FYRwall docs / v0.1.0
FYRwall Documentation
Everything about installing, configuring and operating the safe Linux firewall manager - from the first one-liner to extension manifests.
Get started
InstallationInstall FYRwall with the one-liner script, review-first, or from a release tarball. The installer never touches your firewall rules.
DockerRun the FYRwall server in a container and bridge a host-networked agent so the container can reach the real host firewall.
ConfigurationEvery FYRwall config key, FYRWALL_* environment overrides and config validation in one reference.
UpdatingUpdate FYRwall safely: database backup, restore point, verified download, migrations, health checks. Config is never overwritten.
Core topics
ArchitectureHow FYRwall is built: unprivileged server, typed Unix-socket agent, backend adapters, ownership detection and storage.
Safety and Restore PointsThe transactional apply pipeline, automatic restore points, SHA-256 verification, the safe apply timer and rollback guarantees.
Security ModelPrivilege separation, Argon2id auth, CSRF, RBAC, encrypted agent logs, secret handling and what extensions can never do.
OperationDaily workflow in the web UI, CLI essentials, tray and desktop integration, users, roles and notifications.
Reference
ExtensionsCapability-scoped, declarative extensions: dashboard widgets, notification channels, probes, rule templates and sandboxed panels.
Extensions GuideFull manifest reference for writing FYRwall extensions, with the hard rules the installer enforces.
TroubleshootingFixes for an unreachable UI, backend conflicts, SSH lockout, offline agents, disk usage and password recovery.
FAQCommon questions: licensing, supported distros, fleet management, privacy, commercial use and clean removal.
LicenseFYRwall is licensed under Apache-2.0 with Commons Clause. What is allowed, what is not, and why.