Home

Netbird is king.

$$7727
https://lemmy.fedioasis.cc/u/Cantaloupe posted on Mar 6, 2026 18:15

Figured I’d give Netbird a go, glad I did because I can self host extremely easily by using the new services feature.

You specify a subdomain, point to a peer, specify a protocol and port, and you are good. NetBird fetches you the certificate and your site goes live fast.

I can use my Immich with my mobile data now.

https://lemmy.fedioasis.cc/pictrs/image/6af03fdb-3e87-421b-8830-6c27972d3172.webp

https://lemmy.fedioasis.cc/post/36949
Reply
$$7735
https://feddit.org/u/prenatal_confusion posted on Mar 6, 2026 18:29
In reply to: https://lemmy.fedioasis.cc/post/36949

Shout-out for pangolin. Betbird looks interesting too!

https://feddit.org/comment/11881027
Reply
$$7738
https://lemmy.world/u/urb5tar posted on Mar 6, 2026 18:32
In reply to: https://lemmy.fedioasis.cc/post/36949

It’s great. And I hope it will last as it is as long as possible.

https://lemmy.world/comment/22516387
Reply
$$7748
https://lemmy.world/u/raicon posted on Mar 6, 2026 18:54
In reply to: https://lemmy.fedioasis.cc/post/36949

I applied to work for them. Insta-rejected :/

Must be amazing

https://lemmy.world/comment/22516822
Reply
$$7750
https://lemmy.world/u/Solrac posted on Mar 6, 2026 19:07
In reply to: https://lemmy.fedioasis.cc/post/36949

Where is this hosted? What jurisdiction is netbird in?

https://lemmy.world/comment/22517071
Reply
$$7757
https://infosec.pub/u/tuxec posted on Mar 6, 2026 19:26
In reply to: https://lemmy.fedioasis.cc/post/36949

I really wanted to keep it after deciding to switch from Tailscale, but it’s mobile app is draining my phone’s battery. It also disconnects without automatically reconnect. Now, I’m in the process of setting OpenZiti up.

How’s your experience with NetBird’s mobile app?

https://infosec.pub/comment/20724364
Reply
$$7758
https://lemmy.world/u/breadsmasher posted on Mar 6, 2026 19:32
In reply to: https://infosec.pub/comment/20724364

just curious, why move away from tailscale?

https://lemmy.world/comment/22517518
Reply
$$7762
https://sopuli.xyz/u/hietsu posted on Mar 6, 2026 19:40
In reply to: https://lemmy.world/comment/22517518

Most likely three causes: U, S and A.

https://sopuli.xyz/comment/22278719
Reply
$$7765
https://lemmy.zip/u/fta posted on Mar 6, 2026 19:49
In reply to: https://lemmy.fedioasis.cc/post/36949

What’s the advantage of this over cloudflare and a reverse proxy? It does the certificate management for you as well?

https://lemmy.zip/comment/25081512
Reply
$$7768
https://lemmy.world/u/irmadlad posted on Mar 6, 2026 19:56
In reply to: https://sopuli.xyz/comment/22278719

Didn’t downvote you, and I get what you are saying, but in another way I don’t. What makes every other country safer? Nothing that would happen here in the USA couldn’t happen or is happening in any other country. Oh, and this has nothing to do with people trash talking the US. I do it every day I’m awake. However, for those who go with this line of thought, I honestly want to know what you think Tailscale is going to do with your encrypted traffic? Because the day the world finds out that America has cracked strong ciphers, is the day you are going to see a lot of panic and movement on this planet. And I would certainly love to make that announcement. It’ll be my going out 15 minutes of fame.

https://lemmy.world/comment/22517910
Reply
$$7774
https://infosec.pub/u/tuxec posted on Mar 6, 2026 20:08
In reply to: https://lemmy.world/comment/22517518

Because the main reason I’m self-hosting is to have control over my data. This includes a lot of metadata about my infra/services/devices which Tailscale is uploading all the time to their servers. Besides that, they’re on the Enshitification road, which made me to search for 100% self-hosted alternatives. And yes, I’m going for EU based companies when it’s a viable option.

https://infosec.pub/comment/20724971
Reply
$$7776
https://lemmy.world/u/Hominine posted on Mar 6, 2026 20:11
In reply to: https://lemmy.fedioasis.cc/post/36949

Replaced a self hosted Wireguard/OVPN setup that was used to navigate corporate/public networks with Netbird a few months ago and haven’t looked back. Never having hosted Tailscale, I am impressed with the flexibility and routing an overlay VPN offers, particularly with Netbird’s management UI. The project itself seems well maintained and the team regularly adds new features, many of which I have not bothered to explore yet.
Give it a go I say.

