Commit Graph

1003 Commits

Author SHA1 Message Date
Misha Bragin
e21f92fbda Mention RC for Agent Network (#816) 2026-06-28 12:33:57 +02:00
netbirddev
24d2208015 Update API pages with v0.74.0-rc.2 2026-06-27 21:18:15 +00:00
Misha Bragin
51c1990ac5 Agent Network (#813) 2026-06-27 22:02:57 +02:00
netbirddev
f70a5606a4 Update API pages with v0.75.0-rc.3 2026-06-27 11:47:55 +00:00
netbirddev
e9d322b079 Update API pages with v0.74.0-rc.1 2026-06-27 11:45:43 +00:00
Bruno Mercier Costa
5729ad035e Restructure Troubleshooting into a hub with per-area pages (#814)
* Restructure Troubleshooting into a hub with per-area pages

- Add a Troubleshooting hub (/help/troubleshooting) with icon/chip cards and a "Still stuck?" CTA
- Split NetBird Client troubleshooting into an overview + per-OS pages (Linux, Windows, macOS, Android, iOS)
- Split Self-hosted troubleshooting into an overview + per-area pages (installation, IdP, dashboard, certificates, connectivity, database)
- Split "Report bugs and issues" into Community Support and NetBird Support pages
- Add Troubleshooting resource connectivity and a NetBird Cloud pending-approval page
- Add DNS troubleshooting Issue 8 (Windows NRPT rule blocked by a lingering GPO)
- Cross-reference the new pages from networks, DNS, and reverse-proxy docs; update nav

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Address review: client terminology, dead props, labels, cross-links

- Use "client" instead of "agent" across the client troubleshooting pages (headings, prose, anchors)
- Remove unused source: props from the Troubleshooting hub tiles
- Relabel the "NetBird Cloud" grouping to "Cloud & identity" (SSO/provisioning also apply to self-hosted)
- Add a Tiles title on the report-bug landing; add reverse-proxy -> resource-connectivity cross-link
- Fix comma splices introduced by the em-dash cleanup in relayed-connections

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Add client-side hash redirect for moved self-hosted anchors

Old deep links like /selfhosted/troubleshooting#debugging-turn-connections now
forward to the per-area page, since next.config redirects can't act on the URL fragment.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Apply docs-skill review: conventions + reshape area pages

- "open source" (no hyphen), expand NRPT on first use, descriptive alt text + captions on TURN images
- Fix inherited "Netbird" casing in the client glossary
- Reshape the six self-hosted area pages to Symptom -> likely causes (ordered) -> Fix -> Confirm, preserving anchored headings

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* Fix two typos in client glossary (CodeRabbit)

- "nunning" -> "running" in the glossary
- possessive "it's" -> "its" in the routing-table sentence

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs: fix two broken links in troubleshooting pages

- database: point the "upgrade path" link at /selfhosted/maintenance/upgrade;
  selfhosted-quickstart has no #upgrade anchor so the old link landed at page top
- client: add HashRedirect so old #net-bird-agent-status deep links forward to
  the renamed #net-bird-client-status section on the same page

* docs: address review follow-ups (deep-link redirects + client casing)

- self-hosted troubleshooting: extend the HashRedirect map with the per-issue
  (###-level) anchors from the old single page, so old deep links land on the
  exact sub-section of the new area page rather than just the page top
- client glossary: lowercase "NetBird client" in the peer-a/peer-b entries
  (house convention) and fix "linux" -> "Linux"

* docs: review polish — fix image class + first-use acronym glosses

- connectivity: fix bad CSS class imagewrapper-nig -> imagewrapper on the
  TURN-test screenshot (the typo'd class matched no style and broke zoom)
- gloss acronyms on first use: GPO (DNS Issue 8), IdP/SSO (identity-provider),
  ACME (certificates), CORS (dashboard)

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Jack Carter <128555021+SunsetDrifter@users.noreply.github.com>
2026-06-26 15:42:59 +02:00
Bethuel Mmbaga
ffb72cfa34 Add HA guide for self-hosted Enterprise (#812)
* render mermaid disgrams

* wip: add ha docs

* improve high availability guide

* fix review

* remove nav links and references

* remove dead server.authSecret references

* fix Redis troubleshooting command using non-existent env var

* correct startup-log order
2026-06-25 14:53:25 +02:00
Jack Carter
e21d6da29d docs: stack components matrix + de-numbered troubleshooting on enterprise getting-started (#809)
* docs: add stack components matrix to enterprise fresh install

* docs: drop numbering from enterprise troubleshooting subheadings

* Update enterprise commercial license doc (#808)

* use pkgs.netbird.io for Enterprise scripts

---------

Co-authored-by: Bethuel Mmbaga <bethuelmbaga12@gmail.com>
2026-06-24 17:15:52 +02:00
Theodor Midtlien
6b4aa80457 Add profile id migration (#781)
* Add profile id migration
2026-06-22 11:40:45 +02:00
Brandon Hopkins
de7878eb31 Update Desktop Client RC Links (#807)
* Add RC notes and documentation

