Under Validation

Write WireGuard ACLs as YAML. Compile nftables locally.

A planned local CLI that turns one policy file into previewable nftables for custom WireGuard peers. Compile and inspect only — it will not apply rules to a live host. Waitlist only; no binary yet.

Concept validation only. No payment, no commitment, no recurring newsletter.

Local-first directionPortable outputsBuilt around a specific workflowEarly access is free

Proposed local workflow

Concept stage only. Signup measures search demand, not a shipping compiler.

01

One YAML policy

Declare users, tags, and ports once. The compiler emits nftables you can read in git.

02

Dry-run preview

See allow/deny as a table before any rule is loaded. v1 will not write to a live firewall.

03

On-device

Policy files stay on your machine. No cloud control plane.

This is a product decision, not a finished product.

The concept is being validated before development time is committed. Joining tells us the problem is relevant to you and gives you first access if the evidence supports a build.

  • You will not be charged.
  • Your email is only used for this experiment.
  • You can leave the list at any time.

Questions, answered clearly.

The current scope, privacy model, and next step without launch-day promises.

Does this apply nftables for me?

No. The concept is compile-and-preview only so a bad policy cannot lock you out.

Does this replace Tailscale ACLs?

No. Tailscale users should keep official GitOps ACLs. This targets custom WireGuard overlays only.

Does this guarantee the intended outcome?

No. Generated rules still need human review. A mis-specified YAML can still describe a bad policy.

What happens when I request access?

Your email is recorded for this experiment only. You receive one relevant update or beta invitation if the concept moves forward.

Early access

Want a local WireGuard YAML→nftables preview?

Join the waitlist. One email if a local beta opens; no newsletter drip.