156 lines
6.0 KiB
Markdown
156 lines
6.0 KiB
Markdown
<div align="center">
|
|
|
|
<img src="logo-horizontal.svg" alt="Konduit" height="52"/>
|
|
|
|
<br/><br/>
|
|
|
|
**TCP-Native VPN. Works Where UDP Doesn't.**
|
|
|
|
[](LICENSE)
|
|
[]()
|
|
[]()
|
|
|
|
</div>
|
|
|
|
---
|
|
|
|
Konduit is a modern VPN built around a single principle: **TCP transport that works when UDP is blocked.**
|
|
|
|
WireGuard is excellent — until your ISP throttles or blocks UDP. Konduit solves that without the complexity of OpenVPN or the fragility of UDP-wrapping hacks. It runs fully in userspace, requires no elevated privileges, and gets out of your way.
|
|
|
|
## Why Konduit?
|
|
|
|
Most VPNs treat TCP as a fallback. Konduit is designed for TCP from the ground up, which means:
|
|
|
|
- No HEAD-OF-LINE blocking from tunneling UDP into TCP
|
|
- Reliable behaviour on restrictive corporate and mobile networks
|
|
- WireGuard-level simplicity without the UDP dependency
|
|
|
|
## Features
|
|
|
|
- **TCP-native protocol** — designed for TCP, not retrofitted
|
|
- **Server-controlled routing** — administrators enforce routing policy; clients cannot bypass it
|
|
- **Userspace implementation** — no kernel modules, no root required
|
|
- **Hot config reload** — update server configuration without dropping connections
|
|
- **QR code provisioning** — scan once, connect instantly
|
|
- **Cross-platform** — Linux, Windows, Android (macOS and iOS coming soon)
|
|
- **Modern cryptography** — X25519 key exchange, ChaCha20-Poly1305 data channel
|
|
- **Stealth mode** — port 443 deployment with decoy proxy for hostile network environments
|
|
- **Memory safe** — written entirely in Rust
|
|
|
|
## Download
|
|
|
|
Releases are published on the [Releases](../../releases) page. Each release includes:
|
|
|
|
| Artifact | Platform | Purpose |
|
|
|---|---|---|
|
|
| `konduit-server-*-linux-x86_64` | Linux | VPN server |
|
|
| `konduit-*-linux-x86_64` | Linux | CLI client |
|
|
| `konduit-ctl-*-linux-x86_64` | Linux | Server provisioning tool |
|
|
| `Konduit-*-x86_64.AppImage` | Linux | GUI client (AppImage) |
|
|
| `konduit-cli-*-windows-x86_64.zip` | Windows | CLI client + wintun.dll |
|
|
| `konduit-gui-*-windows-x86_64.zip` | Windows | GUI client |
|
|
| `konduit-*-android.aab` | Android | Android app (sideload via bundletool) |
|
|
|
|
### Linux (CLI)
|
|
|
|
```bash
|
|
# Download konduit and konduit-ctl from the Releases page, then:
|
|
chmod +x konduit konduit-ctl
|
|
|
|
# Bootstrap a server
|
|
echo "your secret mantra" | ./konduit-ctl bootstrap -l vpn.example.com:443 -p -
|
|
|
|
# Connect a client
|
|
./konduit connect --config client.toml
|
|
```
|
|
|
|
### Linux (GUI)
|
|
|
|
Download the `.AppImage`, make it executable, and run it:
|
|
|
|
```bash
|
|
chmod +x Konduit-*-x86_64.AppImage
|
|
./Konduit-*-x86_64.AppImage
|
|
```
|
|
|
|
### Windows
|
|
|
|
Extract the zip and run `konduit.exe` (CLI) or `Konduit.exe` (GUI). `wintun.dll` must remain alongside the executable.
|
|
|
|
### Android
|
|
|
|
Download from [Google Play](https://play.google.com/store/apps/details?id=eu.kaparulin.konduit) or sideload the `.aab` using [bundletool](https://github.com/google/bundletool).
|
|
|
|
### macOS · iOS
|
|
|
|
Coming soon.
|
|
|
|
## Setup
|
|
|
|
**GUI clients**
|
|
- [Linux GUI Quickstart](docs/gui-quickstart-linux.md) — AppImage, privileges, autostart
|
|
- [Windows GUI Quickstart](docs/gui-quickstart-windows.md) — extract, UAC, WinTun, autostart
|
|
|
|
**CLI & server**
|
|
- [Client Quickstart](docs/client-quickstart.md) — download, configure, connect, run as a systemd service
|
|
- [Server Quickstart](docs/server-quickstart.md) — install, provision, NAT setup for iptables and firewalld
|
|
- [Stealth Mode Setup](docs/stealth-setup.md) — HAProxy TCP passthrough + camouflage configuration
|
|
- [systemd units](docs/systemd/) — service files for konduit-server, konduit (client), and konduit-admin-ui
|
|
|
|
## Architecture
|
|
|
|
```
|
|
Flutter UI (Dart)
|
|
│
|
|
flutter_rust_bridge (FFI)
|
|
│
|
|
Konduit engine (Rust)
|
|
├── TUN device (userspace)
|
|
├── TCP tunnel protocol
|
|
├── Key exchange (X25519)
|
|
└── Route manager
|
|
```
|
|
|
|
| Layer | Technology |
|
|
|---|---|
|
|
| UI | Flutter / Dart |
|
|
| Core engine | Rust (Tokio async) |
|
|
| FFI bridge | flutter_rust_bridge |
|
|
| Cryptography | ring / rustls |
|
|
| TUN device | tun crate (userspace) |
|
|
|
|
## Openness Model
|
|
|
|
The [`konduit-platform`](./konduit-platform) crate is published here for transparency and security audit. It contains the cryptographic primitives, connection statistics, and platform networking layer (TUN device, DNS, routes) — everything an auditor needs to verify what runs on your machine. It is licensed under the [PolyForm Noncommercial License 1.0.0](LICENSE) — free to read, study, and use for noncommercial purposes.
|
|
|
|
The VPN server, management UI, and stealth-mode protocol are proprietary. Keeping stealth mechanisms private makes automated DPI fingerprinting significantly harder. Source review under NDA is available for enterprise partners.
|
|
|
|
## Security
|
|
|
|
**No UDP dependency:** Konduit does not require UDP at any layer.
|
|
|
|
**Key storage:** Private keys are stored in the OS secure enclave on every platform (iOS Keychain, macOS Keychain, Android Keystore). They are never written to disk in plaintext.
|
|
|
|
**Stealth mode:** On port 443, failed or unrecognized handshakes are proxied transparently to a configurable decoy service. From the outside, the server is indistinguishable from a standard HTTPS endpoint.
|
|
|
|
## Support
|
|
|
|
**Bug reports:** Use the in-app reporting feature or open an issue in this repository.
|
|
|
|
**Security vulnerabilities:** Do not open a public issue. Contact the maintainer directly at the address shown in the application's About screen.
|
|
|
|
**Contributing:** Core development is handled internally. We do not currently accept external pull requests.
|
|
|
|
---
|
|
|
|
## About
|
|
|
|
Created by **Eugen Kaparulin**.
|
|
Official binaries distributed by **[K-Ops Oy](https://k-ops.eu)**.
|
|
|
|
© Eugen Kaparulin. All rights reserved.
|
|
[`konduit-platform`](./konduit-platform) is published under the [PolyForm Noncommercial License 1.0.0](LICENSE).
|
|
All other parts of Konduit are proprietary.
|
|
[Privacy Policy](docs/privacy-policy.md)
|