* Add download links

* Updates lang and daemon

* Update RC download links
2026-06-21 07:58:00 -07:00
Brandon Hopkins
3ef558be01 Document the redesigned NetBird desktop app (release candidate) (#802)
* Add RC notes and documentation

* Add download links

* Updates lang and daemon
2026-06-19 23:21:23 +02:00
Riccardo Manfrin
59405c5e73 Adds doc for Windows/macOS MDM integration (#783)
* Adds doc for Windows/macOS MDM integration

* Fixes coderabbit suggestions

* Update public/docs-static/files/netbird-policy.reg.ps1

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Check port and allow/disallow in admitted values for macos script

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-06-19 22:47:02 +02:00
Jack Carter
15fdd20777 docs: persistent-route guidance for clientless devices + align site-to-site on Networks (#797)
* docs: add persistent-route guidance for clientless devices and align site-to-site on Networks

Step 5 of both site-to-site guides (and the masquerade page) now walk a
first-time admin through persisting a Linux static route end to end:
detect Netplan vs systemd-networkd with `ls /etc/netplan/`, then a clear
Option A / Option B that are framed as alternatives, with the exact
editing mechanics (open in nano, save/exit keys, or a one-paste
systemd-networkd drop-in). Standardize on the `<IFACE>` placeholder with
an `ip -br addr` hint so a literal `eth0` can't silently misconfigure
hosts using predictable interface names.

Update the site-to-site use-case hub to recommend Networks for all
non-exit-node scenarios, rename "Network Routes" to "Routes", and
reconcile the comparison section with the Routes deprecation.

* docs: promote Routes site-to-site recommendation to a deprecation warning

Move the 'use Networks instead' callout above the Architecture section
and make it a Warning, matching the Routes deprecation. Keep the legacy
no-Policy nuance and the Site-to-VPN pointer; rename Network Routes to Routes.

* docs: correct Networks scenario support and mark Routes deprecated

- advanced-configuration: Networks supports all scenarios (VPN-to-Site,
  Site-to-VPN, Site-to-Site), not VPN-to-Site only
- how-routing-peers-work: Routes labeled deprecated, not 'still supported'

* docs: import Note explicitly in site-to-site use-case page

Addresses CodeRabbit: <Note> was used without an explicit import from
@/components/mdx, relying on the global MDX provider.

* docs: repoint site-to-site cross-links to Networks

Site-to-site moved to Networks; update the homelab and cloud use-case
tiles/table and the access-home-devices and cloud-to-on-premise Next
Steps links to /manage/networks/use-cases/site-to-site.

* docs: rename Network Routes to Routes in prose and repoint advanced-config links

Bucket A rename (display text only): rename the 'Network Routes' feature
name to 'Routes' across prose, link labels, table cells, alt text, Tiles
names, and code comments. Headings are deliberately left unchanged to
avoid breaking anchors and inbound links; URL paths (/manage/network-routes)
are unchanged. Generic routing-table mentions and the desktop system-tray
UI label are left as-is.

Also repoint the access-home-devices and cloud-to-on-premise 'Advanced
configuration' Next Steps links from the Routes advanced-config page to
/manage/networks/masquerade.

* Update site-to-site documentation for clarity

Removed outdated information about using Routes for site-to-site connections.

* Update src/pages/manage/networks/use-cases/site-to-site.mdx

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update section title from 'Networks vs Network Routes' to 'Networks vs Routes'

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-06-19 16:32:14 +02:00
Jack Carter
d00360e5a6 docs: add self-hosted Environment Variables page to sidebar nav (#799)
The /selfhosted/environment-variables reference page had no inbound
links and was only reachable by direct URL or search. Add it under
Maintenance, after Configuration Files.
2026-06-19 16:27:51 +02:00
Jack Carter
0653cacbbd docs: routing-peer self-access + Active Directory guides, and DNS/routing-peer clarifications (#796)
* docs: add routing-peer self-access and Active Directory guides

New use-case guides: reaching a service on a routing peer's own LAN IP
(route + peer-to-peer policy + NB_ENABLE_LOCAL_FORWARDING) and an
end-to-end Active Directory / Windows file shares guide over NetBird.

Clarify domain-resource DNS: with Routing Peer DNS Resolution on, the
routing peer answers the client's A/AAAA lookups (a domain resource
matches the exact name; use a wildcard for hostnames under a domain),
but AD still needs a nameserver group for the SRV/DC-locator records.

Add navigation entries, overlay-vs-LAN-IP notes, and ICMP/ping
troubleshooting guidance.

* docs: fix WireGuard anchor slug and sharpen local-forwarding caution

The #why-wireguard-with-netbird anchor doesn't resolve — the heading
slugifies to #why-wire-guard-with-net-bird (decamelized). Fix it in the
networks intro and the netbird-vs-traditional-vpn self-link.

Clarify the NB_ENABLE_LOCAL_FORWARDING caution: with it on, any permitted
peer can reach services bound to the routing peer's own addresses,
including 127.0.0.1, at the peer's NetBird IP.

