Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
e84725f
setup proto crate
wojcik91 Jun 2, 2026
36276c0
migrate proto conversion module
wojcik91 Jun 2, 2026
9fdc334
use new proto crate
wojcik91 Jun 2, 2026
cf5cc20
scaffold core crate
wojcik91 Jun 2, 2026
2f18bd7
migrate shared code to core crate
wojcik91 Jun 2, 2026
f63e445
extract version constants and into_location into core crate
wojcik91 Jun 2, 2026
b7aea8c
move app_config and wg_config into core, decouple AppHandle from conf…
wojcik91 Jun 2, 2026
d3fb797
extract proxy HTTP client
wojcik91 Jun 2, 2026
ff984ce
extract daemon gRPC client
wojcik91 Jun 2, 2026
8f944c8
extract non-macOS connection setup into core
wojcik91 Jun 2, 2026
82ea64d
split macOS-only extension management into a dedicated module in core
wojcik91 Jun 2, 2026
0109aeb
setup unified connection interface
wojcik91 Jun 2, 2026
3f47bea
setup entirprise crates directory and migrate posture checks
wojcik91 Jun 2, 2026
abf6282
migrate provisioning module
wojcik91 Jun 2, 2026
b864dd9
migrate config sync module to a crate
wojcik91 Jun 2, 2026
07d4e8c
migrate service locations
wojcik91 Jun 2, 2026
1481fa3
scaffold service daemon crate
wojcik91 Jun 2, 2026
7b8ee78
migrate service binary
wojcik91 Jun 2, 2026
28e39fd
cleanup
wojcik91 Jun 2, 2026
59368a5
fix tauri build
wojcik91 Jun 2, 2026
bc99b93
cleanup
wojcik91 Jun 2, 2026
d7cae12
merge nix package update from main
wojcik91 Jun 2, 2026
894ae75
cleanup
wojcik91 Jun 2, 2026
8c8e570
expose other binaries as nix packages
wojcik91 Jun 2, 2026
5552408
make config polling independent from tauri
wojcik91 Jun 3, 2026
a078f81
consolidate crate names and workspace dependencies
wojcik91 Jun 3, 2026
d3a2bea
clean up windows dependencies
wojcik91 Jun 5, 2026
5edf0b2
windows, oh windows
wojcik91 Jun 5, 2026
7342b07
for the love of Bill Gates
wojcik91 Jun 5, 2026
0f6c635
fix import
wojcik91 Jun 5, 2026
888c239
update Windows query cache
Jun 5, 2026
1a3a4a3
macos fixes
wojcik91 Jun 5, 2026
bf8361f
Build on macOS
moubctez Jun 7, 2026
0cb21db
bump react-router to resolve CVE
wojcik91 Jun 8, 2026
e23722a
remove stale advisories
wojcik91 Jun 8, 2026
a707004
update crate names
wojcik91 Jun 8, 2026
f612206
fix license name for enterprise crates
wojcik91 Jun 8, 2026
fb1fe90
remove redundant fields
wojcik91 Jun 8, 2026
8d51115
shorten imports
wojcik91 Jun 8, 2026
91241d6
pre-review cleanup
wojcik91 Jun 8, 2026
42b5504
add common helpers tests
wojcik91 Jun 8, 2026
b934977
update flaky Linux text
wojcik91 Jun 8, 2026
cf5d0e6
add more conversions tests
wojcik91 Jun 8, 2026
ec9442a
add more core logic tests
wojcik91 Jun 8, 2026
c206d54
add basic round-trip tests for core models
wojcik91 Jun 8, 2026
c134316
add unit tests for provisioning config loading and config-sync versio…
wojcik91 Jun 8, 2026
f015058
move select_reported_app_version into core crate with its tests
wojcik91 Jun 8, 2026
91c29f1
reuse workspace license file
wojcik91 Jun 9, 2026
29537c7
update query cache
wojcik91 Jun 9, 2026
148553b
update hash
wojcik91 Jun 9, 2026
106a57f
update windows query cache
Jun 9, 2026
f2332e1
Fix build on macOS
moubctez Jun 9, 2026
a6c59ab
reuse workspace license file
wojcik91 Jun 9, 2026
02bfc94
Fix build on macOS
moubctez Jun 9, 2026
1f0890a
Merge branch 'crate_refactor' of github.com:DefGuard/client into crat…
moubctez Jun 9, 2026
b702276
cleanup
moubctez Jun 9, 2026
729120a
cleanup2
moubctez Jun 9, 2026
76b7dba
fix macos disconnect
wojcik91 Jun 9, 2026
01e798c
fix message formatting
wojcik91 Jun 9, 2026
b42ea59
more cleanup
wojcik91 Jun 9, 2026
b04fdee
one step closer...
moubctez Jun 9, 2026
61a5b63
Fix build on macOS
moubctez Jun 9, 2026
261b683
test a cross-platform check
wojcik91 Jun 9, 2026
c644b3e
temporarily disable sccache
wojcik91 Jun 9, 2026
924d9d0
restore sccache
wojcik91 Jun 9, 2026
e5a63dc
bump sccache action version
wojcik91 Jun 9, 2026
1bf3bde
try skipping failing install
wojcik91 Jun 9, 2026
4c6f43b
another workaround
wojcik91 Jun 9, 2026
c2603bb
Revert "another workaround"
wojcik91 Jun 9, 2026
c9b69cf
setup cargo
wojcik91 Jun 10, 2026
1c821ec
remove duplicate helper
wojcik91 Jun 10, 2026
64ce09a
fix formatting
wojcik91 Jun 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 63 additions & 0 deletions .github/workflows/cross-platform-check.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
name: Cross-platform check

