netbird/README.md

285 lines
11 KiB
Markdown
Raw Normal View History

<p align="center">
<strong>Big News! Wiretrustee becomes Netbird</strong>.
2022-05-18 10:33:37 +02:00
<a href="https://netbird.io/blog/wiretrustee-becomes-netbird">
Learn more
</a>
</p>
<br/>
<div align="center">
<p align="center">
<img width="234" src="docs/media/logo-full.png"/>
</p>
<p>
<a href="https://github.com/netbirdio/netbird/blob/main/LICENSE">
2022-02-28 16:51:12 +01:00
<img src="https://img.shields.io/badge/license-BSD--3-blue" />
</a>
<a href="https://hub.docker.com/r/wiretrustee/wiretrustee/tags">
2022-02-28 16:51:12 +01:00
<img src="https://img.shields.io/docker/pulls/wiretrustee/wiretrustee" />
</a>
<img src="https://badgen.net/badge/Open%20Source%3F/Yes%21/blue?icon=github" />
<br>
<a href="https://www.codacy.com/gh/wiretrustee/wiretrustee/dashboard?utm_source=github.com&amp;utm_medium=referral&amp;utm_content=wiretrustee/wiretrustee&amp;utm_campaign=Badge_Grade"><img src="https://app.codacy.com/project/badge/Grade/d366de2c9d8b4cf982da27f8f5831809"/></a>
<a href="https://goreportcard.com/report/wiretrustee/wiretrustee">
<img src="https://goreportcard.com/badge/github.com/wiretrustee/wiretrustee?style=flat-square" />
</a>
2022-03-06 14:16:17 +01:00
<br>
<a href="https://join.slack.com/t/wiretrustee/shared_invite/zt-vrahf41g-ik1v7fV8du6t0RwxSrJ96A">
<img src="https://img.shields.io/badge/slack-@wiretrustee-red.svg?logo=slack"/>
</a>
</p>
</div>
<p align="center">
<strong>
Start using Netbird at <a href="https://app.netbird.io/">app.netbird.io</a>
<br/>
2022-05-18 10:33:37 +02:00
See <a href="https://netbird.io/docs/">Documentation</a>
<br/>
Join our <a href="https://join.slack.com/t/wiretrustee/shared_invite/zt-vrahf41g-ik1v7fV8du6t0RwxSrJ96A">Slack channel</a>
<br/>
</strong>
</p>
2021-05-06 13:53:58 +02:00
<br>
2022-03-06 21:40:09 +01:00
**Netbird is an open-source VPN management platform built on top of WireGuard® making it easy to create secure private networks for your organization or home.**
2021-12-06 13:54:46 +01:00
It requires zero configuration effort leaving behind the hassle of opening ports, complex firewall rules, VPN gateways, and so forth.
Netbird creates an overlay peer-to-peer network connecting machines automatically regardless of their location (home, office, datacenter, container, cloud or edge environments) unifying virtual private network management experience.
**Key features:**
* Automatic IP allocation and management.
* Automatic peer (machine) discovery and configuration.
* Encrypted peer-to-peer connections without a central VPN gateway.
2021-10-27 13:56:55 +02:00
* Connection relay fallback in case a peer-to-peer connection is not possible.
* Network management layer with a neat Web UI panel ([separate repo](https://github.com/netbirdio/dashboard))
* Desktop client applications for Linux, MacOS, and Windows.
* Multiuser support - sharing network between multiple users.
* SSO and MFA support.
* Multicloud and hybrid-cloud support.
* Kernel WireGuard usage when possible.
* Access Controls - groups & rules (coming soon).
* Private DNS (coming soon).
* Mobile clients (coming soon).
* Network Activity Monitoring (coming soon).
2021-10-27 13:56:55 +02:00
### Secure peer-to-peer VPN in minutes
<p float="left" align="middle">
2021-10-16 16:54:37 +02:00
<img src="docs/media/peerA.gif" width="400"/>
<img src="docs/media/peerB.gif" width="400"/>
</p>
2021-05-06 13:53:58 +02:00
**Note**: The `main` branch may be in an *unstable or even broken state* during development.
For stable versions, see [releases](https://github.com/netbirdio/netbird/releases).
2021-08-20 13:23:57 +02:00
Hosted version: [https://app.netbird.io/](https://app.netbird.io/)
2021-09-12 20:38:26 +02:00
[Web UI repository](https://github.com/netbirdio/dashboard)
2021-09-03 15:33:49 +02:00
2021-09-27 09:23:19 +02:00
### A bit on Netbird internals
* Every machine in the network runs [Netbird Agent (or Client)](client/) that manages WireGuard.
* Netbird features a [Management Service](management/) that offers peer IP management and network updates distribution (e.g. when a new machine joins the network others are getting notified if allowed by access controls). Simply put, this service holds the state of the network.