https://lemmy.world/comment/22518153
Reply
$$7780
https://lemmy.world/u/irmadlad posted on Mar 6, 2026 20:24
In reply to: https://infosec.pub/comment/20724971

This includes a lot of metadata about my infra/services/devices which Tailscale is uploading all the time to their servers

You gave away your metadata getting on the internet today. I like controlling my data as well, however I realize that certain compromises just have to be made in order to continue to live in a global, civilized, society.

https://lemmy.world/comment/22518354
Reply
$$7806
https://pawb.social/u/Dojan posted on Mar 6, 2026 21:22
In reply to: https://lemmy.world/comment/22517071

Netbird is a European company headquartered in Berlin. It’s fully FOSS and you can self-host the entire stack, unlike Tailscale which relies on a third party implementation.

There’s a script on their github that makes setup super easy.

That said, I’ve no idea where their servers are, if you opt to use their servers instead of hosting your own.

https://pawb.social/comment/21006416
Reply
$$7808
https://pawb.social/u/Dojan posted on Mar 6, 2026 21:26
In reply to: https://lemmy.world/comment/22517910

A lot of people are boycotting as many things from the U.S. as they can because of the warmongering paedophile, and his cadre of paedophiles.

It’s not exactly exciting to buy into products when you have that stinky orange mess breathing down your neck about how he’s going to invade your continent and annex countries.

https://pawb.social/comment/21006489
Reply
$$7815
https://lemmy.world/u/irmadlad posted on Mar 6, 2026 21:47
In reply to: https://pawb.social/comment/21006489

It’s not exactly exciting to buy into products when you have that stinky orange mess breathing down your neck about how he’s going to invade your continent and annex countries.

He does like to spread fear and doubt. That’s one of his specialties. Yeah, countries enshitify too. LOL I can understand the sentiment you just expressed rather than the standard ‘Tailscale metadata’. But if you want to take care of stinky orange man, you and your country will have to stand up to him. I’m doing the best I can from this end. LOL

https://lemmy.world/comment/22519556
Reply
$$7818
https://lemmy.world/u/EncryptKeeper posted on Mar 6, 2026 21:59
In reply to: https://lemmy.zip/comment/25081512

Streamlining mostly.

https://lemmy.world/comment/22519727
Reply
$$7821
https://lemmy.world/u/EncryptKeeper posted on Mar 6, 2026 22:03
In reply to: https://infosec.pub/comment/20724971

You can self host the Tailscale server via Headscale.

https://lemmy.world/comment/22519767
Reply
$$7843
https://lemmy.ca/u/Tinkerer posted on Mar 6, 2026 22:47
In reply to: https://lemmy.fedioasis.cc/post/36949

I’ve been looking at this. I’m currently hosting headacale which is super easy and nice. I might five this a try I just need to get over the hurdle of adapting this to work with podman like I have with headscale.

https://lemmy.ca/comment/22070850
Reply
$$7850
https://lemmy.world/u/EpicFailGuy posted on Mar 6, 2026 23:10
In reply to: https://lemmy.fedioasis.cc/post/36949

I’ve been using Pangolin since it came out … to make my services available without opening ports, but I also use Netbird for VPN access.

Is their DNS forwarding “resources” stable? Last I heard it was in beta only … if I can eliminate one more piece of software that I have to admin and maintain, that’d be great.

https://lemmy.world/comment/22520707
Reply
$$7861
https://lemmy.ca/u/dudesss posted on Mar 6, 2026 23:24
In reply to: https://lemmy.fedioasis.cc/post/36949

This is interesting. I’m excited to hear more about NetBird.

if you’re only hosting Immich for yourself, it might be better to look into setting up internal VPN only access to it for remote connection.

https://lemmy.ca/comment/22071333
Reply
$$7966
https://lemmy.ca/u/PeriodicallyPedantic posted on Mar 7, 2026 03:46
In reply to: https://pawb.social/comment/21006416

It seems similar in purpose to pangolin, how do they differ?

https://lemmy.ca/comment/22074341
Reply
$$8021
https://feddit.org/u/prenatal_confusion posted on Mar 7, 2026 07:24
In reply to: https://lemmy.ca/comment/22074341

Had the same question since I am running pangolin

https://netbird.io/knowledge-hub/netbird-vs-pangolin

Network architecture

https://feddit.org/comment/11890038
Reply
$$8022
https://feddit.org/u/prenatal_confusion posted on Mar 7, 2026 07:25
In reply to: https://lemmy.zip/comment/25081512

Independence since no cloud flare

https://feddit.org/comment/11890043
Reply
$$8024
https://feddit.org/u/prenatal_confusion posted on Mar 7, 2026 07:27
In reply to: https://feddit.org/comment/11881027

