NetBird is a WireGuard-based overlay network with its own control plane, and unlike most of its competitors the control plane is open source and genuinely designed to be run by you. That makes it the obvious candidate if the thing putting you off Tailscale is the coordination server you do not own. Here is what it actually takes, and where it is honestly worse.
What NetBird Is
Same architecture as everything else in this space: WireGuard does the data plane, a management server hands out peer configuration, a signal server brokers NAT traversal, and a TURN relay carries traffic when a direct path cannot be established. Peers talk directly whenever they can.
The difference is packaging. NetBird ships the whole stack — management, signal, relay, a dashboard and an identity provider — as a docker compose bundle you can stand up on one VPS. If you have already run a plain WireGuard server on a Raspberry Pi, this is the same tunnel technology with the key distribution problem solved for you.
curl -fsSL https://pkgs.netbird.io/install.sh | sh
sudo netbird up \
--management-url https://netbird.example.com \
--setup-key A1B2C3D4-E5F6-1234-5678-90ABCDEF1234
netbird status -d
netbird status -d is the command you will live in. It tells you per peer whether the connection is p2p or relayed, the last handshake, and the ICE candidate types that were used — which is usually enough to work out why one site is slow.
Self-Hosting the Control Plane
The quick-start script wants a host with a public IP, a DNS record pointing at it, and ports 80, 443, 33073, 33080 and the TURN range 49152-65535/udp reachable.
export NETBIRD_DOMAIN=netbird.example.com
curl -fsSL https://github.com/netbirdio/netbird/releases/latest/download/getting-started-with-zitadel.sh | bash
docker compose ps
docker compose logs -f management
That deploys six or so containers, including Zitadel as the identity provider and a Postgres or CockroachDB behind it. Caddy handles certificates. It works first time far more often than you would expect from a stack that size — but note what you have just taken on: an IdP, a database, a reverse proxy, a TURN server and the management service, all of which are now yours to patch.
The three files worth backing up before you touch anything else:
management.json— the management server’s config, including IdP client secrets and TURN credentials.- The database volume — every peer, group and policy lives here. Lose it and every device re-enrols from scratch.
docker-compose.ymland the Zitadel.env, because the generated secrets are not recoverable.
Where It Differs From Tailscale
Access control is group-based, not a policy file
NetBird has no HuJSON policy document. You create groups, then access control policies that say group A may reach group B on these protocols and ports, with a direction. It is easier to explain to someone else and much harder to version in git. There is a Terraform provider and a REST API if you want policy as code, but it is not the first-class experience that a policy file is.
Things NetBird has that Tailscale does not
- Rosenpass for post-quantum key exchange, one flag:
netbird up --enable-rosenpass. - Posture checks — refuse peers below a minimum client version, or outside a geo/OS set.
- A control plane you can actually read the source of and run offline.
Things you will miss
- No Taildrop-style file transfer, no Funnel, no built-in identity-aware SSH.
- Client polish on macOS and mobile is a step behind.
- DNS works, but the ergonomics of MagicDNS are better.
- The relay is yours, so a busy relayed peer eats your VPS bandwidth rather than someone else’s.
What the Maintenance Actually Costs
This is the part that gets glossed over. Running a self-hosted mesh VPN control plane is not a weekend project that then sits still.
- Upgrades. NetBird releases frequently. Management and clients are not infinitely version-tolerant, so you end up on a rolling upgrade treadmill across every peer.
- Zitadel. The IdP is the single most likely thing to break an upgrade, and the one you understand least.
- Certificates. Caddy renews them, until a rate limit or a DNS change means it does not.
- The blast radius. If the management server is down, existing tunnels keep passing traffic — WireGuard does not care — but no peer can enrol, re-key or pick up a policy change. Do not host it on a box that is only reachable through the VPN.
Budget an evening a quarter, plus the one unplanned evening when an upgrade goes sideways.
Should You Use It
If you want a mesh VPN and you do not have a hard requirement to own the control plane, Tailscale is still the better daily experience and I would use it — as I do for reaching Vaultwarden on a Pi. Choose NetBird when the requirement is real: a client contract that forbids third-party coordination, an air-gapped or regulated environment, or simply that you would rather the outage be your fault than someone else’s.
NetBird is the best self-hosted mesh VPN I have used, and it is a genuine answer to control-plane lock-in. Just go in knowing you have swapped a dependency for a service you now operate.

Leave a Reply
You must be logged in to post a comment.