FYRwallGitHub
v0.1.0 - open source, Apache-2.0 with Commons Clause

The safe way to manage Linux firewalls

curl -fsSL https://fyrwall.docs.potenfyr.in/install.sh | sudo sh
UFWiptables-legacyiptables-nftnftablesfirewalld detectionsystemdOpenRCrunits6amd64arm64arm386ppc64les390xriscv64DebianUbuntuFedoraArchAlpineUFWiptables-legacyiptables-nftnftablesfirewalld detectionsystemdOpenRCrunits6amd64arm64arm386ppc64les390xriscv64DebianUbuntuFedoraArchAlpine
🔒

Never locked out

Every risky change is blocked or auto-rolled back with restore points and SHA-256 verified state.

🛡️

Unprivileged by design

The web server never runs as root. Typed agent socket, zero shell, zero interpolation.

🌍

Any Linux, any arch

Debian to Alpine, amd64 to riscv64. Fully offline-capable, no telemetry, ever.

Transactional applies

Authorize, lock, validate, snapshot, apply, verify, rollback. Every single time.

🧭

Ownership detection

UFW, iptables-legacy/nft, firewalld, nftables - conflicting managers block writes safely.

🧩

Extensible

Dashboard widgets, notification channels, probes and templates via sandboxed manifests.

Every firewall change walks the full pipeline

authorizelockvalidatedetect conflictssnapshotapplyre-readverifyauto-rollback on failure
7
release architectures
46+
tests in CI, Docker-isolated
0
root processes in the UI path
100%
offline capable