Cluster Infra
Netbird
Overlay VPN — cross-site reachability and the daemon socket the dashboard probes through.
Netbird is the cluster's overlay VPN — peer-to-peer WireGuard mesh, central management plane. The dashboard uses Netbird to reach instances at remote sites that aren't on the same L2.
Where it sits
| Chart / values | (in the parent repo) |
| Mode | DaemonSet on every node + a central management API |
| Wire protocol | WireGuard |
How the dashboard uses it
src/lib/netbird.ts is the TS wrapper. The dashboard probes inter-instance
reachability (the green/red pip on a Node-RED row, the Galaxy Map's backhaul status
overlay) by asking the Netbird daemon for peer state.
The daemon socket path
A recent fix (commit a2b66509) corrected the Netbird daemon socket path used by the
dashboard's probe and added an always-try HLS fallback so probe failure doesn't
cascade into video tile failure.
| Symptom that originally led to the fix | Probe couldn't open the daemon socket, all peers showed unreachable, HLS tiles spuriously failed |
| Fix | Correct socket path + decouple HLS init from probe state |
What Netbird does not do
- Not the cluster CNI. Pod-to-pod traffic stays on the cluster CNI (Cilium / canal depending on the cluster).
- Not auth. Peer membership is managed by the Netbird management plane; the dashboard doesn't authenticate users via Netbird.
- Not the L7 ingress. That's nginx-ingress / Caddy / Traefik — see Ingress.
Operator quick-reference
| Symptom | First check |
|---|---|
| All peers unreachable from one node | netbird status on the node — is the daemon up? |
| Some peers reachable, some not | Management plane — are the peers in the same group? |
| Daemon socket error in dashboard logs | Socket path drift — verify against the commit that fixed it |
See also
- Ingress — the L7 edge
- Galaxy Map — backhaul overlay consumer