Where Does NetBird Store Config and Peer State?
Where NetBird keeps its config.json file, WireGuard private keys, and peer state on Linux and Docker.
Last updated
NetBird splits peer files two ways: config.json in /etc/netbird for identity and server URL, state in /var/lib/netbird for keys, routes, and sync data. The management plane holds the network policy; the peer holds only its own keys.
That split decides disaster recovery. Losing config means re enrollment with a fresh setup key; losing state just forces a re sync. Never copy a private key between peers: each machine enrolls separately and shares nothing local. The up command re registers cleanly.
Where NetBird stores this, by platform
/etc/netbird/config.json
config.json plus the private key here. Service runs as root, so permissions are locked down by install. The setup key enrolls once and should leave the machine afterward.
Frequently asked questions
where is the netbird config file
In /etc/netbird/config.json (management URL, log level, interface settings). The private WireGuard key lives beside it and must never leave the host. Reinstalls generate fresh keys, which means re approving the peer in the admin panel.
where does netbird keep peer state
Under /var/lib/netbird (state.json, network map cache, Rosenpass state). Delete it with the service stopped to force a clean re sync; the peer re registers on next start. Keep the config.json; only the state tree is disposable.
does netbird in docker need a volume
Yes through a persistent volume holding config and state, or the container re enrolls on every recreate. The setup key for enrollment is one time, so store it in a vault rather than the compose file. Logs go to stdout for the collector.
Notice an outdated path? Let us know.