I just looked it up and pangolin is based in the us. Since it’s selfhosted the impact is little but if a government turns bad (and theirs has) it poses a risk. Even if it’s open source I don’t read the code and verify every update. Hmm

https://feddit.org/comment/11890066
Reply
$$8026
https://feddit.org/u/prenatal_confusion posted on Mar 7, 2026 07:30
In reply to: https://lemmy.world/comment/22518354

While I agree with You that there is always a compromise regarding privacy and participation. But you can always take steps to reduce that delta between reality and ideal by optimizing things.

https://feddit.org/comment/11890082
Reply
$$8027
https://feddit.org/u/prenatal_confusion posted on Mar 7, 2026 07:32
In reply to: https://lemmy.world/comment/22519556

Absolutely necessary to do more than voting with your wallet. Fascism is on the rise everywhere and we as societies need to actively engage with it and provide working alternative structures to prevent people to be drawn towards it.

https://feddit.org/comment/11890103
Reply
$$8028
https://lemmy.zip/u/baner posted on Mar 7, 2026 07:32
In reply to: https://lemmy.world/comment/22520707

I tested pangolin to replace wireguard on my VPS but the problem with pangolin is that is not designed to allow external devices like a mobiles is more about to connect sites.

Tried netbird and is a great piece of software tons of options and with the new added reverse proxy is the perfect replacement for wireguard my only turn down was that exposing services unlike pangolin that let you have link like service1.domain.com in netbird is service1.proxy.example.com.

https://lemmy.zip/comment/25091756
Reply
$$8031
https://lemmy.decronym.xyz/u/Decronym posted on Mar 7, 2026 07:40
In reply to: https://lemmy.fedioasis.cc/post/36949

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters
DNS Domain Name Service/System
VPN Virtual Private Network
VPS Virtual Private Server (opposed to shared hosting)

[Thread #143 for this comm, first seen 7th Mar 2026, 07:40] [FAQ] [Full list] [Contact] [Source code]

https://lemmy.decronym.xyz/comment/15733
Reply
$$8037
https://lemmy.fedioasis.cc/u/Cantaloupe posted on Mar 7, 2026 07:56
In reply to: https://lemmy.ca/comment/22071333

Netbird is a proxy VPN at heart. The machines you connect called “peers” communicate with eachother like it’s one network. I could access my servers from anywhere else and it would connect provided I have the client on and connected.

When you register a peer by installing the client, the device gets a NetBird IP and domain that other peers in the network can access. The communication between the peers is end to end encrypted and if you access them with the provided Netbird IP or domain via HTTP, the packets in wireshark can not be read. From my testing it seems to be quite good.

The reverse proxy service feature is the way you can make something openly accessable without the end user needing to install a client. You specify the protocol, destination and port and you are set. The only downside is you need two domains, one for management and the other for proxying. You also need to set CNAME records right for the SSL certs to work.

My friend who has little self hosting experience was able to quickly get his Jellyfin up within a few minutes. NetBird deals with the cert for you in the background when you make the service. After a few seconds, the service is live and accessable

https://lemmy.fedioasis.cc/comment/148232
Reply
$$8104
https://lemmy.ohaa.xyz/u/Oha posted on Mar 7, 2026 09:55
In reply to: https://lemmy.zip/comment/25081512

Not routing all your unencrypted traffic through a company located in an dictatorship

https://lemmy.ohaa.xyz/comment/14299263
Reply
$$8108
https://lemmy.ca/u/dudesss posted on Mar 7, 2026 10:05
In reply to: https://lemmy.fedioasis.cc/comment/148232

Is it identical to Tailscale?

https://lemmy.ca/comment/22077688
Reply
$$8115
https://feddit.it/u/kilgore_trout posted on Mar 7, 2026 10:36
In reply to: https://pawb.social/comment/21006489

I am one of them. I am from Italy and simply do not want to support any US-based company any more, independently from their own stance on anything.

https://feddit.it/comment/18690319
Reply
$$8130
https://lemmy.world/u/fightforlife posted on Mar 7, 2026 11:05
In reply to: https://lemmy.fedioasis.cc/post/36949

I am currently using Traefik with rathole to expose services which do not have a public available port. It seems netbird has a nice gui, but is not able Todo advanced reverse prox configs based on path, headers, etc…

https://lemmy.world/comment/22527815
Reply
$$8139
https://lemmy.dbzer0.com/u/Appoxo posted on Mar 7, 2026 11:29
In reply to: https://lemmy.ohaa.xyz/comment/14299263

So? It’s just a reverse proxy?