* docs: polish routing-peer and Active Directory guides

- Correct the DC policy note: TCP/UDP need separate policies because a
  policy carries one protocol, not because of a first-rule limitation
- Make internal-dns-servers the canonical A/AAAA-vs-SRV explanation;
  collapse the three duplicates to one-line pointers
- Trim emphatic bold to enumerated requirements, ports, and flags
- Reduce em-dash density and clarify the routing-peer SSH-management
  and HA cautions in the AD guide

* docs: make Active Directory guide clearer for junior admins

- Rewrite the Verify section to explain why (test as the signed-in
  domain user, port 445 vs ping, name vs IP) instead of assuming
  ICMP/Kerberos/NTLM knowledge
- Clarify the SSH-management and HA cautions in Step 3
- Note Get-DfsnFolderTarget needs the DFS Management tools (RSAT),
  not just any domain-joined machine
- Reduce em-dash density throughout

* docs: Routing Peer DNS Resolution applies to all domain resources, not just wildcards

* docs: refine Active Directory guide and nameserver terminology

- Step 3 DC ports as a Port/Protocol/Needed-for table; promote 123
  (time sync) and 464 (kpasswd) into the baseline
- DFS step: derive each target server's FQDN for the domain resource
- order the agent-placement and reachability shapes consistently
  (dedicated routing peer first)
- drop the niche SSH-wedge caution and the premature masquerade note
- tie the ping/ICMP caveat to the port-scoped policies
- use "Nameserver" + "match domain" (the UI term) instead of
  "nameserver group" across the AD, internal-DNS, and reach-services pages

* docs: scope the local-forwarding caution — loopback exposure is netstack-only

Reaching the routing peer's own 127.0.0.1-bound services via its NetBird IP
only happens on netstack-mode peers; on userspace-TUN (Windows/macOS) it does
not (verified), and Linux kernel mode is a no-op. The general "exposes own
addresses" caution stands; drop the over-broad 127.0.0.1/localhost specifics.

* docs: trim DC-through-routing-peer section to the DNS-only reason and reorder AD subsections

Drop the setup-flavored framing from 'Reaching a Domain Controller
through a routing peer' (it lives on the AD use-case page), keeping the
DNS reference fact: A/AAAA resolves on the routing peer but SRV/DC-locator
records don't, so AD still needs a nameserver to the DC. Heading text is
unchanged so the existing anchor still resolves. Reorder the AD & Domain
Controllers subsections to lead with the recommended case (reach the DC
through a separate routing peer), then the discouraged DC-as-routing-peer
path, then its WireGuard port-conflict troubleshooting.

* docs: drop redundant cross-link from AD Step 4 nameserver note

The note already explains why a domain resource doesn't remove the
nameserver requirement (SRV/DC-locator records). The trailing link to the
DNS page's 'Reaching a Domain Controller through a routing peer' section
just repeated that fact and linked back here, bouncing the reader. Step 4
already links to Internal DNS Servers for the general setup.

* docs: restructure AD routing-peer guidance — least-privilege tiers, DC route/policy split, de-loop cross-links

Active Directory & Windows File Shares:
- Add a TL;DR linking to a new 'The four settings' checklist at the bottom.
- Split Step 3 into Step 3 (route the DC) and Step 4 (allow the AD ports);
  DNS becomes Step 5. Keeps the route distinct from the access policies.
- Step 2: break each routing-peer case into sub-bullets of what's needed;
  point the self-access case to Reach Services on the Routing Peer.
- Step 3: present /32 or apex domain as the granular default and the
  *.corp.example.com wildcard as the least-privilege opt-in — and spell out
  the wildcard's one-policy-scope cost (uniform ports across the whole domain).

Reach Services on the Routing Peer:
- Tighten the setup steps; concrete DNS-nameserver instruction for AD/DFS;
  state the Linux kernel-mode default for NB_ENABLE_LOCAL_FORWARDING.
- 'recipe' -> 'setup' throughout.

Internal DNS Servers:
- Clarify nameserver vs plain share: A/AAAA via the routing peer needs no
  nameserver; AD needs one for SRV records and because the resolver won't
  fall back. Distribute the nameserver to the routing peer's group *and*
  client groups that resolve directly; only when the peer can't resolve on
  its own. Reorder AD subsections; fix the overbroad distribution note.

How Routing Peers Work / cross-links:
- Remove redundant/circular cross-links across the four pages (the
  HRPW -> Internal DNS -> Active Directory -> HRPW loop).

* docs: use "NetBird client"/"clientless" wording in AD and self-access guides

Replace 'the agent'/'agentless' with the preferred 'NetBird client'/'clientless' terms, and add the missing blank line before the Step 2 heading.

* docs: lower altitude of routing-peer/AD guides for junior admins

- Unify the overlay address as 'NetBird IP' and the local one as 'LAN IP' across the routing-peer/DNS pages; add a 2-line two-address primer to the two crux pages.
- Replace the dense userspace/netstack/kernel forwarding sentence with a platform table framed to the self-access case, plus a netstack-override footnote.
- Demote the wildcard policy-scope trade-off in the AD guide to a Note, keeping the granular-first nudge in the main flow.
- Split the 'Reaching a DC through a routing peer' paragraph into what-it-needs / why-a-domain-resource-isn't-enough bullets.
- De-duplicate the self-access section: it now owns the mental model and points to the use-case page for the concrete setup.

