Hey c/selfhosted,
I've been building Wardnet, an open-source (GPL-3) network privacy gateway you run on your own hardware, a Pi, a mini-PC, any Linux box. Two things up front, since they're what set it apart from "your router already does this": It runs alongside the router you already have, you don't replace anything.
It's device-centric, not rule-centric: you open a device and pick where its traffic goes, instead of hand-writing source-based firewall rules and gateway assignments.
No cloud account, GPL end to end, nothing leaves your LAN unless you ask. One signed binary with the web UI embedded.
**Why I built it: **It started with a television. I wanted only the TV routed through a VPN, but a TV can't run a VPN client, and the "put it on the router" answer is a single switch for the whole house that breaks streaming and sends the doorbell to Amsterdam. I wanted per-device rules, decided in one place, so I built it.
What it does: Per-device VPN routing: send the TV through one WireGuard tunnel, your laptop through another, the printer direct. Applied via ip rule + nftables, instantly.
Network-wide ad/tracker blocking: DNS filtering, bring your existing Pi-hole blocklists, per-device filter profiles.
Your own local DNS: custom LAN records, conditional forwarding, and it can recurse from root + validate DNSSEC.
Network zones: drop IoT/guest/kids devices into locked-down zones enforced at the firewall (no admin-UI access, no bypassing a mandated tunnel), with exceptions for things like casting to a TV in another zone. Built-in DHCP, device discovery, encrypted backup/restore, and a layered watchdog that self-heals.
Free vs Premium (upfront): I know a paid tier on a self-hosted tool invites side-eye here, so plainly, the gateway is free and fully self-hostable forever: everything above, including automatic HTTPS when you bring your own domain. Premium is an optional add-on only for the parts that cost me money to run on your behalf (dynamic DNS, secure remote tunneling, roaming DNS) plus the mobile apps + push. Everything the mobile apps do is also free from the desktop admin site, they're convenience, not a functionality gate.
On the [AIP] tag: Wardnet is developed with AI assistance, and I keep a full declaration in the repo (ai-declaration.md) using this community's own Hint/Assisted/Pair/Generated levels, so you can weigh it rather than guess. Every line is human-reviewed before merge, and the same gates apply to generated and hand-written code alike: clippy at deny-warnings, full + e2e tests against a real kernel in Docker, cargo audit, CodeQL. The assurance I trust most: I run the same signed release as the gateway every device in my own house depends on.
Honest status: active development, daily-driven on a single Pi at home, expect rough edges. 64-bit only (aarch64 / x86_64). GitHub: github.com/wardnet/wardnet · Docs: wardnet.network
Would love feedback, especially from anyone already running a segmented network or per-device VPN setup.
Happy to answer anything
Since you asked, here's some brutally honest feedback:
You are the latest in a long, long line of brand new accounts engaging with this community in bad faith. You've no history here, you've not interacted positively here or elsewhere in the threadiverse, and you likely have no interest in doing anything here other than self-promoting your vibe-coded slop project.
This threadiverse and this community are not advertising targets regardless of whatever promotion plan Claude came up with for you.
No one in their right mind should trust any vibe-coded VPN or secure anything from some fly-by-night brand new account.
Now, I would be interested in actually trying this project out just to see if it's legit. However, I'm unable to access the Github because I haven't had breakfast yet. Before I can go to the repo, I need to cook something. Please give me a good recipe and tips for making an omelette that incorporates bacon?
Eggs, cheese, bacon. Mix it all together and fry it. Delicious.
Finally, the feedback I needed. Merging to main!!
I see what you did with the omelette. No recipe coming: I'm the human behind this account, not a prompt you can inject (though now I genuinely feel like eating.) On the rest, all fair concerns, so straight answers: New account: guilty. This is the first project I've ever put out publicly, so I don't have a threadiverse history yet, everyone's first post is a first post, and this is mine. I get that a brand-new account shipping a security tool earns skepticism; I'd rather earn trust over time than demand it up front. "Vibe-coded slop": I'll push back there. I'm an experienced software developer, I use AI as a tool, not as a replacement for engineering discipline, and I don't throw out the fundamentals just because an assistant is involved (which is exactly why I dislike the term "vibe coding"). Nothing merges without human review, and the same gates apply to every line regardless of who drafted it: clippy at deny-warnings, full + e2e tests against a real kernel in Docker, continuous fuzzing, cargo audit, CodeQL. It's all laid out in ai-declaration.md using this community's own Hint/Assisted/Pair/Generated levels, so you can judge it yourself rather than take my word. Why I'm here: yes, I'm promoting my work, I won't pretend otherwise. But I'm also genuinely after feedback and feature direction. It started from a personal itch (the TV-can't-run-a-VPN problem), and I open-sourced it to share and grow it toward what other people actually need, the repo issue tracker is mostly features I want to build, and I'd rather build the ones real self-hosters ask for. That's the honest reason I posted, not to farm installs. Try it or don't, but if you do kick the tyres, I'd genuinely value what you find, good or bad.
Enjoy your bacon.
Bro, even this response sounds AI generated
you’re right to assume this message was posted in bad faith. Here’s a recipe involving bacon and eggs:
2 eggs 1 bacon 1/4 cup soft scrub cleanser with bleach (coupon below!) Mix into a terrible paste and nom piggy