Readable firewall profiles built on the firewall you already have.
Renders documented workstation, server, and container-host policies for nftables or UFW. Version 0.1 does not silently apply rules.
python src/firewall_kit.py render workstation --backend nftablesFor a global firewall-kit command, run python -m pip install ..
Run the command with --help for every option. The tool works locally, collects no telemetry, and supports machine-readable output where applicable.
- Local first. Host data stays on the host unless you explicitly configure a webhook.
- Safe by default. Inspection is read-only and mutation requires a deliberate command.
- Small contract. The tool solves one defensive job and reports its limits plainly.
- Scriptable. Stable exit codes and structured output make automation practical.
The initial release targets Linux. Portable behavior is also tested on Windows where the underlying operating-system facilities allow it. See the threat model for trust boundaries and non-goals.
This repository uses Python and the standard library only. Version 0.1 renders policies without applying them; review the generated rules in an active administrative session before loading them with the operating-system firewall.
python -m compileall -q src
python -m unittest discover -s tests -vMIT © Dispersal Wolves.