Self-hosted secure access gateway that lets teams reach private VPC workloads without exposing them to the public internet, with a Command Center for AWS resource discovery, guided policy automation,
NetBird Private Access Gateway with Command Center
The Command Center combines NetBird with Code Creator software that discovers private AWS resources, visualizes remote user and routing health, previews access changes before they are applied, and creates narrowly scoped NetBird resource and TCP/UDP access policies through a guarded workflow.
What You Get
Additional charges apply for Code Creator's technical additions and deployment automation, including:
Secure Access Command Center - a single-pane interface for managing private access to AWS workloads
AWS resource discovery for EC2, RDS, RDS clusters, and load balancers
First-boot endpoint and credential generation - no baked administrator password; credentials are generated on first boot and written to ~/FIRST_LOGIN.txt
Prebuilt NetBird groups, network, and routing topology created automatically during setup
Live data refresh and connection diagnostics showing whether the AWS target is running, whether the routing peer and remote user are connected, whether a private access policy exists, and whether the selected TCP resource is reachable
Guided Access Setup with a dry-run plan that requires explicit APPLY confirmation before creating a NetBird resource or policy
The Command Center does not modify AWS security groups, route tables, NACLs, or IAM policies.
How to Deploy
Deploy the AMI in the VPC containing the private resources you want to reach, attach the documented read-only IAM discovery role, and provide a public IPv4 address for the NetBird management endpoint. First boot configures HTTPS, creates customer-specific credentials and the Code Creator routing topology, and writes login information to ~/FIRST_LOGIN.txt.
Human users can be enrolled with NetBird's embedded local identity system or an external identity provider. Setup key enrollment is available for quick validation and managed or server devices.
Security and Hardening
The deployment runs entirely in the buyer's AWS account and uses the buyer's EC2, networking, IAM, and security controls. Key security measures include:
HTTPS/TLS - certificates issued via Let's Encrypt on first boot so peers can validate the endpoint immediately
Read-only IAM discovery role - the Command Center uses minimal permissions to discover AWS resources without write access
Narrowly scoped access policies - the Guided Access Setup creates only the specific NetBird resource and TCP/UDP policies you approve through the dry-run workflow
WireGuard encrypted tunnels - peers build encrypted point-to-point tunnels for all private network traffic
UFW firewall - host-level firewall enabled by default
SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin set to no
AppArmor - mandatory access control enforced on the instance
Kernel hardening - SYN cookies, ASLR, rp_filter enabled, kexec disabled
/tmp mounted as tmpfs with nosuid, nodev, noexec flags
auditd - system call auditing of critical paths
Anonymous telemetry disabled by default
Architecture Overview
The AMI runs the complete NetBird control plane on a single instance: the management service, signal service, relay, STUN server, and an embedded identity provider. All services are multiplexed behind one TLS port with an nginx TLS perimeter. The local datastore uses SQLite on the persistent volume.
NetBird geolocation-based posture functionality is disabled in this build.
External Dependencies
The default automated public IP deployment uses sslip.io DNS for its generated hostname and Let's Encrypt for TLS certificate issuance and renewal. Internet connectivity to these services is required. Neither service requires a separate paid subscription.
Get Started
Launch the AMI from AWS Marketplace, attach the read-only IAM role, and the first-boot process handles HTTPS configuration, credential generation, and routing topology creation automatically. Once logged in, use the Command Center to discover your private AWS resources and set up secure access through the guided workflow.
Highlights
Unified Command Center for private access operations: Discover EC2 instances, RDS databases, RDS clusters, and load balancers across your AWS account. Monitor remote users and routing health in real time, refresh live AWS and NetBird state on demand, and trace the complete private-access path from source peer to target resource - all from a single GUI. Eliminates the need to switch between the AWS Console and NetBird dashboard for day-to-day access management.
Dry-run preview before any access change takes effect: The Guided Access Setup validates your private target, displays a detailed plan of proposed changes, reuses the Code Creator routing topology, and creates narrowly scoped NetBird resource and TCP/UDP access policies only after you explicitly confirm with APPLY. This preview-then-commit workflow helps prevent misconfigurations and ensures every policy change is intentional and auditable before it reaches your network.
Automated first boot reduces manual NetBird deployment steps: Launching the AMI triggers automatic provisioning of HTTPS, unique customer credentials, NetBird groups, the private access network, a routing peer, and built-in diagnostics.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour based on the EC2 instance size you choose to run the gateway. All seven options bill the same way, differing only in compute capacity. The t3a options use one processor family, while the t3 options use another. Within each family, sizes range from medium through 2xlarge, so hourly cost rises as you select more compute. Pick the size that matches your expected network load. You can start small and move to a larger instance if your traffic grows.
Top-of-mind questions for buyers
What does the hourly instance charge cover, and what am I billed for separately?
You pay per hour for the running gateway instance you select. The charge meters running time on the compute size you pick. Underlying AWS resources, such as storage or data transfer, bill separately through your AWS account. The software charge covers only the gateway running on that instance.
Am I charged when the gateway instance is stopped or powered off?
Hourly software charges apply only while the instance runs. A fully stopped instance stops accruing software charges. Note that AWS storage tied to a stopped instance may still incur its own fees, billed separately from this software.
What does this gateway do, and does deployment require complex network setup?
NetBird is a Zero Trust networking platform. It creates encrypted point-to-point tunnels between your devices without a central VPN server. Devices connect directly, so you avoid opening ports or writing complex firewall rules. The hourly charge runs this gateway on the compute size you choose.
docs.netbird.io
Helpful?
Vendor refund policy
You may cancel the AWS Marketplace subscription at any time. No contracts. Software charges already incurred are not refundable.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
For support inquiries related to the NetBird Private Access Gateway with Command Center, contact Code Creator by email at info@codecreator.com.
Code Creator provides assistance with the Command Center software, first-boot configuration, AWS resource discovery, Guided Access Setup, connection diagnostics, and NetBird deployment issues specific to this product.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a software product wherein additional charges apply for Code Creator automated AWS deployment, no domain quick start configuration, secure private network setup, EC2 ready configuration, and AWS Marketplace AMI engineering. Deploy a private NetBird based VPN and secure access server in your own AWS account with browser based management
Code Creator deploys a private InfluxDB 3 Core telemetry appliance with Command Center, Explorer, health checks, and S3 backup on AWS. Repackaged open source with additional charges.
Self-hosted AI gateway for centralized LLM provider routing, virtual key management, and spend tracking. Deploy on your own AWS instance with automated first-boot setup.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.