Omahub
← All plugins
N

NetBird

by Nico Kovacs

NetBird status, connection toggling, peer browsing, exit node selection, SSH into peers, and quick copy actions in the Omarchy bar.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
2a49595
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs persistence README.md:56

    Registers scheduled or boot-time system tasks.

    systemctl enable --now netbird`.
  • Docs sudo README.md:56

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl enable --now netbird`.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2a49595
Reviewed
1 month ago

The deterministic findings are false positives: the `sudo systemctl enable --now netbird` line is a README prerequisite for installing the NetBird daemon, not something the plugin executes. The plugin code shells out to the `netbird` CLI for status, toggle, and SSH actions, quotes dynamic values, and performs no privileged, persistent, or destructive operations.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/nico-kovacs/omarchy-plugin-netbird --enable
System #bar #quickshell #security

NetBird for Omarchy

A NetBird bar widget for the Omarchy shell. It mirrors the built-in Tailscale widget: connection state at a glance, one-click toggling, peer browsing, exit node selection, and quick copy actions.

NetBird widget in the Omarchy bar

Features

  • Status at a glance — daemon state, your own peer name and NetBird IP, and a connected/total peer count in the bar.
  • Toggle the connection — bring NetBird up or down from the panel, with an optimistic UI so the icon reacts immediately instead of waiting for the next status poll.
  • Login handling — when the daemon reports NeedsLogin, the panel surfaces the authentication URL that netbird up prints.
  • Peer browsing — every peer with its status, connection type (P2P or relayed), and latency. Connected peers sort to the top.
  • Exit nodes and networks — list advertised networks and select or deselect one without leaving the bar.
  • Profile switching — see available NetBird profiles and switch the active one.
  • Copy actions — copy a peer's NetBird IP or its short name.
  • SSH into a peer — open a terminal running netbird ssh <peer> straight from the peer row. Available for connected peers; if the peer's SSH server is disabled, netbird reports that in the terminal. The username is remembered per peer, since netbird ssh otherwise defaults to your local username and many peers run a different account.

Keyboard shortcuts

With the panel open: t toggle the connection, r refresh, and on the peer under the cursor s SSH, S change that peer's SSH username, c copy IP, n copy name, d copy FQDN.

SSH usernames

netbird ssh connects as your local username unless told otherwise, so a peer whose account differs fails with User authentication failed right after the SSO login succeeds. The username is therefore resolved as:

  1. the username remembered for that peer,
  2. the sshUser setting,
  3. nothing — netbird falls back to your local username.

The first time you SSH to a peer, the button asks for the username and remembers it. Right-click the button (or press S) to change it later. Remembered usernames live in ~/.local/state/omarchy/netbird-ssh-users.json, outside the plugin directory, so they survive a plugin update.

Requirements

  • Omarchy with the Omarchy shell (Quickshell) bar.
  • The netbird CLI on PATH, plus a running netbird daemon. On Arch: omarchy pkg aur add netbird (or yay -S netbird), then sudo systemctl enable --now netbird.

The widget shells out to the netbird binary only. It makes no network requests of its own, bundles no binaries, and never invokes sudo or pkexec. If netbird is not installed, the widget reports it and stays inert.

Installation

omarchy plugin add https://github.com/nico-kovacs/omarchy-plugin-netbird --enable

That clones the plugin into ~/.config/omarchy/plugins/ and adds the widget to your bar. To install without enabling it immediately, drop --enable and then:

omarchy plugin enable io.github.nico-kovacs.netbird right

Configuration

Configurable from the bar widget settings UI, or in ~/.config/omarchy/shell.json:

Setting Type Default Range Description
refreshIntervalSec integer 30 5–3600 How often to poll netbird status
sshUser string "" — Default SSH username; blank uses your local username

Updating

omarchy plugin update io.github.nico-kovacs.netbird

Removal

omarchy plugin remove io.github.nico-kovacs.netbird --yes

That disables the widget, removes it from your bar layout, and deletes the plugin directory. To only hide it while keeping it installed:

omarchy plugin disable io.github.nico-kovacs.netbird

Development

omarchy plugin validate .

Model.js holds the parsing logic with no QML imports, so it can be exercised directly under Node:

const M = require("./Model.js");
M.parseStatus(rawJsonFromNetbirdStatusJson);

License

MIT — see LICENSE.