* docs: clarify the forwarding section for junior admins

- Disambiguate NB_ENABLE_LOCAL_FORWARDING from the IP-forwarding sysctl by naming the setting explicitly before the table.
- Split local forwarding into its own '### Local forwarding' subheading, distinct from '### IP forwarding'; repoint the #local-forwarding cross-link.
- Drop the netstack-specific override footnote — edge-case reference material that doesn't help the target reader (the row already names the correct flag).

* docs: apply review feedback to routing-peer/AD guides

- AD Step 4: list the AD ports per TCP/UDP access control policy instead of a dense one-rule-per-policy sentence; add 123 to the four-settings recap.
- De-duplicate the route+policy+local-forwarding triad within how-routing-peers-work (Local forwarding now points to the canonical statement); render the LAN-IP requirements as a sub-list.
- Plain-language rewrite of why a domain resource isn't enough for AD DNS.
- Qualify Global Catalog 3268/3269 to multi-domain forests; state the default branch in AD Step 1.
- Fix the Networks Tiles description to say 'NetBird client', not 'agent'.
- Add DNS troubleshooting Issue 7 for the AD symptom (login/DFS fails but file-by-IP works), cross-linked to the AD guide and the DC section.

* docs: recast AD "four settings" as an explicit NetBird config checklist

Rename the summary to 'What you configure in NetBird' and list the discrete NetBird objects: routing peer, a route (resource) to the file server and to the DC, separate access control policies for each, and a DNS nameserver. Keep the full AD port set in Step 4 only; update the TL;DR link to the new (decamelized) anchor.

* docs: clarify the self-access setup steps

- Identify NB_ENABLE_LOCAL_FORWARDING as an environment variable and link the Client Environment Variables reference.
- Front-load the platform on step 3 (Windows/macOS need the flag; Linux kernel forwarding doesn't, only netstack) and soften the 'all three required' framing accordingly.
- Explain that steps 1 and 3 exist only because clients reach the file server at its LAN IP; reaching a peer at its NetBird IP needs only the policy.
2026-06-19 16:23:49 +02:00
Jack Carter
fb4c110df3 docs: add Enterprise Commercial License self-hosted getting-started page (#801)
* docs: add unlisted Enterprise Commercial License getting-started page

Self-hosted NetBird stack guide with embedded IdP, served at /selfhosted/enterprise/getting-started. Reachable by direct link only; intentionally not added to the sidebar nav.

* docs: add custom TLS certificate appendix to Enterprise getting-started

* docs: rewrite Enterprise Commercial getting-started from script-based deployment guide

Replace the topology-choice page with the current script-based flow:
getting-started.sh for fresh installs and migrate-to-commercial.sh for
community-to-enterprise migrations. Add the migration path, numbered
sections, and a troubleshooting section; standardize on enterprise
terminology and <your-domain> placeholders. Keep the IdP-connection
links and the custom-TLS appendix.

* docs: clarify traffic-flow note in Enterprise getting-started

* docs: link Docker install in Enterprise getting-started prerequisites
2026-06-18 17:37:35 +02:00
Jack Carter
f83b1b65a4 docs: rename Network Routes to Routes, deprecate, and relocate Browser Client Architecture (#792)
* docs: rename Network Routes to Routes, deprecate, and relocate Browser Client Architecture

- Rename the docs sidebar entry "Network Routes" to "Routes" and the page H1
- Add a deprecation note to the Routes page: all use cases except exit nodes
  have moved to Networks; reconcile the body framing accordingly
- Move Browser Client Architecture under Peers > Browser Client
  (/manage/peers/browser-client/architecture), nest the nav, add a redirect,
  and update cross-links
- Shrink the site-to-site Architecture diagram boxes to fit their content

* docs: rename Routes nav 'Concept' link to 'Overview'
2026-06-15 15:57:55 +02:00
Jack Carter
b34404102f Add Troubleshooting relayed connections teaching page (#791)
* docs: add Troubleshooting relayed connections teaching page

Adds a help-section teaching doc that walks junior admins from
'Connection type: Relayed' to a fixed P2P connection (or a justified
stop): mental model, the four players (NAT/Signal/STUN/Relay), ICE
candidate reading, an elimination-based decision flow, a port-forwarding
escape hatch, a worked walkthrough, and when relay is the right answer.

Moves the troubleshooting-oriented sections (Checking Your Connection
Type, Tips for Improving P2P Success) out of Understanding NAT and
Connectivity, leaving it purely conceptual with pointers to the new
page. Adds sidebar entry and a pointer from troubleshooting-client.