* Every agent is connected to Management Service.
* Netbird agent uses WebRTC ICE implemented in [pion/ice library](https://github.com/pion/ice) to discover connection candidates when establishing a peer-to-peer connection between machines.
* Connection candidates are discovered with a help of [STUN](https://en.wikipedia.org/wiki/STUN) server.
* Agents negotiate a connection through [Signal Service](signal/).
* Signal Service uses public Wireguard keys to route messages between peers.
Contents of the messages sent between peers through the signaling server are encrypted with Wireguard keys, making it impossible to inspect them.
* Sometimes the NAT traversal is unsuccessful due to strict NATs (e.g. mobile carrier-grade NAT) and p2p connection isn't possible. When this occurs the system falls back to a relay server called [TURN](https://en.wikipedia.org/wiki/Traversal_Using_Relays_around_NAT), and a secure Wireguard tunnel is established via the TURN server.
[Coturn](https://github.com/coturn/coturn) is the one that has been successfully used for STUN and TURN in Netbird setups.
2021-12-06 13:54:46 +01:00
<p float="left" align="middle">
2022-05-22 14:03:43 +02:00
<img src="https://netbird.io/docs/img/architecture/high-level-dia.png" width="700"/>
2021-12-06 13:54:46 +01:00
</p>
See a complete [architecture overview](https://netbird.io/docs/overview/architecture) for details.
**Testimonials:** We use open-source technologies like [WireGuard®](https://www.wireguard.com/), [Pion ICE (WebRTC)](https://github.com/pion/ice), and [Coturn](https://github.com/coturn/coturn). We very much appreciate the work these guys are doing and we'd greatly appreciate if you could support them in any way (e.g. giving a star or a contribution).
2021-05-06 13:57:21 +02:00
2021-06-02 21:30:19 +02:00
### Product Roadmap
- [Public Roadmap](https://github.com/netbirdio/netbird/projects/2)
2021-06-02 21:30:19 +02:00
### Client Installation
#### Linux
2021-10-03 18:55:47 +02:00
**APT/Debian**
1. Add the repository:
```shell
sudo apt-get update
sudo apt-get install ca-certificates curl gnupg -y
curl -L https://pkgs.wiretrustee.com/debian/public.key | sudo apt-key add -
echo 'deb https://pkgs.wiretrustee.com/debian stable main' | sudo tee /etc/apt/sources.list.d/wiretrustee.list
```
2022-05-22 18:53:47 +02:00
2. Update APT's cache
2021-10-03 18:55:47 +02:00
```shell
sudo apt-get update
```
2022-05-22 18:53:47 +02:00
3. Install the package
```shell
# for CLI only
sudo apt-get install netbird
# for GUI package
sudo apt-get install netbird-ui
```
2021-10-03 18:55:47 +02:00
**RPM/Red hat**
1. Add the repository:
```shell
cat <<EOF | sudo tee /etc/yum.repos.d/wiretrustee.repo
[Wiretrustee]
name=Wiretrustee
baseurl=https://pkgs.wiretrustee.com/yum/
enabled=1
gpgcheck=0
gpgkey=https://pkgs.wiretrustee.com/yum/repodata/repomd.xml.key
repo_gpgcheck=1
EOF
```
2. Install the package
```shell
2022-05-22 18:53:47 +02:00
# for CLI only
sudo yum install netbird
# for GUI package
sudo yum install netbird-ui
2021-10-03 18:55:47 +02:00
```
#### MACOS
**Homebrew install**
1. Download and install homebrew at https://brew.sh/
2. If wiretrustee was previously installed with homebrew, you will need to run:
```shell
# Stop and uninstall daemon service:
sudo wiretrustee service stop
sudo wiretrustee service uninstall
# unlik the app
brew unlink wiretrustee
```
> netbird will copy any existing configuration from the Wiretrustee's default configuration paths to the new Netbird's default location
3. Install the client
2021-10-03 18:55:47 +02:00
```shell
2022-05-22 18:53:47 +02:00
# for CLI only
brew install netbirdio/tap/netbird
# for GUI package
brew install --cask netbirdio/tap/netbird-ui
2021-10-03 18:55:47 +02:00
```
4. If you are install CLI only, you need to install and start the client daemon service:
2022-05-22 18:53:47 +02:00
```shell
sudo netbird service install
sudo netbird service start
```
**Installation from binary (CLI only)**
1. Checkout Netbird [releases](https://github.com/netbirdio/netbird/releases/latest)
2021-05-30 12:35:18 +02:00
2. Download the latest release (**Switch VERSION to the latest**):
2021-10-03 18:55:47 +02:00
```shell
2022-05-22 18:53:47 +02:00
curl -o ./netbird_<VERSION>_darwin_amd64.tar.gz https://github.com/netbirdio/netbird/releases/download/v<VERSION>/wiretrustee_<VERSION>_darwin_amd64.tar.gz
2021-10-03 18:55:47 +02:00
```
3. Decompress
2021-10-03 18:55:47 +02:00
```shell
2022-05-22 18:53:47 +02:00
tar xcf ./netbird_<VERSION>_darwin_amd64.tar.gz
sudo mv netbird /usr/bin/netbird
chmod +x /usr/bin/netbird
2021-10-03 18:55:47 +02:00
```
After that you may need to add /usr/bin in your PATH environment variable:
2021-10-03 18:55:47 +02:00
````shell
export PATH=$PATH:/usr/bin
2021-10-03 18:55:47 +02:00
````
4. Install and run the service
```shell
2022-05-22 18:53:47 +02:00
sudo netbird service install
sudo netbird service start
```
2021-06-23 01:38:44 +02:00
#### Windows
1. Checkout Netbird [releases](https://github.com/netbirdio/netbird/releases/latest)
2022-05-22 18:53:47 +02:00
2. Download the latest Windows release installer ```netbird_installer_<VERSION>_windows_amd64.exe``` (**Switch VERSION to the latest**):
