HOSTED BY

Vultr

TRACK PARTNER

NetBird

THE AGENT ARENA HACKATHON · SEP 26–27 · SAN FRANCISCO

Connect your stack.
Expose what matters.

How hackathon teams use NetBird: peer-to-peer WireGuard networking, a built-in reverse proxy, and one-command sharing with netbird expose.

Brandon Hopkins · Head of Content and Developer Relations, NetBird

THE PROBLEM

Your stack is spread everywhere

Your laptops

Agent code, the demo UI and local tools

Vultr VMs

Agent backends and tool servers

A GPU box

A teammate's machine serving a model

Isolated networks

A Docker stack or a subnet with no way in

The quick fixes are public IPs, open ports and shared SSH keys. Each one widens what an agent, or anyone scanning the internet, can reach.

NetBird

The Agent Arena Hackathon · San Francisco

WHAT NETBIRD IS

Open Source networking on WireGuard

Install the client on any machine and sign in. It joins your private network with its own 100.x address.

From there it can reach any peer your policies allow, from any network, behind any NAT.

Peer-to-peer

Direct WireGuard tunnels between machines, with NAT traversal and an encrypted relay as fallback.

Access by identity

Sign in with SSO and MFA. Groups and policies replace IP allowlists.

Runs everywhere

Linux, macOS, Windows, iOS, Android, Docker and Kubernetes.

Open source

Use NetBird Cloud, or run the whole control plane yourself.

NetBird

The Agent Arena Hackathon · San Francisco

PEER-TO-PEER CONNECTIVITY

How two peers connect

Management

Signal

STUN

Relay

Identity provider
(e.g., Okta)

NetBird

Peer A

netbird
agent

Peer B

netbird
agent

managed or
self-hosted

auth

control
channel

control
channel

point-to-point WireGuard connection

NetBird

The Agent Arena Hackathon · San Francisco

NetBird

The Agent Arena Hackathon · San Francisco

IN YOUR PROJECT

How teams use it

Share an MCP server

Run tools on your laptop and let an agent on a Vultr VM call them at a private NetBird address.

Keep data private

Postgres, Redis or a vector store never gets a public IP. Only allowed peers connect.

Fence in your agents

Give agents their own group and allow only the hosts and ports they need.

REVERSE PROXY · CLOUD (BETA) AND SELF-HOSTED

Put a private service on the web

THE INTERNET

A visitor's browser

Plain HTTPS, no client to install

HTTPS

NETBIRD PROXY

TLS and auth at the edge

Certificates issued for you

WireGuard

YOUR PEER

Your service

No public IP, no open ports

Protect it with

SSO / OIDC

Password

6-digit PIN

API key header

NetBird peers only

IP and country rules

CrowdSec reputation

Route it

  • Your own domain via one CNAME
  • Routing by URL path
  • HTTP or TCP, UDP, TLS
NetBird

The Agent Arena Hackathon · San Francisco

NETBIRD EXPOSE · v0.66 AND LATER

One command, one public URL

$ netbird expose 3000 --with-name-prefix demo

→ https://demo-a1b2c3.proxy.example.com

Lock it down

--with-pin
--with-password
--with-user-groups

Any protocol

--protocol tcp | udp | tls
--with-external-port
--with-custom-domain

Gone on Ctrl+C

The URL lives only while the command runs. No cleanup, no forgotten tunnels.

An admin enables Peer Expose in account settings first. Up to 10 active sessions per peer.

NetBird

The Agent Arena Hackathon · San Francisco

🔐 BONUS · ADD-ON TO CHALLENGE 1 OR 2

Zero-Port Access

Serve your project through the NetBird reverse proxy instead of opening ports on your Vultr VM, and earn bonus points on top of your challenge score.

1

No open ports

Your public demo URL is served through NetBird, with no inbound application ports on the VM.

2

Gated access

The service sits behind SSO, password, PIN or header auth, matched to a real user role.

3

Peer-to-peer

Demo the connectivity: machines on your NetBird network reaching each other directly over WireGuard.

NetBird

The Agent Arena Hackathon · San Francisco

DEPLOYMENT

Two ways to run it

OPTION 1 · FASTEST

NetBird Cloud

Free for up to 5 users and 100 machines. Nothing to host.

OPTION 2 · FULL CONTROL

Self-hosted on Vultr

A one-click Marketplace app on your own server and domain.

OPTION 1 · NETBIRD CLOUD

Start free on NetBird Cloud

$0

for up to 5 users and 100 machines


INCLUDED ON THE FREE PLAN

  • Peer-to-peer connections
  • Social SSO and MFA
  • Access policies
  • Private DNS and routes
  • NetBird SSH

1

Sign up

app.netbird.io

2

Install the client on each machine

curl -fsSL https://pkgs.netbird.io/install.sh | sh

3

Connect it

netbird up

macOS, Windows, iOS and Android installers: docs.netbird.io

NetBird

The Agent Arena Hackathon · San Francisco

OPTION 2 · SELF-HOSTED

Self-host it on Vultr

Vultr

1

Deploy the Marketplace app

Shared CPU with at least 2 GB of memory. Under Marketplace Apps, search for NetBird.

2

Enter an email and a domain

The email is for Let's Encrypt. The domain is where NetBird lives, like netbird.example.com.

3

Add two DNS records

A · netbird → your server IP
CNAME · *.netbird → netbird.example.com

4

Create your admin account

When the console prints “NetBird setup is complete”, open your domain in a browser.

WHAT THE IMAGE RUNS

  • Management, Signal and Relay
  • Dashboard with a built-in identity provider
  • NetBird Proxy for the reverse proxy and expose
  • Traefik with automatic Let's Encrypt TLS
  • CrowdSec to block known threats
  • All in Docker on one instance
NetBird

The Agent Arena Hackathon · San Francisco

NetBird

Start building

Free on NetBird Cloud, or yours on Vultr. Either way, your whole stack is one private network.

Questions this weekend? Find Brandon Hopkins, or reach out at community@netbird.io.

NETBIRD CLOUD, FREE

app.netbird.io

DOCS

docs.netbird.io

SOURCE

github.com/netbirdio/netbird

VULTR MARKETPLACE · SEARCH NETBIRD

vultr.com/marketplace