NetBird
3 posts on NetBird: design decisions and how-to guides from small infrastructure estates run on a very low budget.
- OPNsense as the routing peer for a NetBird mesh
Install the NetBird agent on both firewalls of an HA pair, advertise one route per VLAN with the pair as routing peers, add the outbound NAT the agent's masquerade does not cover, filter on the overlay interface, and avoid the endpoint trap that drops large packets.
Self-hosted NetBird as the operator plane: firewalls as routing peers, policies as transportOne small VM runs the control plane, with its database shipped to a warm standby every thirty seconds. The firewalls are the routing peers. NetBird policies are treated as transport; real authorisation lives at the service.
- PBS: pull replication between two sites with a read-only token
The remote PBS pulls, with a token that can only read one datastore, a pinned fingerprint, and a per-source namespace so guest IDs from two clusters never collide. Every command, in order, then the storage entry that lets the surviving cluster restore.