on:
push:
branches:
- main
- dev
- "release/**"
paths-ignore:
- "*.md"
- "LICENSE"
pull_request:
branches:
- main
- dev
- "release/**"
paths-ignore:
- "*.md"
- "LICENSE"

env:
CARGO_TERM_COLOR: always
SQLX_OFFLINE: "1"
SCCACHE_GHA_ENABLED: "true"
RUSTC_WRAPPER: "sccache"

jobs:
check:
strategy:
fail-fast: false
matrix:
os:
- macOS
- Windows

runs-on:
- self-hosted
- ${{ matrix.os }}

defaults:
run:
working-directory: ./src-tauri

steps:
- name: Checkout
uses: actions/checkout@v6
with:
submodules: recursive

- name: Install Rust
uses: dtolnay/rust-toolchain@stable

- name: Run sccache-cache
uses: mozilla-actions/sccache-action@v0.0.10

- name: Install protoc
if: matrix.os != 'Windows'
uses: arduino/setup-protoc@v3
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}

- name: Check compilation
run: cargo check --workspace
2 changes: 1 addition & 1 deletion .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ jobs:
scanners: "vuln"

- name: Run sccache-cache
uses: mozilla-actions/sccache-action@v0.0.9
uses: mozilla-actions/sccache-action@v0.0.10

- name: Install required packages
run: |
Expand Down
4 changes: 2 additions & 2 deletions LICENSE.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
# Dual license info
The code in this repository is available under a dual licensing model:

1. Open Source License: The code, except for the contents of the "src-tauri/src/enterprise/" directory, is licensed under the AGPL license (this license). This applies to the open core components of the software.
2. Enterprise License: All code in this repository (including within the "src-tauri/src/enterprise/" directory) is licensed under a separate Enterprise License (see file src/enterprise/LICENSE.md).
1. Open Source License: The code, except for the contents of the "src-tauri/enterprise/" directory, is licensed under the AGPL license (this license). This applies to the open core components of the software.
2. Enterprise License: All code in this repository (including within the "src-tauri/enterprise/" directory) is licensed under a separate Enterprise License (see file src-tauri/enterprise/LICENSE.md).

# GNU AFFERO GENERAL PUBLIC LICENSE

Expand Down
28 changes: 22 additions & 6 deletions flake.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

42 changes: 36 additions & 6 deletions flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
nixpkgs.url = "nixpkgs";
flake-utils.url = "github:numtide/flake-utils";
rust-overlay.url = "github:oxalica/rust-overlay";
crane.url = "github:ipetkov/crane";

# let git manage submodules
self.submodules = true;
Expand All @@ -25,26 +26,55 @@
nixpkgs,
flake-utils,
rust-overlay,
crane,
...
}:
flake-utils.lib.eachDefaultSystem (system: let
# add rust overlay
pkgs = import nixpkgs {
# Plain nixpkgs — used for packages and checks.
pkgs = import nixpkgs {inherit system;};

