awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
netbirdio avatar

netbirdio/netbird

0
View on GitHub↗
26,188 estrellas·1,428 forks·Go·16 vistasnetbird.io↗

Netbird

NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device.

The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a centralized control plane for orchestrating network resources, automating device enrollment, and managing peer lifecycles at scale. Administrators can define complex routing policies, manage internal DNS resolution, and expose services securely without manual firewall modifications. The system also supports advanced security postures, including post-quantum cryptography, compliance-based access enforcement, and integration with endpoint security platforms to isolate non-compliant devices.

Beyond core connectivity, the project offers a comprehensive suite of tools for infrastructure management, including support for hybrid cloud bridging, Kubernetes cluster integration, and multi-tenant administrative scoping. It provides deep observability through traffic event streaming, network topology visualization, and diagnostic utilities. The software is designed for flexible deployment, offering headless agents for servers, containerized sidecars for orchestration environments, and support for mobile and desktop operating systems.

Features

  • Mesh Networking - Connects distributed devices into a secure, encrypted peer-to-peer network using the WireGuard protocol.
  • Zero Trust Networking - Enforces strict identity verification and granular access policies for every user and device connecting to private resources.
  • Network Connection Managers - Provides command-line tools to manage and monitor secure peer-to-peer network connections.
  • NAT Traversal Mechanisms - Establishes secure connections between devices behind restrictive networks without requiring manual port forwarding or firewall adjustments.
  • Overlay Networks - Provides a virtual network layer for seamless communication between distributed infrastructure across cloud and physical locations.
  • Peer-to-Peer Networking - Builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol.
  • Secure Remote Access - Exposes internal applications to authorized users through secure tunnels without public internet exposure.
  • Encrypted Tunneling - Establishes secure point-to-point connections between network nodes using high-performance WireGuard encrypted tunnels.
  • Software-Defined Perimeters - Hides network resources from the public internet and grants access based on identity and device posture.
  • Control Planes - Provides a centralized control plane for orchestrating network resources, identity synchronization, and policy distribution.
  • Network Overlays - Maintains a virtual network topology that routes traffic between private subnets and remote peers across physical infrastructure.
  • WireGuard Management - Manages low-level WireGuard interface settings, including kernel/userspace modes and proxy configurations.
  • Access Policies - Enforces granular network access by defining rules that connect user groups to specific resources using protocols and ports.
  • Enterprise Identity Providers - Synchronizes users and groups from external identity services to automate network access control.
  • Identity Provider Integrations - Integrates external identity providers to verify user identity and map group memberships to network permissions.
  • Network Segmentation - Synchronizes user identities and group memberships to automate network access control and isolate network segments.
  • Virtual Private Clouds - Bridges private networks and cloud VPCs by routing traffic through gateway peers for seamless communication.
  • Network Infrastructure Management - Provides programmatic access to manage network infrastructure, including peer configuration and access control policies.
  • Gateway Deployments - Installs gateway clients within private networks to forward traffic to non-client devices and enable high availability through redundant peer configurations.
  • Service Exposure - Exposes internal cluster services to external networks through secure tunnels without requiring public internet exposure.
  • Compliance Enforcement Tools - Enforces security posture requirements by blocking network access for non-compliant devices.
  • SCIM Provisioning - Synchronizes users and groups from external identity providers via SCIM to automate network access and permissions.
  • Enrollment Management - Automates the secure registration of new devices into the private network using unique enrollment keys.
  • Multi-Factor Authentication - Requires users to provide a second form of verification during login to enhance account security.
  • Network Access Control - Enforces granular access control and identity-based segmentation to isolate network resources across distributed environments.
  • Traffic Filtering - Enforces zero-trust security by applying stateful firewall rules based on user identity and device compliance.
  • Overlay Networks - VPN management platform for building secure private organizational networks.
  • Software Development - Secure private network connectivity for computers and IoT devices.
  • Multi-Tenant Data Management - Organizes network resources into isolated accounts to allow multi-tenant management from a single control plane.
  • Infrastructure Orchestration - Exposes network configuration and lifecycle management through APIs for automated infrastructure-as-code workflows.
  • Network Automation - Deploys and configures network infrastructure at scale using setup keys and automated agent management.
  • High Availability Routing - Assigns metrics to multiple routing peers to provide automatic failover for network routes and ensure continuous connectivity to private resources.
  • Network and Server Infrastructure - Automates the deployment, configuration, and lifecycle management of network resources across diverse environments.
  • Access Control Grouping - Automates the assignment of new devices to access control groups to enforce consistent security policies.
  • Private Networks - Forwards traffic between overlay networks and remote subnets to provide access to resources without installing agents on every host.
  • Traffic Routing - Manages traffic flow between connected sites and subnets using configurable routing policies and masquerading.
  • Security Agent Integrations - Verifies endpoint security agent status to automatically grant or deny network access based on device compliance.
  • Multi-Tenant Identity Management - Scopes administrative operations to specific client accounts using unified authentication tokens for multi-tenant management.
  • Identity-Based SSH Access - Maps remote SSH sessions to specific user identities via OIDC or network policies to control access to operating system accounts.
  • User Identity Management - Authenticates users through embedded or external identity providers to centralize access control across a network.