* fix: correct nftables example for STUN outbound rule

The STUN service runs on UDP 80/443/3478/5555, but the example rule
allowed TCP/443. Also note that nftables resolves hostnames at
ruleset-load time only, which matters for a dynamic geo-distributed
endpoint pool.
2026-06-12 18:49:45 +02:00
Brandon Hopkins
9cf8498a33 Make sidebar nav groups with landing pages collapsible and fix mobile drawer closing on expand (#786)
* Add collapsible nav groups and delete old /docs dir

* coderabbit fixes: auto-open effect, stable key, push guard
2026-06-12 09:24:47 -07:00
Brandon Hopkins
b70301ee4d Image Audit: Unreferenced Images (#787) 2026-06-11 19:22:11 -07:00
Bruno Mercier Costa
0743354d4d Update ports-and-firewalls.mdx (#790)
adding relay.netbird.io as required
2026-06-11 16:39:16 +02:00
Jack Carter
6a31154b96 Add dedicated User Roles page (#789)
Create a standalone User Roles reference covering all six roles (Owner,
Admin, Network Admin, Billing Admin, Auditor, User) with a permission
matrix aligned to the current dashboard, per-role sections, API/token
notes, and role-assignment steps.

Reduce the role section on the Add Users page to a pointer (keeping the
existing anchor), repoint inbound links from delete-account,
control-center, and msp-portal, add the page to the Team sidebar, and
refresh the role screenshots.
2026-06-11 16:19:08 +02:00
Brandon Hopkins
3d4f037c89 Merged WireGuard page into VPN comparison, added Self-Hosted tile (#788) 2026-06-11 04:08:49 -07:00
Philip Laine
abb000575d Add documentation for API server proxy (#776) 2026-06-11 10:29:57 +02:00
Brandon Hopkins
39303d1c48 Align docs with the new dashboard UI (Phase 1) (#778)
* bulk text edit to fit new flows

* Updated screenshots, some minor docs fix. (#782)

* Update Settings on site-to-site.mdx

* fix image names and embedded links

* Update high level dia

* general dashboard images and auto-update stucture fix

* remove temp audit file

---------

Co-authored-by: PizzaLovingNerd <cameron@stillhq.io>
2026-06-10 09:24:36 -07:00
Bruno Mercier Costa
6107943b50 Update Entra Provisioning Screenshot (#785) 2026-06-10 09:59:16 +02:00
Jack Carter
7fb329aba7 docs: rewrite Networks page as a teaching guide (#779)
* docs: rewrite Networks page as a teaching guide

Rework /manage/networks from a reference-style concept page into a
structured teaching guide: mental model, the four building blocks
(Network, Resource, Access policy, Routing peer), how a packet reaches
a resource, and an end-to-end walkthrough for reaching two internal
apps with Zero Trust access by default.

- Add a production checklist (HA, monitoring, masquerade, internal DNS,
  routing-peer access) and a clear "Networks or Network Routes?" split:
  Networks now covers every remote-access scenario except exit nodes.
- Add worked-example and resource-list screenshots.
- how-routing-peers-work: point site-to-site at Networks, describe
  Routing Peer DNS Resolution as on by default, and restore the
  0.59.x domain-resolution compatibility note.
- Rename the sidebar entry from "Concept" to "Overview".

* image organization into /networks dir

* fix embedded images in networks/index.mdx

* docs: note no inbound ports and Linux-only masquerade on Networks page

---------

Co-authored-by: TechHutTV <brandon@techhut.tv>
2026-06-09 17:06:22 +02:00
Bethuel Mmbaga
a8c86c48e0 Add Zoho Directory SSO (#780) 2026-06-08 18:12:40 +03:00
Maycon Santos
c2ccdf43e0 Documented NetBird-Only Access and Proxy Cluster features in reverse … (#767)
* Documented NetBird-Only Access and Proxy Cluster features in reverse proxy settings. Updated authentication methods, backend configuration guides, and cluster capability requirements.

* Expanded documentation for NetBird-Only services, updated Access Control baseline behavior, added details on Direct Upstream and Proxy Cluster features, and refined cluster capability descriptions.

* add private services diagrams and update auth screenshot

* Document ProxyService gRPC routes and expand reverse proxy configuration details

---------

Co-authored-by: TechHutTV <brandon@techhut.tv>
2026-06-05 08:16:03 -07:00
netbirddev
4ea4552b18 Update API pages with v0.72.0 2026-06-05 15:13:45 +00:00
Theodor Midtlien
711faa386e Add docs for logging env vars and log rotation troubleshooting (#763)
Adds docs for env variables for logging (including the new NB_LOG_DISABLE_ROTATION) and troubleshooting using external logging rotation (describing also new detection behavior).
2026-06-04 17:37:15 +02:00
Brandon Hopkins
d7d9e75e5b Add optional logout URL step (#775) 2026-06-03 16:42:33 +02:00
Jack Carter
e49d920fb6 docs: add Networks site-to-site use-case guide (#773)
* docs: add Networks site-to-site use-case guide

Add a canonical site-to-site guide built on Networks/Resources/Policies,
which is the recommended and actively developed approach. Reposition the
legacy Network Routes site-to-site Note to point at the new page and scope
Network Routes to the wide-open, no-policy case only. Add the new page to
the docs sidebar under Networks > Use Cases.

