[email protected]

NetBird: Managed Hosting, Installation and Operations

WZ-IT designs, installs and operates NetBird as a self-hosted networking platform. We integrate identity providers, routing, DNS and access policies and handle monitoring, backups, updates and connectivity for your sites and applications.

  • Self-hosted Tailscale alternative
  • SSO, MFA & zero-trust policies
  • Community and commercial editions
Reviews
At a glance
  • EditionsCommunity to Enterprise
  • IdentitySSO · MFA · Policies
  • Licencesofficial reseller
Cloud Wolke HerausforderungServer NachhaltigkeitIT Beratung Service Consulting SoforthilfeTimo Wevelsiep Robin ZinsExperten für Innovation Migration AWSHetzner Hosting zuverlässig

Companies worldwide trust WZ-IT

  • Stadtwerke Brühl
  • DGHO e.V.
  • ABCO Water Systems
  • Golem.de
  • EVADXB
  • nextGYM
  • AInergy
  • ml&s
  • Odiseo Solutions
  • Annota
  • ARGE
  • SweetConnect GmbH
  • Aphy AG
  • CORGOS
  • Rekorder
  • SolidProof
  • Yonju
  • Keymate
  • Paritel
  • Mr. Clipart
  • Millenium
  • Negosh
  • Führerscheinmacher
  • Boese VA
Read client reviews

About the technology

About NetBird

NetBird is an open-source solution for encrypted peer-to-peer networking and centrally managed access policies. Its control plane can be self-hosted and integrated with existing network and identity systems.

NetBird uses WireGuard for data connections and adds coordination, routes, DNS and access policies. The components and functions used are verified for the selected edition and version.

The platform can support remote access, site connectivity and private access to cloud, Kubernetes and on-premises systems. Sizing and edition depend on users, devices, routing, availability and operating requirements.

Self-Hosted Features

  • Complete Infrastructure Control

    The self-hostable control plane can run on your own or agreed infrastructure. External dependencies, identity providers and vendor licences are documented transparently in the architecture concept.
  • Open source and self-hostable

    Community Edition covers the client and self-hosted control-plane components. Commercial Starter and Enterprise add licensed capabilities; as an official NetBird Reseller Partner, WZ-IT can supply the required vendor licence directly.
  • Advanced Network Routes

    Connect LANs, VPCs and office networks through routing peers without installing a client on every target system. Redundancy and traffic masquerading are designed for the selected edition and architecture.
  • Granular Access Policies

    Define precise access control rules between peer groups, networks, and resources with support for protocol-specific restrictions (TCP/UDP/ICMP).
  • DNS Routes & Wildcard Domains

    Private DNS zones and name-based access can be integrated into the access model. Supported DNS capabilities are verified for the deployed version and edition.
  • Service Users & API Access

    Create non-interactive service accounts with API tokens for automation, infrastructure-as-code tools like Terraform, and third-party integrations.
  • Flexible Database Support

    Database and persistence are selected according to scale, availability and recovery requirements. For production installations, we document backup and restore procedures.
  • Role-Based Access Control

    Administrative responsibilities and access are separated through available roles, groups and policies. The exact scope depends on version and edition.
  • High Availability Routes

    Redundant control-plane and routing components are included where availability requirements demand them. Commercial Starter adds active-active HA among other capabilities.

Infrastructure, integration and operations

NetBird as part of your infrastructure

We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.

Architecture and migration

Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

  • On-Premise

    In your data center: Installation on bare-metal, VM or Docker · Integration with existing Active Directory/LDAP

  • Cloud Installation

    AWS, Azure, Hetzner & more: Terraform/IaC setup (optional) · Kubernetes or Docker Compose · Capacity and scaling design

  • Enterprise Setup

    Advanced architecture after technical and licence assessment: HA and recovery design where supported by the application and edition · Logging according to feature set and edition · Custom security policies

Network and identity

SSO, secure access, internal systems and existing security components are integrated appropriately.

  • VPN Access

    WireGuard, NetBird, Tailscale, Headscale, OpenVPN, Cloudflare Tunnel

  • SSO Integration

    Directly or through an upstream identity layer

  • Multi-Factor Auth

    Depends on application, edition and identity provider

  • Firewall & Hardening

    Fail2Ban, Rate Limiting, IP Whitelisting

Monitoring and service level

Updates, backups, technical monitoring and response paths follow a transparent operational scope.

