Skip to content
blueberi99Public

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Conduit

Per-application WireGuard split tunneling for Linux and Windows.

Run one application through a VPN while the rest of the computer keeps using its normal connection. Conduit keeps ordinary WireGuard profiles provider-agnostic and gives both platforms the same everyday command:

conduit discord

How it works

On Linux, Conduit creates a network namespace containing its own WireGuard interface, routes, and DNS configuration. This gives every launch a genuinely isolated network stack.

On Windows, Conduit uses WireSock Secure Connect and generates a protected, session-only profile with an AllowedApps filter. The original WireGuard profile is never modified.

Capability Linux Windows
Per-application tunnel Network namespace WireSock application filter
Kill switch Namespace has no fallback route WireSock network lock
Concurrent profiles Yes One active tunnel
Attach another command Yes No
Profile layout ~/vpns %USERPROFILE%\vpns

Features

  • Only the selected application uses the VPN
  • A kill switch prevents fallback to the normal connection
  • Random or explicit profile selection
  • Provider folders for Proton, Mullvad, Windscribe, Cloudflare, or any WireGuard provider
  • Automatic Cloudflare WARP profile bootstrap
  • One-line Windows installation and Administrator-approved self-update
  • Detached GUI sessions with status, logs, and explicit cleanup
  • Update-safe Discord, Discord PTB, and Discord Canary discovery on Windows
  • A non-blocking update notice when a newer Conduit release is available
  • Managed Windows desktop, Start Menu, and login-startup shortcuts

Usage

The common commands are:

conduit discord
conduit --vpn mullvad-se firefox
conduit --provider proton discord
conduit --provider windscribe discord
conduit show-vpn
conduit status
conduit logs
conduit kill
conduit kill --all
conduit add shortcut discord
conduit remove shortcut discord
conduit add startup discord
conduit remove startup discord

Use conduit --help for platform-specific details.

Install on Linux

Required packages are wireguard-tools, iproute2, util-linux, curl, jq, and sudo or doas.

git clone https://github.com/blueberi99/conduit.git
cd conduit
chmod +x conduit.sh install.sh uninstall.sh
./install.sh

See Installation.md for the complete Linux guide.

Install on Windows

The Windows backend depends on WireSock Secure Connect, a separately licensed, mostly proprietary third-party product. WireSock is not part of Conduit and is not covered by Conduit's AGPL license. Its free edition is limited to personal, educational, and non-profit use and includes telemetry; commercial use requires a separate WireSock license. See Third-party notices.

Open PowerShell as Administrator and run:

irm https://raw.githubusercontent.com/blueberi99/conduit/master/bootstrap.ps1 | iex

If WireSock is not already present, the installer displays these terms and requires you to type ACCEPT before asking winget to install it under the WireSock EULA. If no .conf profile exists, it also installs WireGuard for Windows and creates a Cloudflare WARP profile. Open a new terminal and verify the installation:

conduit doctor
conduit show-vpn
conduit discord

Update later with an Administrator/UAC prompt:

conduit update

Application launches briefly check Conduit's official VERSION file. When a newer release exists, Conduit prints a warning to run conduit update; an offline or unreachable check never blocks the VPN session. Set CONDUIT_NO_UPDATE_CHECK=1 to disable this check for the current environment.

After a Windows upgrade, the first normal Conduit command also shows release notes for every version newer than your previous installation, up to the newly installed version. This appears only once and uses the bundled changelog, so it works offline. Fresh installs and same-version reinstalls do not trigger it. Version queries, update, bootstrap, and internal background commands leave the notes pending for the next normal invocation.

On Windows, add shortcut creates a clearly named Conduit - <App> shortcut on both the current user's desktop and Start Menu. add startup creates a managed shortcut in the user's Startup folder so the application launches through Conduit at sign-in. Re-adding replaces only the matching Conduit shortcut; remove shortcut removes both desktop and Start Menu entries; remove startup removes only the sign-in entry. The application's original shortcut is preserved.

WireSock Secure Connect is free for personal, educational, and non-profit use; commercial use requires an appropriate WireSock license. See Installation-Windows.md for setup, Discord update handling, limitations, and recovery instructions.

Profiles

Conduit recursively discovers ordinary .conf files:

vpns/
├── proton/
│   └── PDE-778-DE-778.conf
├── mullvad/
│   └── de-sto-wg-001.conf
├── windscribe/
│   └── Athens-Odeon-WG.conf
└── cloudflare/
    └── warp.conf

Standard Windscribe WireGuard profiles are supported, including dual-stack Address values, provider DNS, and PresharedKey. Legacy flat files named Windscribe-*.conf can also be selected with --provider windscribe.

Without --vpn, Conduit chooses a random profile and avoids the last-used one when another choice exists.

Platform notes

Linux network namespaces can isolate several simultaneous applications and profiles. Windows has no equivalent public desktop API, so the Windows backend allows one active Conduit tunnel and does not implement attach.

Discord's Windows executable lives in a changing app-<version> directory. Conduit resolves the newest executable at launch and filters the stable Discord installation root, so Discord updates do not invalidate the VPN rule.

Windows resolves hostnames before WireSock's per-application filter sees the result. Conduit compares Discord DNS answers with a trusted public resolver and fails early with a specific remediation message if the host or ISP resolver is rewriting them. This prevents a connected WireGuard tunnel from silently sending Discord to a block-page address. conduit doctor reports the same condition. The Windows installer configures Cloudflare system DNS on connected physical Internet adapters and enables native DNS over HTTPS when available. Original DNS settings are saved and can be restored with conduit dns restore from Administrator PowerShell. Use -SkipSystemDns with install.ps1, or set CONDUIT_SKIP_SYSTEM_DNS=1 before running the online installer, to keep existing system DNS. See Windows DNS configuration.

License

AGPLv3. Derivatives must remain open source under the same license and preserve the copyright notice. If a modified version is run as a network service, its source must be offered to users. See LICENSE.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages