Netmaker

Netmaker·Netmaker.Netmaker

Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.

winget install --id Netmaker.Netmaker --exact --source winget

Latest 1.7.0·August 31, 2026

Release Notes

Netmaker v1.7.0 Release Notes 🚀

🚀 What’s New

🏢 Multi-Tenancy for MSPs (Organizations & Tenants)

Run multiple customer environments from a single Netmaker server.

• Organizations & tenants — Group customers under an organization; each tenant is an isolated Netmaker environment (networks, devices, users). • MSP license sync — EE/MSP installs create and update orgs/tenants from the MSP license (including teardown when a tenant is removed from the license). CE and normal Pro accounts continues to use a single local default tenant. • Scoped access — API and nmctl select the target org/tenant via X-Organization-ID / X-Tenant-ID (--org_id / --tenant_id), with nmctl organization list and nmctl tenant list for discovery.

🔌 TCP Proxy / WSS Uplink

Gateways can publish a TCP/WSS uplink so clients can reach the mesh in restrictive environments when UDP is blocked.

• Enable TCP proxy on the gateway/host (tcp_proxy_enabled and related listen/TLS settings). • Clients can opt into a TCP uplink to the gateway when the proxy is enabled. • Supports self-signed and externally terminated TLS modes for WSS endpoints.

🛡️ EDR Integration (Pro)

Connect endpoint detection and response platforms for posture checks from Integrations.

• Supported providers:Microsoft Defender, CrowdStrike, SentinelOne, and Wazuh. • Sync managed endpoints and evaluate EDR compliance (agent health / risk level) as part of device posture. • Configure, test, and manage integrations via the REST API (/api/v1/integrations/edr/{provider}).

📱 MDM Integration (Pro)

Connect mobile device management platforms for device compliance posture from Integrations.

• Supported providers:Microsoft Intune, Jamf, JumpCloud, and Iru. • Match devices by Entra device ID, serial number, hardware UUID, or hostname. • Enforce MDM enrollment/compliance checks alongside existing posture policies. • Configure, test, and manage integrations via the REST API (/api/v1/integrations/mdm/{provider}).


🗄️ Database Schema Migration

This release completes the SQL schema path and introduces multi-tenancy (org/tenant) bootstrap as part of the v1.7.0 migration.

Upgrade requirement (existing deployments):

• You must run Netmaker v1.6.0 successfully before upgrading to v1.7.0. • v1.7.0 will refuse to start if migration-v1.6.0 has not completed on a prior v1.6.0 deployment. • Recommended path:deploy v1.6.0 → confirm the server starts cleanly → then upgrade to v1.7.0.

Impact:

• Schema and data are updated automatically on successful startup. • Downgrades may not be supported after migration.

👉 Action Required:

• Do not jump from v1.5.x (or earlier) straight to v1.7.0 on an existing database. • Ensure migrations complete and validate core functionality post-upgrade.

For detailed upgrade steps, refer to the official upgrade documentation:

Server Upgrades v1.5.1+


🧰 Improvements & Fixes

• Auto-relay peer reset — Reset a specific peer-to-peer connection that is using a relay (clear/reassign auto-relay for that peer pair) without resetting the entire network’s auto-relay state.

• Migration reliability — v1.7.0 blocks startup until v1.6.0 migration completed on existing deployments; migration failures exit cleanly instead of panicking.

• Host status — Host filtering uses live check-in status (Online/Offline/Disconnected) rather than a stale DB value.

• MSP installs — nm-quick.sh -s flag to skip nmctl/mesh/netclient on MSP server installs.


🐞 Known Issues

• IPv6-only machines
Netclients cannot currently auto-upgrade on IPv6-only systems.

• Multi-network join performance
Multi-network netclient joins using an enrollment key still require optimization.

• systemd-resolved DNS limitation
On systems using systemd-resolved in uplink mode, only the first 3 entries in resolv.conf are honored; additional entries are ignored. This may cause DNS resolution issues. Stub mode is recommended.

• Windows Desktop App + mixed gateway modes
When the Windows Desktop App is connected to both: • a Full Tunnel Gateway, and • a Split Tunnel Gateway

the gateway monitoring component may disconnect from the Split Tunnel Gateway.

Installer type: portable

x64—511A9CA49390CBEE0895BB20DD5D07102C6AC83C6E35973B99073CAF818DE841

Details

Homepage
https://github.com/gravitl/netmaker
License
Apache 2.0
Publisher
Netmaker
Support
https://github.com/gravitl/netmaker/issues
Copyright
Copyright (c) Netmaker,Inc.

Tags

clouddevsecopsk8skubernetesmeshnetworknetworkingsecurityvirtual-networkvpnvpn-serverwg-quickwireguardwireguard-uiwireguard-vpnzero-trust

Older versions (11)

1.6.0
x64—B9A5E2B30D81A4C8247786D792E251E2278B7036D2A7902CFB4C1905DDCFCDD9
1.5.1
x64—3C81211A7DEE96277E866AA7D070D46042616A236256EF700A18A1E00510CBE0
1.5.0
x64—EDE3850DECF9AE43B36D7E7A2A1098BD51F8821265754E30A8027C0E5A41ECC5
1.4.0
x64—0E7B23D302422AF7DDC1AF0604F89B92EB30CABF74E7DEE034D26B99B989BFF6
1.2.0
x64—1EA2AA2086AA247907B5760D3C2C477E143B387999308374A7A0E02A4FD92150
1.1.0
x64—FFCE26BD6754FD9A559EF7907A4B21532E4A93048A7E58B89BC15F32CD03D87E
1.0.0
x64—63039A8EE59226717B77504F85E1D2BDE280CBFEC23EBAD7B40DD06A74499830
0.99.0
x64—F1D11B289DB406FC95B127AA50E904C77275F102AE4E47AC81850D8DDF415FAF
0.90.0
x64—83204B708CA268A9C7D7CD3CE4EA3E940BDA0F9222114C991E174609F6B1C984
0.30.0
x64—7A3E272176EB6169EFADB24A413B1E5FD41DF6D593BC5E5AB0FB1CA50538E667
0.24.0
x64—1FC1FF34C28795C480A33257172E920252110409510FD05CBF46F47559229946