How to Completely Disable the ‘systemd-networkd’ Service in Ubuntu Server

In Ubuntu Server, systemd-networkd.service is a core systemd daemon responsible for managing network configurations. It reads configuration files from /etc/systemd/network/ and dynamically applies IP addresses, routing, and tunneling settings to network interfaces as they appear. While highly efficient for containerized environments, cloud instances, or modern declarative deployments, systemd-networkd can conflict with legacy network managers (like NetworkManager or ifupdown) or specialized SD-WAN overlay software that require exclusive control over the Linux networking stack. In environments where network interfaces are provisioned strictly by external orchestration engines (like Kubernetes CNI plugins) or legacy bridging scripts, systemd-networkd MUST be neutralized to prevent race conditions and configuration overwrites.

This guide explains how to completely disable the systemd-networkd service in Ubuntu Server, enforcing absolute manual or external orchestration control over the network stack.

Stop and Mask the systemd-networkd Service

Because systemd-networkd is a fundamental component of the modern systemd ecosystem, simply stopping it is insufficient. It may be re-triggered by D-Bus activation, socket activation, or dependencies from other units (like systemd-networkd-wait-online.service). To guarantee the init system is physically prevented from executing the daemon under any circumstances, we must explicitly mask the unit file.

  1. Log into your Ubuntu Server via SSH using an account with sudo privileges.
  2. Stop the running service immediately to release control of the network interfaces:
    sudo systemctl stop systemd-networkd.service systemd-networkd.socket
  3. Disable the service to remove it from the systemd boot targets:
    sudo systemctl disable systemd-networkd.service systemd-networkd.socket
  4. For absolute certainty, explicitly mask both the service and its associated socket. This symlinks the unit files to /dev/null, creating a hard cryptographic block against them being invoked during the startup sequence or via inter-process communication:
    sudo systemctl mask systemd-networkd.service systemd-networkd.socket

Verify the Service Lockdown

By masking systemd-networkd, you guarantee that systemd will completely bypass network interface configuration, leaving the networking stack entirely to your chosen alternative manager (e.g., NetworkManager, Netplan with NetworkManager renderer, or manual iproute2 commands).

To verify the lockdown is successful, attempt to start the service manually:

sudo systemctl start systemd-networkd.service

Systemd will return a fatal error stating that the unit is masked (e.g., Failed to start systemd-networkd.service: Unit systemd-networkd.service is masked). You have successfully neutralized the automated systemd network configuration daemon, hardening your server’s state logic and ensuring compliance with strict, externally managed deployment pipelines.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.