{
title: 'External Relays (Licensed)',
href: '/selfhosted/enterprise/external-relays',
},
{
title: 'Grafana Dashboard',
href: '/selfhosted/enterprise/grafana-dashboard',