  • Account Management - Provisions and tracks customer organizations from a centralized dashboard for lifecycle management.
  • Infrastructure-as-Code Providers - Automates network resource provisioning through dedicated providers that integrate with standard infrastructure orchestration workflows.
  • Kubernetes Cluster Management - Discovers and configures secure access to Kubernetes clusters without exposing endpoints to the public internet.
  • Kubernetes Network Operators - Automates network connectivity and service exposure within Kubernetes clusters by injecting network client containers.
  • Ephemeral Node Management - Manages the lifecycle of ephemeral network nodes by automating registration and deregistration to maintain network topology.
  • DNS Configuration - Allows configuration of custom nameservers to ensure private network resources resolve correctly across distributed environments.
  • Exit Node Traffic Routing - Configures designated peers as exit nodes to centralize and secure internet-bound traffic from connected clients.
  • Local Resource Exposure - Exposes local services to the public internet via secure tunnels for temporary development and testing access.
  • Optimization Strategies - Configures static port mapping to ensure reliable direct peer-to-peer connections by preventing source port randomization on network gateways.
  • Network Diagnostics - Provides diagnostic tools to inspect the internal state and logs of the background service for troubleshooting connectivity issues.
  • Reverse Proxies - Hosts account-specific reverse proxies on private infrastructure to maintain control over traffic routing and TLS management.
  • Access Provisioning - Registers new client organizations by verifying domain ownership and assigning administrative access permissions.
  • Access Tokens - Generates scoped credentials for external applications to authenticate with the platform API without primary user credentials.
  • Device Identity Management - Registers new devices to a private network using unique keys for automated, non-interactive onboarding.
  • API Request Authentication - Validates incoming API requests using OAuth2 bearer tokens or personal access tokens for secure communication.
  • Process-Based Access Policies - Verifies that specific security software or required applications are active on a device before granting network access.
  • Post-Quantum Cryptography - Protects peer-to-peer connections against future decryption threats using post-quantum cryptographic protocols.
  • Endpoint Integrations - Connects security monitoring platforms to network infrastructure to automatically isolate compromised devices and restrict access based on threat intelligence.
  • Mobile Network Clients - Extends private network access to mobile devices via secure peer-to-peer tunnels.
  • Remote Desktop Environments - Bridges RDP traffic through secure tunnels to enable remote desktop sessions directly within a web browser.
  • Traffic Routing - Directs web traffic to different backend services based on URL path prefixes to share domains.
  • Containerized Service Deployment - Runs network nodes as containerized services using environment variables for automated configuration.
  • Automated DNS Managers - Automates the management of network-wide DNS settings and resolution rules to integrate with infrastructure deployment workflows.
  • IPv6 Network Stacks - Allocates unique IPv6 addresses to peers within a private network to enable dual-stack communication alongside existing IPv4 infrastructure.
  • Connection Management - Manages secure peer-to-peer network connectivity on Windows via background services.
  • Custom Labels - Enables custom hostname assignment for network peers to facilitate easier discovery and service load balancing.
  • DNS Resolution - Manages internal DNS forwarding and resolution probes to ensure reliable connectivity across the overlay network.
  • Load Balancers - Distributes incoming requests across multiple peers sharing the same DNS label using round-robin resolution.
  • Logical Network Environments - Organizes infrastructure into logical containers that map specific environments like cloud VPCs to sets of routing peers.
  • Domain Name System Services - Resolves internal domain names to private IP addresses to enable seamless routing to network services.
  • Relay Server Infrastructures - Deploys private relay infrastructure to route traffic between peers when direct connections are blocked by firewalls.
  • Traffic Routing Proxies - Routes network traffic between peers via intermediary servers when direct point-to-point connections cannot be established.
  • Authentication Status Validation - Tracks multi-factor authentication enrollment status and allows administrators to reset settings for access recovery.
  • SSL/TLS Certificate Management - Automates the provisioning and management of SSL/TLS certificates for exposed services using ACME challenges.
  • Device Approval Workflows - Requires manual administrative authorization for new devices before they are permitted to join the network.
  • Domain-Based Access Controls - Groups new users into organizations automatically based on email domains to simplify onboarding.
  • Firewall Configurations - Manages virtual interface traffic flow while delegating granular access control to the overlay network platform.
  • Simulation Tools - Tests network access policies by simulating packet flow through firewall rules to verify connectivity without sending actual traffic.
  • Topology Visualizers - Displays a graphical map of connections between users, machines, groups, and network resources to verify existing access control policies.
  • Network Access Restrictions - Limits network connectivity to devices running specific software versions to ensure secure and compliant configurations.
  • Secure Tunneling - Creates secure local or remote tunnels to route traffic between machines and remote network addresses.
  • User Invitation Systems - Sends email invitations to individuals to join private networks and associate with access groups.
  • Group-Based - Assigns network access configurations to specific device sets using organizational tags to enforce team-based policies.
  • Service Account Permissions - Creates non-interactive accounts with scoped permissions to perform automated actions independent of user credentials.
  • Network Log Streaming - Forwards network activity and security audit logs to external monitoring systems via HTTP to enable centralized alerting and analysis.
  • Performance Monitoring - Tracks resource utilization and access patterns on routing peers to identify bottlenecks and ensure optimal throughput across an overlay network.
  • Status Monitors - Displays real-time connection details, peer health, and service connectivity status to help identify network or daemon issues.