* docs: fix Resource fields, policy heading, and prerequisites in Networks site-to-site

- Remove non-existent 'Type: Subnet' field; describe Resource Groups under
  Additional Options to match the actual UI
- Rename Step 4 to 'Create access control policies'
- Trim prerequisites (drop account line and device examples)

* docs: clarify Masquerade requirement and Linux-only SNAT for site-to-site
2026-06-01 11:23:44 +02:00
Jack Carter
93e57b61f6 docs: document posture check evaluation timing and policy distribution (#774)
Add a 'When Posture Checks Are Evaluated' section to the posture checks
page covering connect/login evaluation, immediate distribution of changes,
and the connection-time evaluation caveat for mid-session state changes.

Add a 'How Policy Changes Are Distributed' section to the access control
overview covering event-driven push, no redistribution interval, and
change coalescing. The two sections cross-link.
2026-06-01 10:14:31 +02:00
Maycon Santos
109140a77a Add observability documentation for self-hosted deployments (#772)
* Add observability documentation for self-hosted deployments

* Update src/pages/selfhosted/observability/index.mdx

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update src/pages/selfhosted/observability/index.mdx

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Document metric naming conventions and updates across self-hosted observability pages

---------

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
2026-05-29 16:04:04 +02:00
Bethuel Mmbaga
9e09fa68fa Update sqlite to postgres migration (#771) 2026-05-29 11:38:31 +03:00
Jack Carter
f022842ef3 docs: add migration and sync context to Entra ID integration guides (#769)
Answers common customer questions about the Entra ID API to SCIM
migration that the public docs did not cover:

- One-integration-at-a-time limit and tenant-separation workaround
- Reusing an existing Enterprise Application for SCIM vs. the legacy
  API App Registration
- Why the group externalId mapping is removed (displayName matching)
- Why unused user attribute mappings are trimmed
- Why externalId source changes from mailNickname to objectId
- New Sync Behavior section contrasting 5-min API polling with
  event-driven SCIM provisioning
2026-05-28 16:37:43 +02:00
Jack Carter
d1936d99ec fix: replace invalid <p> wrapping Button with <div> (#768)
* fix: replace invalid <p> wrapping Button with <div>

The Button component renders a <div> in its primary variant. HTML
disallows block elements inside <p>, so browsers auto-close the <p>
during parsing and React 19 reports a hydration mismatch. The
float="center" attribute was non-functional, so rendering is unchanged.

* chore: gitignore .playwright-mcp run artifacts
2026-05-27 13:51:03 -07:00
Misha Bragin
14efe3f46a User Servers ref when relevant instead of User Devices (#770) 2026-05-27 16:38:39 +02:00
Tiranajunge
090eff7117 OPNsense checkbox "Show community plugins" (#765)
* OPNsense checkbox "Show community plugins"

OPNsense requires a new checkbox "Show community plugins" to be checked, before you can find the netbird plugin.

Tested on OPNsense 26.1.8_5

* docs: tighten OPNsense community plugins instruction

---------

Co-authored-by: Jack Carter <128555021+SunsetDrifter@users.noreply.github.com>
2026-05-26 16:14:50 +02:00
Misha Bragin
3bac72719b Align docs with the simplified layout changes (#766) 2026-05-26 10:35:24 +02:00
Bruno Mercier Costa
a28e476670 docs: add Support Matrix section under Get More Help (#764)
* Add Support Matrix section under Get More Help

Adds /help/support-matrix with an overview, NetBird client (split into
per-OS pages following the get-started/install layout), Kubernetes
operator, Terraform provider, and self-hosted sub-sections.

Linux/Windows/macOS pages pre-fill OS version cutoffs derived from the
Go toolchain's minimum OS requirements at each NetBird release's Go
version (sourced from go.mod at release tags). Each derived page carries
a Warning callout marking the values as inferences pending team
confirmation. Mobile/TV pages and the other component pages remain TBD
placeholders.

* Rework Linux support page around client modes

Drops the per-distro TBD table and consolidates the description with the
Warning callout. Splits Linux support by client mode: userspace follows
the Go toolchain's minimum OS requirements; kernel mode depends on the
host's iptables/nftables features. Notes Ubuntu 20.04 as the
end-to-end test floor.


* Add full Linux e2e test matrix to support page

Replaces the single Ubuntu 20.04 floor reference with the full set of
distributions covered by the NetBird team's end-to-end tests: Ubuntu
20.04/22.04/24.04, Debian 12, Rocky Linux 9, and Fedora 41. Ubuntu
20.04 remains called out as the oldest tested release.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------
2026-05-22 11:47:42 +02:00
netbirddev
2cc722e436 Update API pages with v0.71.3 2026-05-20 17:35:38 +00:00
Maycon Santos
30cb1bff3b Update BYOP documentation to reflect "Clusters" terminology (#762)
* Update BYOP documentation to reflect "Clusters" terminology and add shared vs account cluster details.