# nixpkgs with rust-overlay — only needed for the dev shell, which uses
# pkgs.rust-bin to get a customised Rust toolchain.
devPkgs = import nixpkgs {
inherit system;
overlays = [rust-overlay.overlays.default];
};

craneLib = crane.mkLib pkgs;

defguard-client = pkgs.callPackage ./nix/package.nix {
inherit pkgs craneLib;
};
in {
devShells.default = import ./nix/shell.nix {
inherit pkgs;
pkgs = devPkgs;
inherit crane;
};

packages.default = pkgs.callPackage ./nix/package.nix {
inherit pkgs;
packages = {
default = defguard-client;
inherit defguard-client;
defguard-service =
pkgs.runCommand "defguard-service" {
nativeBuildInputs = [pkgs.makeWrapper];
} ''
mkdir -p $out/bin
cp ${defguard-client}/bin/defguard-service $out/bin/
'';
dg =
pkgs.runCommand "dg" {
nativeBuildInputs = [pkgs.makeWrapper];
} ''
mkdir -p $out/bin
cp ${defguard-client}/bin/dg $out/bin/
'';
};

checks.default = defguard-client;

formatter = pkgs.alejandra;
})
// {
nixosModules.default = import ./nix/nixos-module.nix;
nixosModules.default = import ./nix/nixos-module.nix {mkCraneLib = crane.mkLib;};
};
}
46 changes: 27 additions & 19 deletions nix/nixos-module.nix
Original file line number Diff line number Diff line change
@@ -1,61 +1,69 @@
{
{mkCraneLib}: {
config,
lib,
pkgs,
...
}:
with lib; let
defguard-client = pkgs.callPackage ./package.nix {};
}: let
craneLib = mkCraneLib pkgs;
defguard-client = pkgs.callPackage ./package.nix {inherit pkgs craneLib;};
cfg = config.programs.defguard-client;
in {
options.programs.defguard-client = {
enable = mkEnableOption "Defguard VPN client and service";
enable = lib.mkEnableOption "Defguard VPN client and service";

package = mkOption {
type = types.package;
package = lib.mkOption {
type = lib.types.package;
default = defguard-client;
description = "defguard-client package to use";
};

logLevel = mkOption {
type = types.str;
logLevel = lib.mkOption {
type = lib.types.str;
default = "info";
description = "Log level for defguard-service";
};

statsPeriod = mkOption {
type = types.int;
statsPeriod = lib.mkOption {
type = lib.types.int;
default = 30;
description = "Interval in seconds for interface statistics updates";
};
};

config = mkIf cfg.enable {
# Add client package
config = lib.mkIf cfg.enable {
environment.systemPackages = [cfg.package];

# Setup systemd service for the intrerface management daemon
systemd.services.defguard-service = {
description = "Defguard VPN Service";
documentation = ["https://docs.defguard.net"];
wantedBy = ["multi-user.target"];
wants = ["network-online.target"];
after = ["network-online.target"];
serviceConfig = {
ExecStart = "${cfg.package}/bin/defguard-service --log-level ${cfg.logLevel} --stats-period ${toString cfg.statsPeriod}";
ExecReload = "/bin/kill -HUP $MAINPID";
Group = "defguard";
Restart = "on-failure";
RestartSec = 2;
ExecStart = "${cfg.package}/bin/defguard-service --log-level ${cfg.logLevel} --stats-period ${toString cfg.statsPeriod}";
ExecReload = "kill -HUP $MAINPID";
KillMode = "process";
KillSignal = "SIGINT";
LimitNOFILE = 65536;
LimitNPROC = "infinity";
Restart = "on-failure";
RestartSec = 2;
TasksMax = "infinity";
OOMScoreAdjust = -1000;
# Security hardening
NoNewPrivileges = true;
PrivateTmp = true;
ProtectControlGroups = true;
# Requires WireGuard to be built into the kernel or pre-loaded via
# boot.kernelModules. If WireGuard is a loadable module, auto-loading
# will be blocked by ProtectKernelModules.
ProtectKernelModules = true;
RestrictRealtime = true;
LockPersonality = true;
};
};

# Make sure the defguard group exists
users.groups.defguard = {};
};
}
Loading
Loading