nebula: Build Secure Peer-to-Peer Overlay Networks

Summary
Nebula connects hosts across networks through an encrypted, certificate-based overlay, with group-based traffic rules and peer discovery. It suits teams that need secure connectivity across cloud, datacenter, and endpoint environments without relying on a fixed addressing scheme.
At a glance
- Language
- Go
- License
- MIT
- Stars
- 18.4k
- Forks
- 1.2k
- Added to OSRepos
- October 26, 2025
- Last analyzed
- October 3, 2026
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Overview
Nebula is a Go-based overlay networking tool for connecting computers securely across the internet. It creates a mutually authenticated peer-to-peer network, so hosts can communicate across cloud providers, datacenters, and other networks without requiring a particular addressing scheme.
It is aimed at teams that want control over network identity and traffic policy. Certificates identify hosts and their groups, while lighthouses help peers discover one another and can support UDP hole punching through many firewalls and NATs.
Key Features
- Encrypts peer connections using the Noise Protocol Framework, with ECDH and AES-256-GCM in the default configuration.
- Uses certificates to identify hosts by IP address, name, and group membership.
- Supports group-based traffic filtering across providers and environments.
- Provides lighthouse nodes for peer discovery and optional UDP hole punching.
- Runs on Linux, macOS, Windows, iOS, and Android, with desktop and server packages also listed for FreeBSD.
- Includes
nebula-certfor creating a certificate authority and signing host certificates. - Offers build targets for Go FIPS 140-3 mode and P256 cryptography for deployments with compliance requirements.
Use Cases
- Teams connecting servers across multiple cloud providers or datacenters without maintaining a shared network address plan.
- Administrators creating private connectivity between employee laptops and internal hosts, with access rules based on certificate groups.
- Small organizations or individuals linking their own devices across home, office, and hosted networks.
- Operators needing a self-managed peer network, or evaluating a managed option when they do not want to run their own PKI and lighthouses.
Project Facts
- Language: Go
- License: MIT
- Stars: 18.4k
- Forks: 1.2k
- Topics: none listed
- Archived: No
Getting Started
On Debian, install the package with:
sudo apt install nebula
A working network also needs host certificates and configuration. See the README and official documentation for setup details.
Alternatives
- tailscale: Tailscale builds WireGuard-based private networks with integrated authentication, while Nebula uses certificate-based identities and group-based traffic rules.
- EasyTier: EasyTier emphasizes decentralized VPN connectivity with NAT traversal and optional relays, while Nebula uses certificate-based identity and peer discovery.
Considerations
- Initial setup requires a certificate authority and host certificates. The CA private key is sensitive and must not be copied to individual nodes.
- A lighthouse is optional, but the README recommends having at least one discovery node with a routable IP address for peer discovery.
- Certificate authorities expire by default after one year, so deployments need a plan for renewal or rotation.
- FIPS mode and P256 are available for compliance needs, but the README describes these as non-default options. BoringCrypto support is deprecated and is slated for removal in the next release.
- Although the project supports several platforms, the available packages and installation steps differ by platform.
Source repository
Open the original repository on GitHub.
18 counted GitHub visits
Related repositories
Similar repositories that may be relevant next.

e2a: Open-Source Email API for Applications and AI Agents
September 29, 2026
e2a is an open-source email API designed for applications and AI agents, offering robust transactional email capabilities and real two-way inboxes. It supports both managed hosting and self-hosting with Docker, providing features like human-in-the-loop approval and advanced content screening. Built in Go, e2a aims to bridge email's universal addressability with the structured data world of AI agents.

Router: Optimize AI Model Selection and Costs for Agentic Systems
September 28, 2026
The Weave-OS Router is an intelligent model router for agentic systems, optimizing AI model selection for every request. It acts as a drop-in proxy for major AI providers, routing prompts to the most suitable model in under 50ms. This solution helps users significantly cut costs, often by 40-70%, simply by changing an endpoint.

KSail: The All-in-One Kubernetes SDK for Cluster Management and GitOps
September 27, 2026
KSail is a comprehensive Kubernetes SDK designed to simplify cluster creation, management, and operation across multiple distributions like Kind, K3d, Talos, and VCluster. It integrates essential features such as GitOps, secrets management, an AI assistant, and an MCP server, making cloud-native development accessible with just Docker or a cloud provider.

Memoh: An Open-Source Multi-Agent Platform with Dedicated AI Workspaces
September 26, 2026
Memoh is an innovative open-source multi-agent platform designed to provide each AI agent with its own dedicated cloud computer. This includes a filesystem, desktop, browser, network, and persistent long-term memory, ensuring agents remain online 24/7. Users can integrate their own API keys or host existing AI models, fostering a versatile and always-on environment for AI development and deployment.