ADORSYS-GIS / ADORSYS-GIS/openstack

Netbird Installation and Network Monitoring

Open
#64 0 comments 0 reactions 1 assignee Claimed by @Donemmanuelo View on GitHub
Dominant language
Shell
Stars
0
Forks
1
PR merge metrics
No merged PRs in 30d

Description

### Description
This ticket involves setting up a secure peer-to-peer mesh network using Netbird and establishing robust monitoring.

### Sub-tasks
- [ ] **2.1: Control Plane Deployment**
- [ ] Decide between Netbird Cloud and a self-hosted control plane.
- [ ] If self-hosting, provision the necessary infrastructure.

- [ ] **2.2: Client Installation and Configuration**
- [ ] Install Netbird clients using OS-native packages on all target devices.
- [ ] Enable IP forwarding only on designated gateway nodes.
- [ ] Automate client installation and configuration where possible.

- [ ] **2.3: Access Control and Security**
- [ ] Implement default-deny ACLs as a baseline.
- [ ] Define granular, least-privilege access rules for groups and services.
- [ ] Configure split tunneling and per-group DNS settings.
- [ ] Enforce SSO/OIDC for user authentication.
- [ ] Establish a process for regular WireGuard key rotation.

- [ ] **2.4: Observability and Monitoring**
- [ ] Integrate system and Netbird logs with a central SIEM.
- [ ] Implement monitoring to track device posture and connectivity status.
- [ ] Set up alerts for critical network events.

- [ ] **2.5: Network Troubleshooting and Maintenance**
- [ ] Document troubleshooting steps, including validation of outbound UDP traffic.
- [ ] Schedule periodic reviews of group memberships, ACLs, and network routes.

### Relevant Links
- [NetBird Documentation](https://docs.netbird.io/)
- [NetBird GitHub Repository](https://github.com/netbirdio/netbird)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.