Self-Hosting NetBird Mesh VPN with Zitadel IAM: The Ultimate Enterprise Alternative to Perimeter 81
Introduction: The Cost of Modern Secure Remote Access
In the era of distributed teams and hybrid cloud architectures, securing corporate resources is no longer a luxury—it is a operational necessity. For years, enterprises relied on traditional hardware-based VPNs. However, as the corporate perimeter dissolved, solutions like Perimeter 81 emerged, pioneering the Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) markets. While these platforms offer robust security, their rigid per-user subscription models can quickly become cost-prohibitive for growing enterprises and mid-market businesses.
As IT budgets face increased scrutiny, forward-thinking infrastructure engineers and CTOs are turning to open-source, self-hosted alternatives. By combining NetBird—a cutting-edge overlay mesh VPN built on WireGuard®—with Zitadel, a cloud-native Identity and Access Management (IAM) platform, organizations can build a private, self-hosted ZTNA infrastructure. This combination not only eliminates steep licensing fees but also ensures absolute sovereignty over corporate data and access control logs.
The Anatomy of the Problem: Why Perimeter 81 Might Not Fit Your Budget
Perimeter 81 is undeniably a polished product. It integrates network security, cloud management, and zero-trust principles into a unified dashboard. However, reliance on proprietary SaaS vendors introduces several challenges:
- Escalating Total Cost of Ownership (TCO): Per-user-per-month pricing means your security budget scales linearly with headcount, regardless of actual network utilization.
- Data Sovereignty Concerns: In highly regulated industries (such as finance, healthcare, or government), routing sensitive corporate traffic through third-party infrastructure introduces compliance complexities.
- Vendor Lock-in: Migrating away from a proprietary ecosystem becomes increasingly difficult as more policy engines and routing rules are integrated into their closed platform.
By shifting to a self-hosted model, organizations reclaim control over their financial and operational destinies without compromising on architectural integrity.
Introducing the Power Duo: NetBird and Zitadel
What is NetBird?
NetBird is an open-source platform that allows organizations to create a secure, private mesh network connecting servers, cloud instances, and worker devices. Unlike traditional hub-and-spoke VPNs that route all traffic through a single, often congested gateway, NetBird establishes peer-to-peer (P2P) encrypted connections directly between devices using the WireGuard protocol. If a direct connection is blocked by strict firewalls or NATs, NetBird automatically falls back to encrypted relay servers (TURN), ensuring seamless connectivity.
What is Zitadel?
A secure VPN is only as good as its authentication mechanism. That is where Zitadel enters the frame. Zitadel is a modern, open-source Identity Management platform designed for multi-tenancy, strong security defaults, and developer-friendly integration. It supports advanced standards like OAuth 2.0, OpenID Connect (OIDC), and FIDO2, enabling businesses to enforce strict Multi-Factor Authentication (MFA), passwordless logins, and granular role-based access control (RBAC).
Integrating NetBird with Zitadel allows you to achieve true Zero Trust Network Access: network connectivity is granted only after identity is explicitly verified, continuously authenticated, and contextually validated.
Architectural Overview: How the Integration Works
When you self-host NetBird and integrate it with Zitadel, you replicate the core functionalities of an enterprise-grade ZTNA solution. The architecture operates through a clear separation of concerns:
- Identity Provider (IdP) Layer: Zitadel acts as the single source of truth for corporate identities. It manages user credentials, enforces MFA, and handles authentication requests.
- Control Plane: The NetBird Management Service orchestrates the network. When a user attempts to connect, the NetBird client redirects them to Zitadel for authentication via OIDC. Once authenticated, Zitadel issues a token back to NetBird.
- Signal and STUN/TURN Layer: NetBird uses a signaling server to help peers discover each other and negotiate direct WireGuard connections using STUN/TURN protocols.
- Data Plane: Once the connection is established, data flows directly between peers using end-to-end WireGuard encryption. The control plane never sees or intercepts the actual data payload.
Step-by-Step Blueprint for Deployment
Setting up this infrastructure requires a clear, methodical approach. Below is the high-level roadmap to successfully deploying your self-hosted corporate mesh network.
Step 1: Preparing the Infrastructure
You will need at least one Linux virtual machine (Ubuntu 22.04 LTS or later recommended) hosted on a cloud provider of your choice (e.g., AWS, DigitalOcean, Hetzner). Ensure you have a registered domain name and access to configure DNS records, as both NetBird and Zitadel require valid SSL certificates (easily automated via Let's Encrypt).
Step 2: Deploying Zitadel IAM
The most resilient way to run Zitadel is via Docker Compose or Kubernetes, backed by a CockroachDB or PostgreSQL database. Once deployed:
- Access the Zitadel Console and set up your organization instance.
- Configure security policies, ensuring that Multi-Factor Authentication (MFA) is mandated for all corporate users.
- Create a new Project and register an OIDC Application specifically for NetBird. Note down the Client ID, Issuer URL, and Client Secret.
Step 3: Setting Up the NetBird Control Plane
Using the official NetBird self-hosting guide, clone the deployment repository and execute the setup script. During configuration, you will be prompted to input your OIDC parameters. Provide the details gathered from Zitadel. This links NetBird's management server directly to your identity provider, ensuring no user can register a device or connect to the mesh without a valid corporate identity.
Step 4: Defining Access Control Lists (ACLs)
With both systems running, you can leverage NetBird's powerful dashboard to define access rules. Instead of giving every user full access to the entire network, you can group devices and users. For instance, you can create a rule specifying that only users in the "DevOps" group (passed via Zitadel OIDC claims) can access the "Production Database Server" peer.
Comparing the Cost: Perimeter 81 vs. Self-Hosted Stack
To put the financial benefits into perspective, let's examine a typical mid-sized business scenario with 100 remote employees and 20 cloud servers:
| Metric | Perimeter 81 (Enterprise/Premium tier) | Self-Hosted NetBird + Zitadel |
|---|---|---|
| Licensing Fees | ~$12 - $20 per user/month (~$1,200 - $2,000/month) | $0 (Open Source / Self-Hosted) |
| Gateway/Server Costs | Included or additional per-gateway fee | Cloud VM infrastructure (~$40 - $100/month) |
| Data Transfer Costs | Subject to vendor fair-use limits | Standard cloud egress rates (often minimal via direct P2P) |
| Data Sovereignty | Hosted on vendor cloud | 100% Owned by your organization |
While self-hosting introduces an operational overhead in terms of maintenance and updates, the raw infrastructure savings often exceed 80% to 90% annually compared to SaaS subscriptions. This frees up crucial capital that can be reinvested into other core engineering initiatives.
Conclusion: Embracing Sovereign Zero-Trust
Replacing a polished SaaS platform like Perimeter 81 requires a shift in mindset, but the rewards are profound. By pairing NetBird's blazing-fast WireGuard peer-to-peer architecture with Zitadel's advanced, compliant identity management, you build a state-of-the-art corporate network. You gain complete financial predictability, uncompromising performance, and absolute ownership over your organization's digital perimeter. It is time to stop paying premium per-seat tax for secure access and start building your own sovereign, enterprise-grade ZTNA framework.