Historial de estrellas

Gráfico del historial de estrellas de netbirdio/netbirdGráfico del historial de estrellas de netbirdio/netbird

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Preguntas frecuentes

¿Qué hace netbirdio/netbird?

NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device.

¿Cuáles son las características principales de netbirdio/netbird?

Las características principales de netbirdio/netbird son: Mesh Networking, Zero Trust Networking, Network Connection Managers, NAT Traversal Mechanisms, Overlay Networks, Peer-to-Peer Networking, Secure Remote Access, Encrypted Tunneling.

¿Qué alternativas de código abierto existen para netbirdio/netbird?

Las alternativas de código abierto para netbirdio/netbird incluyen: fosrl/pangolin — Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private… gravitl/netmaker — Netmaker is a platform for automating and managing virtual mesh networks built on WireGuard. It functions as a… tailscale/tailscale — Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted… slackhq/nebula — Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer… octelium/octelium — Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and… firezone/firezone — Firezone is a zero trust network access platform that uses WireGuard to provide identity-based connectivity to…

Alternativas open-source a Netbird

Proyectos open-source similares, clasificados según cuántas características comparten con Netbird.
  • fosrl/pangolinAvatar de fosrl

    fosrl/pangolin

    21,255Ver en GitHub↗

    Pangolin is a zero-trust remote access platform designed to provide secure, identity-aware connectivity to private network resources. It functions as a cloud-native network controller that orchestrates encrypted tunnels, traffic routing, and access policies across distributed environments. By leveraging WireGuard for secure data transport, the platform enables authenticated access to internal web applications, terminal sessions, and remote desktops without exposing services to the public internet. The platform distinguishes itself through a declarative infrastructure model that synchronizes n

    TypeScriptcrowdsecdockerhome-lab
    Ver en GitHub↗21,255
  • gravitl/netmakerAvatar de gravitl

    gravitl/netmaker

    11,630Ver en GitHub↗

    Netmaker is a platform for automating and managing virtual mesh networks built on WireGuard. It functions as a centralized control plane that orchestrates encrypted, peer-to-peer tunnels across distributed infrastructure, including cloud environments, on-premise data centers, and containerized clusters. By automating the configuration of routing tables and access policies, the system enables secure, private connectivity between diverse devices and services without requiring manual network administration. The platform distinguishes itself through its focus on zero-trust network access and soft

    Goclouddevsecopsipv6-support
    Ver en GitHub↗11,630
  • tailscale/tailscaleAvatar de tailscale

    tailscale/tailscale

    32,596Ver en GitHub↗

    Tailscale is a zero-trust networking overlay that connects distributed devices and services into a private, encrypted mesh network. By utilizing a high-performance, user-space implementation of the WireGuard protocol, it establishes secure peer-to-peer tunnels across diverse network topologies without requiring complex firewall configuration. The platform operates on a centralized control plane that manages global network state, authentication, and policy distribution, ensuring that connectivity is governed by identity rather than traditional IP-based rules. What distinguishes Tailscale is it

    Go2faoauthsso
    Ver en GitHub↗32,596
  • slackhq/nebulaAvatar de slackhq

    slackhq/nebula

    17,405Ver en GitHub↗

    Nebula is a scalable, decentralized overlay networking tool designed to create secure, encrypted peer-to-peer connections between distributed hosts. By utilizing a certificate-based identity authority, it enables the construction of private communication fabrics across disparate physical infrastructures, such as multiple cloud providers or on-premises data centers, without requiring central authentication servers. The project distinguishes itself through a zero-trust architecture that enforces granular, policy-driven firewall filtering based on certificate-derived group memberships. It facili

    Go
    Ver en GitHub↗17,405
  • Ver las 30 alternativas a Netbird→