
NetBird is an open-source peer-to-peer VPN platform that creates secure, private networks across distributed infrastructure. It uses WireGuard-based tunnels to establish encrypted mesh networks, allowing low-latency connections between nodes without manual firewall or port forwarding.
This guide explains how to self-host the NetBird control plane on a Vultr instance and connect peers across both Vultr and Google Cloud Platform (GCP). By the end, you have a functional multi-cloud mesh network, with peers in Vultr and GCP communicating securely over private addresses. You will also learn how to designate an exit node for centralized egress routing.
Before setting up your Vultr–GCP mesh network, make sure you have:
netbird.example.com.us-central1).The control plane coordinates all peers in your network and must run on a publicly accessible server. In this setup, you will deploy it on a Vultr instance using Docker. The deployment includes the management service, signaling service, TURN/STUN server, and a default identity provider (Zitadel).
Open firewall ports for HTTPS, signaling, management, and TURN/STUN on the Vultr control plane host.
Install Docker Engine, Docker Compose plugin, and required utilities from Docker’s official repository.
Enable and start the Docker service.
Add your user to the Docker group and refresh group membership.
Verify that the Docker Compose plugin is available.
Run the NetBird installer with NETBIRD_DOMAIN set to your domain.
Replace netbird.example.com with the domain pointing to your Vultr control plane instance.
After the installer completes, the NetBird management interface is available at:
Copy the credentials displayed in your terminal to log in to the dashboard and begin adding peers to your mesh network.
Do not close your terminal before copying the setup key and credentials. These values are only shown once during installation.
Google Cloud Platform (GCP) controls network access at the VPC firewall level. By default, outbound (egress) traffic is open to all destinations. If your project uses custom firewall rules, you must confirm that outbound access to the NetBird control plane is allowed.
Log in to the Google Cloud Console.
In the left sidebar, click VPC Network.
Select Firewall rules.
Click Create firewall rule (or edit an existing one if outbound rules are restricted).
Add egress rules that allow the following ports:
Verify connectivity from the GCP VM to your Vultr control plane domain.
A response such as 200 OK confirms the peer can reach the control plane.
The recommended way to connect servers from Vultr and GCP is by using setup keys. Setup keys are pre-authorized tokens that let peers join automatically without an interactive login. See the NetBird Setup Keys documentation for more details.
In the Admin Panel, navigate to Setup Keys and click Create Setup Key.
multi-cloud-peers). On each peer, install the NetBird client.
Register the peer with your self-hosted control plane.
Replace <SETUP_KEY> with the copied key.
In the Admin Panel, verify the peer appears online. Rename it to something descriptive, such as vultr-ams or gcp-vm, and assign it to groups as needed.
Once you register both Vultr and GCP peers, confirm they can communicate securely over the NetBird private network.
In the Admin Panel, open the Peers tab.
100.x.x.x mesh IP address assigned.From one peer (for example, your Vultr AMS VM), test connectivity to the other peer’s NetBird IP (for example, the GCP VM).
If the ping succeeds, the NetBird mesh is working as expected.
Your output should be similar to the one below:
Repeat the ping in the opposite direction (from GCP > Vultr) to verify two-way connectivity.
You can configure one peer as an exit node so others route their internet traffic through it. In this example, the Vultr AMS instance will act as the exit node, and the GCP VM will route through it.
In the Peers tab of the Admin Panel, select the peer named vultr-ams.
Scroll down and click Set Up Exit Node.
Assign an identifier, such as ams-exit.
In the Distribution Groups dropdown, select or create a group that will include the GCP peer (for example, gcp-nodes).
Click Save Changes.
The vultr-ams instance is now configured as an exit node.
gcp-vm).gcp-nodes group.vultr-ams as an exit node.To confirm that traffic from the GCP VM is routed through the Vultr AMS exit node, run the following on the AMS-region Vultr peer.
Enable IP forwarding.
Add a MASQUERADE rule to NAT outbound traffic via the correct network interface.
Confirm IP forwarding is enabled.
Monitor traffic routed through this peer.
The output shows a live counter of packets hitting the MASQUERADE rule. You should see the packet and byte counts increase as traffic from the GCP VM flows through the Vultr AMS exit node.
If the packet count does not increase, confirm that the GCP peer is assigned to use vultr-ams as its exit node, and verify that both VM firewalls allow outbound connections.
In this guide, you deployed the NetBird control plane on a Vultr instance and connected peers across Vultr and Google Cloud. You registered peers using setup keys, verified private connectivity, and configured an exit node for centralized traffic routing. With this configuration, you can securely extend applications and workloads across providers, making Vultr–GCP deployments more flexible, resilient, and easier to manage.
0 Comments
Be the first to comment and share your perspective with the community.