diff --git a/README.md b/README.md new file mode 100644 index 0000000..15c5327 --- /dev/null +++ b/README.md @@ -0,0 +1,87 @@ +
+ koridor + + # koridor + + **VPN over your own SSH server.** + + [![License: Proprietary](https://img.shields.io/badge/license-Proprietary-red)](#about) + [![Platform](https://img.shields.io/badge/platform-Linux%20%7C%20Windows%20%7C%20Android-lightgrey)]() + [![Status](https://img.shields.io/badge/status-Beta-orange)]() + +
+ +--- + +koridor is a full-device VPN client built around a single idea: **you already have a server you trust — just tunnel through it.** + +Instead of operating its own VPN infrastructure, koridor routes your device's traffic through a plain SSH server you configure yourself. There's no koridor-operated backend, no account, and no third party in the middle. + +## Why koridor? + +Most VPN apps ask you to trust the app vendor's servers. koridor doesn't have any — it connects to a server you already own or personally trust, using nothing more exotic than standard SSH port forwarding on the wire. If you can run `sshd`, you can run a koridor server. + +## Features + +- **Full-device tunnel** — a TUN-based VPN, not just an app-aware SOCKS proxy. Every app on the device is covered, with no per-app setup. +- **Bring your own server** — connects to any SSH server with `AllowTcpForwarding yes`. No special server-side software required. +- **Zero-friction onboarding** — scan a QR code exported from your server, toggle on, done. +- **Fail-closed reconnects** — transient drops are retried with exponential backoff; if the tunnel can't recover, the route is torn down rather than silently leaking traffic in the open. +- **Tunnel-only DNS** — lookups are resolved through the server's own resolver over the tunnel, never leaked to a third-party DNS provider. +- **No telemetry** — no analytics, crash reporting, or usage tracking of any kind. +- **Cross-platform** — Linux, Windows, Android (macOS and iOS planned). + +## Download + +### Android + + + Get it on Google Play + + +### Linux · Windows + +Releases are published on the [Releases](../../releases) page. + +### macOS · iOS + +Coming soon. + +## Architecture + +``` +Flutter UI (Dart) + │ +FFI (cdylib) + │ +koridor engine (Rust) + ├── TUN device + ├── smoltcp netstack (packets → TCP flows) + ├── russh SSH client (direct-tcpip per flow) + └── Route manager +``` + +Each TCP flow captured off the TUN device is proxied over its own SSH `direct-tcpip` channel — the same kind of traffic an ordinary SSH port-forward produces, indistinguishable on the wire from routine SSH use. + +## Security + +- Your SSH private key and passphrase are stored only in the OS secure credential store (Android Keystore / platform-equivalent) and are only ever sent to the server you configure, as part of establishing the tunnel. +- All traffic between client and server is carried inside the SSH transport. + +See the [Privacy Policy](privacy-policy.md) for full details on what koridor does and does not process. + +## Support & Contributing + +**Bug reports and vulnerabilities:** contact the maintainer directly via the address shown in the app's About screen. + +**Contributing:** core development is handled internally. We do not currently accept external pull requests. + +--- + +## About + +Created by **Eugen Kaparulin**. +Official binaries distributed by **[K-Ops Oy](https://k-ops.eu)**. + +© Eugen Kaparulin. All rights reserved. +[Privacy Policy](privacy-policy.md)