flowchart LR
client["VPN client"] --> vpn["openvpn udp/5443"]
vpn --> mitm["mitmproxy<br/>splice | bump per URL category"]
mitm --> clam["clamd :3310"]
mitm --> log[("decisions.jsonl")]
mitm --> net((Internet))
OpenSASE
Self-hosted SASE-style TLS inspection, declared end-to-end with Nix
OpenSASE is an open, self-hosted SASE-style edge, deployed from one source of truth: a Nix flake. Clients connect over OpenVPN; an mitmproxy addon decrypts and re-encrypts traffic per a URL-category policy; every payload is scanned by ClamAV; every verdict — splice, bump, clean, INFECTED — is written to a JSONL decision log.
It is growing two halves: the SASE edge for teams and servers, and a home appliance — install it like a Pi-hole and every family device routes through it, with per-device policy, traffic visibility, and verdicts. The stack stays modular: the bare-minimum decrypt edge stands alone; scanner, DNS-policy, agent-inspection, and chat modules layer on as opt-ins. The planned shapes live in Future directions; the working tracker is the Roadmap.
Two deployment paths:
Containers — no Nix required
Pre-built OCI images are published to GHCR by CI. Pull and docker compose up on Linux, macOS, or Windows, any OCI runtime.
NixOS appliance
The same stack as stock NixOS modules: build a QEMU VM, nixos-rebuild a physical machine, or deploy remotely with --target-host.
Kubernetes
Prebuilt manifests are not shipped yet (a kustomize follow-up is tracked). The four images are stateless OCI and stage on Kubernetes with the standard contract — NET_ADMIN on openvpn, RWO volumes per service, PKI injected before the VPN starts. See the README Kubernetes section for the staging table and constraints.
Why Nix end-to-end
- No floating bases. Every image and appliance closure is a hash-pinned derivation from one nixpkgs revision — CI builds what you build, byte-identical.
- Declare, don’t assemble. The appliance is
services.clamav+services.dnsmasq+services.openvpn+services.opensase, not five hand-maintained Dockerfiles. - Portability for non-Nix users. Consumers pull the GHCR images
dockerToolsproduced; no Nix anywhere in their path.
Status
| Piece | State |
|---|---|
| NixOS flake (appliance + QEMU VMs) | nix flake check --all-systems clean |
OCI images via dockerTools |
built; release workflow in place |
| GHCR publish + SBOM | wired on v* tags; first release pending |
| Quarto docs site | this site |
| OpenSSF Scorecard | workflow live; Best Practices project 15121 registered |
| Kubernetes | images stage cleanly; kustomize overlays TODO |
| VM boot smoke test | CI TODO |
| Live EICAR verification | TODO |
Read the architecture overview, or go to deployment. Project direction: Roadmap · Future directions. Operations help: Troubleshooting. Contributing, security policy, code of conduct: CONTRIBUTING · SECURITY · CoC.




