Per-application WireGuard split tunneling for Linux and Windows.
Run one application through a VPN while the rest of the computer keeps using its normal connection. Conduit keeps ordinary WireGuard profiles provider-agnostic and gives both platforms the same everyday command:
conduit discord
On Linux, Conduit creates a network namespace containing its own WireGuard interface, routes, and DNS configuration. This gives every launch a genuinely isolated network stack.
On Windows, Conduit uses WireSock Secure Connect and generates a protected,
session-only profile with an AllowedApps filter. The original WireGuard
profile is never modified.
| Capability | Linux | Windows |
|---|---|---|
| Per-application tunnel | Network namespace | WireSock application filter |
| Kill switch | Namespace has no fallback route | WireSock network lock |
| Concurrent profiles | Yes | One active tunnel |
| Attach another command | Yes | No |
| Profile layout | ~/vpns |
%USERPROFILE%\vpns |
- Only the selected application uses the VPN
- A kill switch prevents fallback to the normal connection
- Random or explicit profile selection
- Provider folders for Proton, Mullvad, Windscribe, Cloudflare, or any WireGuard provider
- Automatic Cloudflare WARP profile bootstrap
- One-line Windows installation and Administrator-approved self-update
- Detached GUI sessions with status, logs, and explicit cleanup
- Update-safe Discord, Discord PTB, and Discord Canary discovery on Windows
- A non-blocking update notice when a newer Conduit release is available
- Managed Windows desktop, Start Menu, and login-startup shortcuts
The common commands are:
conduit discord
conduit --vpn mullvad-se firefox
conduit --provider proton discord
conduit --provider windscribe discord
conduit show-vpn
conduit status
conduit logs
conduit kill
conduit kill --all
conduit add shortcut discord
conduit remove shortcut discord
conduit add startup discord
conduit remove startup discord
Use conduit --help for platform-specific details.
Required packages are wireguard-tools, iproute2, util-linux, curl,
jq, and sudo or doas.
git clone https://github.com/blueberi99/conduit.git
cd conduit
chmod +x conduit.sh install.sh uninstall.sh
./install.shSee Installation.md for the complete Linux guide.
The Windows backend depends on WireSock Secure Connect, a separately licensed, mostly proprietary third-party product. WireSock is not part of Conduit and is not covered by Conduit's AGPL license. Its free edition is limited to personal, educational, and non-profit use and includes telemetry; commercial use requires a separate WireSock license. See Third-party notices.
Open PowerShell as Administrator and run:
irm https://raw.githubusercontent.com/blueberi99/conduit/master/bootstrap.ps1 | iexIf WireSock is not already present, the installer displays these terms and
requires you to type ACCEPT before asking winget to install it under the
WireSock EULA. If no .conf profile exists, it also installs WireGuard for
Windows and creates a Cloudflare WARP profile.
Open a new terminal and verify the installation:
conduit doctor
conduit show-vpn
conduit discordUpdate later with an Administrator/UAC prompt:
conduit updateApplication launches briefly check Conduit's official VERSION file. When a
newer release exists, Conduit prints a warning to run conduit update; an
offline or unreachable check never blocks the VPN session. Set
CONDUIT_NO_UPDATE_CHECK=1 to disable this check for the current environment.
After a Windows upgrade, the first normal Conduit command also shows release
notes for every version newer than your previous installation, up to the newly
installed version. This appears only once and uses the bundled changelog, so it
works offline. Fresh installs and same-version reinstalls do not trigger it.
Version queries, update, bootstrap, and internal background commands leave
the notes pending for the next normal invocation.
On Windows, add shortcut creates a clearly named Conduit - <App> shortcut
on both the current user's desktop and Start Menu. add startup creates a
managed shortcut in the user's Startup folder so the application launches through
Conduit at sign-in. Re-adding replaces only the matching Conduit shortcut;
remove shortcut removes both desktop and Start Menu entries; remove startup
removes only the sign-in entry. The application's original shortcut is preserved.
WireSock Secure Connect is free for personal, educational, and non-profit use; commercial use requires an appropriate WireSock license. See Installation-Windows.md for setup, Discord update handling, limitations, and recovery instructions.
Conduit recursively discovers ordinary .conf files:
vpns/
├── proton/
│ └── PDE-778-DE-778.conf
├── mullvad/
│ └── de-sto-wg-001.conf
├── windscribe/
│ └── Athens-Odeon-WG.conf
└── cloudflare/
└── warp.conf
Standard Windscribe WireGuard profiles are supported, including dual-stack
Address values, provider DNS, and PresharedKey. Legacy flat files named
Windscribe-*.conf can also be selected with --provider windscribe.
Without --vpn, Conduit chooses a random profile and avoids the last-used one
when another choice exists.
Linux network namespaces can isolate several simultaneous applications and
profiles. Windows has no equivalent public desktop API, so the Windows backend
allows one active Conduit tunnel and does not implement attach.
Discord's Windows executable lives in a changing app-<version> directory.
Conduit resolves the newest executable at launch and filters the stable Discord
installation root, so Discord updates do not invalidate the VPN rule.
Windows resolves hostnames before WireSock's per-application filter sees the
result. Conduit compares Discord DNS answers with a trusted public resolver and
fails early with a specific remediation message if the host or ISP resolver is
rewriting them. This prevents a connected WireGuard tunnel from silently
sending Discord to a block-page address. conduit doctor reports the same
condition. The Windows installer configures Cloudflare system DNS on connected
physical Internet adapters and enables native DNS over HTTPS when available.
Original DNS settings are saved and can be restored with conduit dns restore
from Administrator PowerShell. Use -SkipSystemDns with install.ps1, or set
CONDUIT_SKIP_SYSTEM_DNS=1 before running the online installer, to keep existing
system DNS. See Windows DNS configuration.
AGPLv3. Derivatives must remain open source under the same license and preserve the copyright notice. If a modified version is run as a network service, its source must be offered to users. See LICENSE.