One YAML policy
Declare users, tags, and ports once. The compiler emits nftables you can read in git.
Under Validation
A planned local CLI that turns one policy file into previewable nftables for custom WireGuard peers. Compile and inspect only — it will not apply rules to a live host. Waitlist only; no binary yet.
Concept validation only. No payment, no commitment, no recurring newsletter.
Proposed workflow
Concept stage only. Signup measures search demand, not a shipping compiler.
Declare users, tags, and ports once. The compiler emits nftables you can read in git.
See allow/deny as a table before any rule is loaded. v1 will not write to a live firewall.
Policy files stay on your machine. No cloud control plane.
The honest status
The concept is being validated before development time is committed. Joining tells us the problem is relevant to you and gives you first access if the evidence supports a build.
Before you decide
The current scope, privacy model, and next step without launch-day promises.
No. The concept is compile-and-preview only so a bad policy cannot lock you out.
No. Tailscale users should keep official GitOps ACLs. This targets custom WireGuard overlays only.
No. Generated rules still need human review. A mis-specified YAML can still describe a bad policy.
Your email is recorded for this experiment only. You receive one relevant update or beta invitation if the concept moves forward.
Early access
Join the waitlist. One email if a local beta opens; no newsletter drip.
Leave your email to receive the beta invitation if this concept moves forward.