netbird mgmt might reject unknown top-level JSON keys depending on parser flags. The rendering note stays in turnserver.conf (# comments are valid INI syntax). After this, the rendered management.json will be byte-identical to what's currently live on the VPS, so the dry-run will show /opt/management.json as unchanged.