All SNO traffic routes through a self-hosted WireGuard mesh VPN. If you are not connected to the Netbird mesh, no SNO service is reachable — the network layer blocks access before authentication is even attempted.
Add the four Netbird services to your docker-compose.yml: netbird-management, netbird-signal, netbird-relay, and coturn. The provided SNO compose file has these pre-configured.
In the Netbird management config (netbird/management.json), set the OIDC endpoint to your Keycloak realm: http://keycloak:8080/realms/secure-os/.well-known/openid-configuration
macOS: brew install netbird-io/netbird/netbird
iOS/Android: Netbird app from App/Play Store
Linux: curl -fsSL https://pkgs.netbird.io/install.sh | sh
Run netbird up --management-url http://your-rpi-ip:33073. Browser opens → login with Keycloak → YubiKey touch → device enrolled in mesh.
Dashboard → Users → Me → Access Tokens → Generate. Copy token to NETBIRD_TOKEN in your .env file. Restart FastAPI container to pick it up.
Dashboard → Access Control → Policies → Add. Require YubiKey-verified identity. Optionally restrict to Starlink IP range. All resources should be in a group only accessible from the mesh.
| DEVICE | MESH IP | OS | STATUS |
|---|---|---|---|
| hylas-rpi5 | 100.64.1.1 | Linux/RPi | CONNECTED |
| hylas-macbook | 100.64.1.2 | macOS | CONNECTED |
| hylas-heltec | 100.64.1.5 | ESP32 | CONNECTED |
| hylas-iphone | 100.64.1.3 | iOS | CONNECTED |
| hylas-fieldkit | — | RP2040 | PENDING |
| RESOURCE | URL | NOTES |
|---|---|---|
| Netbird Dashboard | localhost:33073 | Your local instance |
| Netbird Self-Hosted Guide | docs.netbird.io | Official setup docs |
| Netbird Keycloak OIDC | docs.netbird.io/keycloak | IdP integration |
| WireGuard | wireguard.com | The underlying VPN protocol |