Then it doesnt solve the purpose of Cloudflare which also has WAF.
And that can (for example) be done with CrowdSec.
Crowdsec is OSS, but probably not fully autonomous because it needs the hivemind to really work it’s intended purpose.
Other than that it’s a fancy fail2ban.

Thus I need to ask: What does Netbird better?

https://lemmy.dbzer0.com/comment/24813552
Reply
$$8140
https://lemmy.dbzer0.com/u/Appoxo posted on Mar 7, 2026 11:31
In reply to: https://lemmy.ca/comment/22077688

Sounds like those solutions.
Essentially a reverse proxy and vpn client.

https://lemmy.dbzer0.com/comment/24813561
Reply
$$8158
https://sh.itjust.works/u/this posted on Mar 7, 2026 12:19
In reply to: https://lemmy.zip/comment/25091756

I use both. Pangolin for anything that absolutely requires an external connection, netbird for internal.

https://sh.itjust.works/comment/24155941
Reply
$$8164
https://pawb.social/u/Dojan posted on Mar 7, 2026 12:35
In reply to: https://lemmy.ca/comment/22074341

Never used Pangolin, so I’ve no idea. Sorry.

https://pawb.social/comment/21016074
Reply
$$8165
https://pawb.social/u/Dojan posted on Mar 7, 2026 12:36
In reply to: https://feddit.it/comment/18690319

Aye, same. I’m Swedish. Not thrilled about the U.S. threatening to invade Greenland, or kidnapping heads of state. Denmark has been sucking up to the U.S. a lot through the years which goes to show that you can’t trust the U.S., ever.

https://pawb.social/comment/21016091
Reply
$$8247
https://sopuli.xyz/u/hietsu posted on Mar 7, 2026 15:48
In reply to: https://feddit.org/comment/11890103

Yeah, and looking at the history, unfortunately the end game is always violence. But we are nowhere near that yet, so sadly things are going to go where they are going for a while still.

https://sopuli.xyz/comment/22292647
Reply
$$8253
https://lemmy.world/u/kcweller posted on Mar 7, 2026 16:02
In reply to: https://lemmy.fedioasis.cc/post/36949

I’m an oldhead on hosting. I have an semi-old server running in a cabinet in my office space at home, which runs an nginx reverse proxy. My DNS records are maintained on the side of the webhost where I have my domain (and email inbox) registered. These records point directly to my WAN IP, so a lookup of my domain would instantly show my public IP.

I host a couple of services on that server, some for myself, some for friends. One of them is a Jellyfin instance.

I’m a bit lost in the technobabble, would Netbird help me hide my IP from a lookup, and solve things like DDoS protection / AI scraping, without me needing all kinds of wireguard apps etc?

I know its superficial, but I find it important that when I’m visiting my dad’s, I can watch a film on the Chromecast from my server, so putting a vpn in front of that would mean to screw with that.

https://lemmy.world/comment/22531514
Reply
$$8328
https://lemmy.world/u/Trail posted on Mar 7, 2026 18:27
In reply to: https://lemmy.world/comment/22517910

You are comparing something that could happen, to something that is already happening, though. Of course people will take stance.

https://lemmy.world/comment/22533655
Reply
$$8343
https://lemmy.world/u/EpicFailGuy posted on Mar 7, 2026 18:55
In reply to: https://lemmy.zip/comment/25091756

Thats an interesting limitation, so netbird has to use the “site” as part of the URL for resources? can you pick the name? or is it dynamicaly generated?

https://lemmy.world/comment/22534090
Reply
$$8457
https://lemmy.zip/u/baner posted on Mar 7, 2026 22:21
In reply to: https://lemmy.world/comment/22534090

Yes, you can pick the name.

https://lemmy.zip/comment/25104344
Reply
$$8489
https://lemmy.fedioasis.cc/u/Cantaloupe posted on Mar 7, 2026 23:33
In reply to: https://lemmy.fedioasis.cc/post/36949

lmao

https://lemmy.fedioasis.cc/pictrs/image/2040f130-08e0-44a2-ae7d-5032a0cbe494.webp

https://lemmy.fedioasis.cc/comment/152548
Reply
$$8492
https://lemmy.sdf.org/u/un_ax posted on Mar 7, 2026 23:38
In reply to: https://lemmy.world/comment/22531514

I don’t think so in your case. From their docs these features are only available for self hosted instances, so you’d have to host Traefik instead of Nginx and end up with a similar config as your current one.

If you wanted to hide your home IP you could either use something like Defelct or Cloudflare as a reverse proxy, or host your own reverse proxy on a cloud provider (either Nginx like you currently are, or Netbird’s reverse proxy UI) and proxy it back to your local server over something like Netbird/Tailscale.

DDOS/Scraping protection would depend on the method you choose.

https://lemmy.sdf.org/comment/26468279
Reply