* Update BYOP DNS documentation and replace modal images
2026-05-20 12:07:28 +02:00
PizzaLovingNerd
4e1f5669c9 Added Homebrew for Linux as instructions for atomic, updated DistroBox docs. (#756)
* Update Linux installation instructions for NetBird on Fedora Silverblue and Universal Blue. Added Homebrew and Distrobox installation methods, including necessary commands and SELinux configuration notes. Updated Distrobox container image version from Debian 12 to 13.

* Some adjustments to homebrew docs

* removed leading space on the \``bash` opening fence

---------

Co-authored-by: TechHutTV <brandon@techhut.tv>
2026-05-19 14:20:53 -07:00
Brandon Hopkins
8ab98eff17 Add Cloud Marketplaces section, reorganize self-hosted docs, clean up redirects (#760)
* Add marketplace section with Vultr

* Add Images and Self-Hosted Restructure

* Organize self-hosted pages

* Clean up redirects
2026-05-19 07:55:43 -07:00
Maycon Santos
6dc4724fa2 Add short flags for CLI command options (#754) 2026-05-19 15:57:01 +02:00
Jack Carter
84a3532943 docs: add Masquerade configuration page (#751)
* docs: add Masquerade configuration page

Documents persistent return-route setup on the destination host when
masquerade is disabled on a routing peer. Covers Netplan, systemd-networkd,
NetworkManager, ifupdown, and RHEL legacy network-scripts, plus verification
and a security note. Resolves the previously dangling "Related" tile in
how-routing-peers-work.mdx.

* docs: clarify masquerade page and trim persistent recipes

- Netplan: show as a fragment with addresses/default route context so readers
  don't paste it as a standalone file
- systemd-networkd: note the drop-in needs a matching .network file and
  point at networkctl status to find it
- Test section: add ping/curl reachability examples
- Verify section: call out that proto/onlink/metric fields are normal
- Remove NetworkManager, ifupdown, and RHEL legacy sections

* docs: clarify netplan section when /etc/netplan is empty

Lead with the common case (cloud-init / installer yaml already exists),
and call out the placeholders in the example. Add a fallback path for
the rare case where /etc/netplan/ is empty.

* docs: comment <IFACE> placeholder in netplan example

* docs: clarify <IFACE> is the destination's LAN interface

* docs: comment <PEER_LAN_IP> placeholder in netplan example

* docs: tighten <PEER_LAN_IP> comment to 'local IP on this subnet'

* docs: make 'pick one' explicit for the persistent-config methods

Replace the weak one-liner with a bold "pick one" callout and a
two-bullet decision criterion (ls /etc/netplan/) so readers don't
mistake the two H3 sections for sequential steps.

* docs: add 'Find your account's NetBird range' to the masquerade page

Mirror the section already on the site-to-vpn page so readers learn to
use their account's /16 block rather than pinning the whole /10. Same
prose and netbird status recipe; trailing line adapted to reference
100.64.0.0/10 (the placeholder used elsewhere on this page).

* docs: remove 'Related' Tiles block from masquerade page

* docs: align security warning with the recommended /16 range

* docs: restore cross-link from advanced-configuration to masquerade

* docs: drop ping from the test-route example

ping would fail for ACL reasons (not routing reasons) on policies
scoped to specific TCP ports, misdirecting troubleshooting. Use curl or
nc against an allowed port instead.

* docs: apply review findings to masquerade page and legacy warning

masquerade.mdx
- add "Disable masquerade on the routing peer" section (dashboard +
  API path), so the page actually documents the toggle, not just
  the prerequisite
- "What changes when masquerade is off": say the route lives on the
  destination host (or its gateway for multi-hop)
- forward-ref "Find your account's NetBird range" from the inputs
  list to remove the substitute-then-rewind loop
- ip route del: include via <PEER_LAN_IP> so the test takedown is
  unambiguous
- netplan prose: spell out that you append to the existing routes:
  list, not add a second routes: key (YAML rejects that)
- verify output: use 192.168.1.10 for the routing peer so it stops
  colliding with the 192.168.1.50 used as the destination's own IP
  in the netplan example
- add an end-to-end verification step (curl + tcpdump) so a reader
  confirms source IPs are actually preserved, not just that a route
  exists in the table

advanced-configuration.mdx
- rewrite the contradictory Warning so it scopes correctly to legacy
  Network Routes (which match peer NetBird IPs only) and points
  readers to the Networks path when they want policy-layer ACLs
  with masquerade off

* docs: promote the /16 substitution reminder to a Note callout

* docs: clearer wording for the /16 substitution Note
2026-05-19 15:07:07 +02:00
Jack Carter
8f06376f4f docs: drop inaccurate containerized routing peer ip_forward note (#761)
The agent already enables ip_forward inside the container's own network
namespace when it has NET_ADMIN, so the blanket claim that a container
cannot do this on its own is misleading. The preceding paragraph
already covers the fallback case when the agent cannot modify sysctl.
2026-05-19 10:28:21 +02:00
Jack Carter
47f7ab7b33 docs: rework Site-to-VPN SNAT guidance, verified end-to-end (#758)
* docs: rewrite Site-to-VPN SNAT requirement to always be manual

The dashboard Masquerade flag does not cover the Site-to-VPN direction on
any route — the marking rules NetBird installs are only wired up when a
policy targets the resource, and the documented flow uses a peer-to-peer
policy. The old guidance ("on Linux kernel mode, no manual SNAT needed")
was wrong, so manual SNAT is now framed as required on every routing peer
regardless of OS or WireGuard mode.

