# NetBird

Source: https://docs.sliplane.io/private-networking/netbird

Set up NetBird to access your private Sliplane services through a secure mesh VPN.

[NetBird](https://netbird.io/) is an open-source peer-to-peer mesh VPN. Once configured, you can access your private Sliplane services using their internal hostnames from any device connected to your NetBird network.

## Prerequisites

* A [NetBird account](https://app.netbird.io/)
* A Sliplane server with services you want to make private

## Step 1: Get Your NetBird Setup Key

1. Log in to [NetBird](https://app.netbird.io/)
2. Go to **Setup Keys** in the left menu
3. Create a new setup key or copy an existing one

## Step 2: Deploy NetBird on Sliplane

Create a new service with the following configuration:

| Setting     | Value                                |
| ----------- | ------------------------------------ |
| **Image**   | `docker.io/netbirdio/netbird:latest` |
| **Network** | Private (no public access)           |

Add these environment variables:

| Variable               | Value                      | Description                                 |
| ---------------------- | -------------------------- | ------------------------------------------- |
| `NB_SETUP_KEY`         | Your setup key from Step 1 | Used for automatic registration             |
| `NB_HOSTNAME`          | `routing-peer`             | The internal name for this peer             |
| `NB_USE_NETSTACK_MODE` | `true`                     | **Required** - Enables userspace networking |

## Step 3: Configure Network Resources

1. Go to [app.netbird.io/networks](https://app.netbird.io/networks)
2. Select your network
3. Click **Add Resource**
4. Set the address to `*.internal`

> **info**
>
> You may also need to add this resource to your **Access Policies** to allow traffic from your devices.

## Step 4: Connect Your Local Device

1. Install the [NetBird client](https://netbird.io/docs/how-to/installation) on your local machine
2. Log in to your NetBird account
3. Your device will automatically connect to the mesh network

## Step 5: Access Your Private Services

Once connected, you can access any private service using its internal hostname:

```bash
curl http://my-service.internal:3000
```

Replace the hostname and port with those of your HTTP service.

![netbird dashboard](/_next/static/media/netbird.25b97f88.webp)

***

## Troubleshooting

**Service not reachable:**

* Ensure the NetBird service is running on Sliplane
* Check that your local device is connected to NetBird
* Verify the `*.internal` resource is configured in NetBird

**NetBird container not starting:**

* Make sure `NB_USE_NETSTACK_MODE` is set to `true`
* Verify your setup key is valid and not expired
