
Deploy NetBird
Run a NetBird agent on Railway
NetBird
Just deployed
/var/lib/netbird
Deploy and Host NetBird on Railway
NetBird is an open-source overlay network built on WireGuard. It connects your laptops, servers, and cloud services into one private network with zero-trust access control. You manage peers, groups, access policies, and routes from a web dashboard, using either NetBird Cloud or your own self-hosted management server.
About Hosting NetBird
This template runs a NetBird peer. It does not run the NetBird management server. Railway containers have no TUN device and no NET_ADMIN capability, so the template uses NetBird's official rootless image in netstack mode, where WireGuard and routing run entirely in userspace. You supply a setup key from your NetBird dashboard, and the template stores the peer's state on a Railway volume so the peer keeps its identity across redeploys. Set NB_HOSTNAME to give the peer a stable name. If you self-host NetBird, point NB_MANAGEMENT_URL at your server. You can also pin the image with VERSION. Routes into Railway's private network, or exit node traffic, are configured centrally in the NetBird dashboard.
Common Use Cases
- Reach databases and internal services on
*.railway.internalfrom your own devices without exposing them to the public internet - Give your team access to private or staging services on Railway, controlled by NetBird groups and access policies
- Run an exit node on Railway to send a client's internet traffic through Railway
Dependencies for NetBird Hosting
- A NetBird account (NetBird Cloud or a self-hosted management server) and a reusable or one-off, non-ephemeral setup key
- A Railway volume for the peer's state (the template points NetBird at it wherever it's mounted)
Implementation Details
Variables:
NB_SETUP_KEY="<your setup key>" # required, only used on first login
NB_HOSTNAME="${{RAILWAY_SERVICE_NAME}}-${{RAILWAY_ENVIRONMENT_NAME}}" # stable peer name
NB_STATE_DIR="${{RAILWAY_VOLUME_MOUNT_PATH}}" # set by the template
NB_CONFIG="${{RAILWAY_VOLUME_MOUNT_PATH}}/config.json" # set by the template
NB_MANAGEMENT_URL="https://netbird.example.com" # optional, for self-hosted NetBird
VERSION="0.79.0-rootless" # optional, defaults to rootless-latest
You can set any netbird up flag as an NB_-prefixed variable (for example, NB_LOG_LEVEL).
To route into Railway's private network, go to Networks > Add Network in the NetBird dashboard. Add *.railway.internal as a domain resource (and optionally 10.128.0.0/9 as a subnet resource), set this peer as the routing peer, and add an access policy. To use the peer as an exit node, add a 0.0.0.0/0 network route with this peer as the routing peer.
Railway doesn't accept inbound UDP, so connections usually go through NetBird's relay servers.
Why Deploy NetBird on Railway?
Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.
By deploying NetBird on Railway, you are one step closer to supporting a complete full-stack application with minimal burden. Host your servers, databases, AI agents, and more on Railway.
Template Content
NetBird
jayhale/railway-netbirdNB_SETUP_KEY
The agent setup key from the NetBird management server
