docs: add Groups and Access Control Policies guide

Explain what Groups are in NetBird, the four places they surface
(policies, setup keys auto_groups, network routes, DNS), and a
concrete segmentation plan for the current mesh:

- servers group: CT100, CT101
- personal group: mbp-13-pro, iphone-15-pro
- Replace default All->All with least-privilege policies
  (personal->servers, servers<->servers)

Includes UI and API workflows, a phased migration plan, rollback
strategy, and how to wire auto_groups into setup keys for future
deployments.
This commit is contained in:
2026-04-18 15:27:23 +08:00
parent aaece30ca6
commit d7a9fb55ec
3 changed files with 271 additions and 1 deletions

View File

@@ -101,7 +101,8 @@ reopen fd 8: permission denied
├── setup-keys-and-pat.md ← Setup Keys / PAT 操作與 API 限制繞道
├── stun-port-conflict.md ← STUN 改用 3479 (3478 被 Headscale 佔用)
├── client-troubleshooting.md ← 客戶端 Force Relay / bufferbloat 排錯
── peer-deployment-ops.md ← Docker 部署客戶端、改名、Mac daemon 重啟
── peer-deployment-ops.md ← Docker 部署客戶端、改名、Mac daemon 重啟
└── groups-and-policies.md ← Groups 與 Access Control 設計與操作
```
### 遠端伺服器192.168.42.127:/opt/netbird/