Also adds an nftables example alongside the iptables one, drops the
"(If applicable)" qualifier from the Step 3 heading, fixes the four
in-page anchor links that were already 404ing against the old heading,
and reframes the Step 4 masquerade-flag note plus the Outbound SNAT
requirement and Troubleshooting sections to match.

Verified end-to-end in a kernel-mode Linux lab: with the documented setup
(masquerade=true, peer-to-peer policy only, no manual SNAT) curl from a
clientless device to the overlay peer's NetBird IP times out; adding
either the iptables or the nftables rule from the new Step 3 makes it
return HTTP 200.

* docs: make Step 3 SNAT examples persistent

The previous version showed runtime iptables/nft commands with
persistence as a trailing comment. Replace with two equivalent
fully-persistent options: iptables-persistent (recommended) and a
dedicated systemd-unit + /etc/nftables.d/ file for nftables-native
setups.

Explicitly call out why /etc/nftables.conf is not the right persistence
target — its default starts with "flush ruleset", which wipes the
iptables-nft chains NetBird installs.

Both options verified end-to-end in a lab: rule applied, curl succeeds;
rule removed (simulating reboot), curl fails; reload via
netfilter-persistent / systemctl restart, curl succeeds again.

* docs: drop nftables-only option from Step 3

iptables-persistent works on every Linux NetBird supports — whether the
underlying backend is iptables-legacy or iptables-nft — so a separate
nftables variant with its own systemd unit was strictly more complexity
for the same outcome. Keep the iptables-persistent block as the single
Linux instruction.

* docs: drop UFW/firewalld FORWARD caveat from Step 3

The note was scoped to a minority of routing peers (those running UFW or
firewalld with default-DROP on FORWARD), and the persistence guidance
was too vague to be actionable. The symptom — packets reaching the
routing peer but not the target — is already covered by the
Troubleshooting section, which is enough of a lead for affected users.

* docs: drop standalone Outbound SNAT requirement section

The section's three takeaways — ACL ipset rejects routed-CIDR sources,
SNAT rewrites the source to a known NetBird IP, dashboard Masquerade
flag doesn't cover this direction — are already covered inline in Step
3 and the Step 4 masquerade note. Fold the one unique bit (the ipset
mechanic) into Step 3's opening sentence and drop the standalone
section plus the three "see Outbound SNAT requirement" backreferences
that pointed at it.

* docs: use ss -tan in Test Connectivity verification

The previous command (ss -tnp | grep :8080) filters by process and
misses TIME-WAIT sockets, which are kernel-owned. After a fast curl the
TCP connection closes before ss runs, so the user only ever sees the
LISTEN socket — no indication of the source IP. ss -tan lists all
states, so the TIME-WAIT entry showing the routing peer's NetBird IP as
the remote address is reliably visible for ~60 s.

Verified end-to-end in a kernel-mode Linux lab.

* docs: make Linux static route in Step 6 persistent

Replace the runtime "ip route add" + persistence-as-a-comment with two
fully-persistent options: a netplan drop-in (Ubuntu Server default) and
an nmcli equivalent (RHEL / Fedora / desktop). The netplan YAML was
validated against netplan generate. Also annotate the Windows command
to highlight that "-p" is what makes it persistent.

* docs: drop unverified pfSense/OPNsense and MikroTik examples

Neither platform ships a first-class NetBird routing-peer setup, and we
have no way to verify the SNAT commands in those sections work as
written. Replace with a single "Other platforms" paragraph that points
back to the general principle (any SNAT that rewrites the site-CIDR
source on egress from wt0 is sufficient) without claiming to give
verified instructions. Also tighten the Prerequisites line that
referenced "per-platform SNAT syntax" that no longer exists.

* docs: rewrite DNS NXDOMAIN troubleshooting entry

The previous entry referenced a "127.0.0.1-co-located NetBird resolver"
that doesn't exist — the doc's own DNS section explicitly notes that
the NetBird daemon binds its resolver on the peer's own NetBird IP,
not on 127.0.0.1. The "binding loopback causes it to refuse forwarding"
explanation was therefore exactly backwards.

Replace with a dig-based isolation flow that distinguishes the three
real failure modes (timeout = dnsmasq not reachable on the site IP;
SERVFAIL = forward to NetBird resolver failed; NXDOMAIN = wrong FQDN).
Diagnostic flow verified end-to-end in a lab — valid hostnames return
NOERROR with an answer record, unknown ones return status: NXDOMAIN as
described.
2026-05-18 14:40:53 +02:00