  • 24/7 proactive monitoring

  • Updates and patches

    CVE and security-advisory monitoring for the operating system and managed application, regular updates, and priority deployment of available patches for critical vulnerabilities

  • Daily backup with 7-day retention

  • Personal technical contact

Full-service installation with no hidden costs

What the NetBird setup includes

  • Complete installation & configuration
  • SSL certificate & reverse proxy setup
  • Backup strategy & disaster recovery
  • Performance optimization & tuning
  • Security hardening following OWASP
  • Monitoring & logging setup
  • Documentation & best practices
  • Administrator training (remote)
  • 30 days email support included
  • Dedicated contact person
  • Optional integration: LDAP/AD, SSO, MFA
  • Update strategy & patch management setup

The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.

Use Cases

Perfect for These Use Cases

  • Serverless Functions & FaaS

    Connect AWS Lambda, Azure Functions, and other serverless environments to your private infrastructure without exposing services to the internet. Access databases, APIs, and internal resources securely.
  • Multi-Cloud Infrastructure Connection

    Securely connect your infrastructure across AWS, Azure, Hetzner, DigitalOcean, and on-premises servers. No need to expose services publicly - maintain and troubleshoot systems through secure private access.
  • Container & Kubernetes Networking

    Provide private access to cluster APIs, admin tools and selected internal services through routing peers and identity-based policies. The Kubernetes CNI and network policies remain responsible for communication inside the cluster.
  • Custom Use Cases & Infrastructure Consulting

    We assess whether NetBird fits the network, identity, security requirements and operating model and compare it with WireGuard, Headscale or existing VPN solutions where appropriate.

Connectivity as a system layer

NetBird connects sites and platforms without turning them into a public environment

NetBird is more than remote access for individual users. It can connect cloud networks, Proxmox, Kubernetes, App Nodes, AI Cubes and internal services under one controlled access and routing model.

Configure Managed NetBirdView hybrid operations

Identities and policies

Users, devices, roles and permissions are managed centrally and transparently.

Sites and networks

Cloud, data centre and on-premises networks connect through defined routes.

Managed platform

The control plane, relays, updates, monitoring, backup and support are operated under the managed model.

Clearly defined migration

Replace an existing VPN with tested parallel operation

WZ-IT builds the new secure-access path, migrates a pilot group and documents testing, rollback and the wider rollout.

  • from €2,490 excl. VAT
  • Pilot in 2 to 3 weeks

Frequently Asked Questions

Answers to the most important questions

General Information

Self-Hosting & Installation

NetBird vs. Alternatives

Enterprise & Security

Technical Details

Knowledge

Further guides

In-depth knowledge from our remote access knowledge base.

Reviews & projects

Client feedback on networking and secure access

From the NetBird setup with Kubernetes cluster connectivity to site networking in production.

WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.
Steve KirchnerManaging Director, nextGYM GmbH
View project

International

Built in Germany's Ruhr Valley. Running worldwide.

WZ-IT designs, develops and operates infrastructure and software for clients in Germany and internationally. We deliver projects remotely and continue supporting them in ongoing operations after go-live.

Selected projects

Read client reviews

  • Connect sites and clusters securely
  • Secure your Proxmox & backup setup
  • Modernize your infrastructure - sovereign
  • Plan a sovereign open-source stack
  • Integrate a local AI solution
  • Modernize your legacy software
  • Cut cloud cost - up to −81%
  • Build a high-availability Proxmox cluster
  • Virtualize with Managed Proxmox
  • Design an open-source AI architecture
  • Get collaboration fully managed
  • Ship your prototype to production

NetBird

Scope a managed NetBird deployment

Name users, devices, networks, and the required operational scope. We assess the architecture and required edition.

  • Straight with Timo and Robin - no sales team, no pitch
  • An honest take, including when we are not the right fit
  • Concrete next steps for infrastructure, software or AI

No risk: worst case, you leave with a clearer understanding of your project than before.

Timo and Robin, founders of WZ-IT

How should we support your NetBird deployment?

Choose the appropriate starting point and add the technical context.

We usually respond within one business day. No credentials required.

WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.
Jakob ÖschlbergerInno7 GmbH