3. Proceed with installation steps
2022-05-22 18:53:47 +02:00
4. This will install the client in the C:\\Program Files\\Netbird and add the client service
2021-10-03 18:55:47 +02:00
5. After installing, you can follow the [Client Configuration](#Client-Configuration) steps.
> To uninstall the client and service, you can use Add/Remove programs
2021-06-23 01:38:44 +02:00
### Client Configuration
2022-05-22 18:53:47 +02:00
If you installed the UI client, you can launch it and click on Connect
> It will open your browser, and you will be prompt for email and password
Simply run:
```shell
netbird up
```
> It will open your browser, and you will be prompt for email and password
Check connection status:
```shell
netbird status
```
In case you are activating a server peer, you can use a setup-key as described in the steps below:
1. Login to the Management Service. You need to have a `setup key` in hand (see ).
2021-06-23 01:38:44 +02:00
2022-05-22 18:53:47 +02:00
For all systems:
2021-10-03 18:55:47 +02:00
```shell
2022-05-22 18:53:47 +02:00
netbird up --setup-key <SETUP KEY>
2021-10-03 18:55:47 +02:00
```
2022-05-22 18:53:47 +02:00
For **Docker**, you can run with the following command:
```shell
2022-05-22 18:53:47 +02:00
docker run --network host --privileged --rm -d -e NB_SETUP_KEY=<SETUP KEY> -v netbird-client:/etc/netbird netbirdio/netbird:<TAG>
```
2022-05-22 18:53:47 +02:00
> TAG > 0.6.0 version
2021-05-06 13:53:58 +02:00
Alternatively, if you are hosting your own Management Service provide `--management-url` property pointing to your Management Service:
2021-10-03 18:55:47 +02:00
```shell
2022-05-22 18:53:47 +02:00
sudo netbird up --setup-key <SETUP KEY> --management-url http://localhost:33073
2021-10-03 18:55:47 +02:00
```
2022-02-10 19:18:25 +01:00
> You could also omit the `--setup-key` property. In this case, the tool will prompt for the key.
2022-05-22 18:53:47 +02:00
2. Check connection status:
```shell
netbird status
```
2022-05-22 18:53:47 +02:00
3. Check your IP:
2021-10-03 18:55:47 +02:00
For **MACOS** you will just start the service:
````shell
2022-05-22 18:53:47 +02:00
sudo ifconfig utun100
2021-10-03 18:55:47 +02:00
````
For **Linux** systems:
2021-10-03 18:55:47 +02:00
```shell
ip addr show wt0
```
For **Windows** systems:
2021-10-03 18:55:47 +02:00
```shell
netsh interface ip show config name="wt0"
```
2022-05-22 18:53:47 +02:00
4. Repeat on other machines.
### Troubleshooting
2022-05-22 18:53:47 +02:00
1. If you are using self-hosted version and haven't specified `--management-url`, the client app will use the default URL
which is ```https://api.wiretrustee.com:33073```.
2022-05-22 18:53:47 +02:00
2. If you have specified a wrong `--management-url` (e.g., just by mistake when self-hosting)
to override it you can do the following:
```shell
2022-05-22 18:53:47 +02:00
netbird down
netbird up --management-url https://<CORRECT HOST:PORT>/
```
To override it see solution #1 above.
2021-09-13 07:58:52 +02:00
### Running Dashboard, Management, Signal and Coturn
2022-05-22 14:03:43 +02:00
See [Self-Hosting Guide](https://netbird.io/docs/getting-started/self-hosting)
2021-06-02 21:30:19 +02:00
### Legal
[WireGuard](https://wireguard.com/) is a registered trademark of Jason A. Donenfeld.