OpenSASE

Self-hosted SASE-style TLS inspection, declared end-to-end with Nix

License GitHub commit activity Libraries.io dependency status for GitHub repo pre-commit.ci status OpenSSF Scorecard OpenSSF Best Practices

flake-check release-images pages Dependency Review GitHub Release

OpenSASE is an open, self-hosted SASE-style edge, deployed from one source of truth: a Nix flake. Clients connect over OpenVPN; an mitmproxy addon decrypts and re-encrypts traffic per a URL-category policy; every payload is scanned by ClamAV; every verdict — splice, bump, clean, INFECTED — is written to a JSONL decision log.

It is growing two halves: the SASE edge for teams and servers, and a home appliance — install it like a Pi-hole and every family device routes through it, with per-device policy, traffic visibility, and verdicts. The stack stays modular: the bare-minimum decrypt edge stands alone; scanner, DNS-policy, agent-inspection, and chat modules layer on as opt-ins. The planned shapes live in Future directions; the working tracker is the Roadmap.

Two deployment paths:

Containers — no Nix required

Pre-built OCI images are published to GHCR by CI. Pull and docker compose up on Linux, macOS, or Windows, any OCI runtime.

NixOS appliance

The same stack as stock NixOS modules: build a QEMU VM, nixos-rebuild a physical machine, or deploy remotely with --target-host.

Kubernetes

Prebuilt manifests are not shipped yet (a kustomize follow-up is tracked). The four images are stateless OCI and stage on Kubernetes with the standard contract — NET_ADMIN on openvpn, RWO volumes per service, PKI injected before the VPN starts. See the README Kubernetes section for the staging table and constraints.

Why Nix end-to-end

  • No floating bases. Every image and appliance closure is a hash-pinned derivation from one nixpkgs revision — CI builds what you build, byte-identical.
  • Declare, don’t assemble. The appliance is services.clamav + services.dnsmasq + services.openvpn + services.opensase, not five hand-maintained Dockerfiles.
  • Portability for non-Nix users. Consumers pull the GHCR images dockerTools produced; no Nix anywhere in their path.

flowchart LR
    client["VPN client"] --> vpn["openvpn udp/5443"]
    vpn --> mitm["mitmproxy<br/>splice | bump per URL category"]
    mitm --> clam["clamd :3310"]
    mitm --> log[("decisions.jsonl")]
    mitm --> net((Internet))

Status

Piece State
NixOS flake (appliance + QEMU VMs) nix flake check --all-systems clean
OCI images via dockerTools built; release workflow in place
GHCR publish + SBOM wired on v* tags; first release pending
Quarto docs site this site
OpenSSF Scorecard workflow live; Best Practices project 15121 registered
Kubernetes images stage cleanly; kustomize overlays TODO
VM boot smoke test CI TODO
Live EICAR verification TODO

Read the architecture overview, or go to deployment. Project direction: Roadmap · Future directions. Operations help: Troubleshooting. Contributing, security policy, code of conduct: CONTRIBUTING · SECURITY · CoC.