{"id":50815516,"url":"https://github.com/ilia-ae/wg-yubikey-manager","last_synced_at":"2026-06-13T09:04:50.071Z","repository":{"id":345998196,"uuid":"1187036828","full_name":"ilia-ae/wg-yubikey-manager","owner":"ilia-ae","description":"🚓🔓 macOS app for managing WireGuard VPN configurations with YubiKey authentication","archived":false,"fork":false,"pushed_at":"2026-05-18T06:13:54.000Z","size":196,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-05-18T07:54:34.024Z","etag":null,"topics":["2026","blog","hardware-token","macos","swift","vpn","wireguard","yubikey"],"latest_commit_sha":null,"homepage":"https://ilia.ae/en/blog/infosec/wireguard-yubikey-manager-hardware-backed-vpn-security/","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ilia-ae.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-03-20T09:13:34.000Z","updated_at":"2026-05-18T06:13:57.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/ilia-ae/wg-yubikey-manager","commit_stats":null,"previous_names":["razqqm/wg-yubikey-manager","ilia-ae/wg-yubikey-manager"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ilia-ae/wg-yubikey-manager","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilia-ae%2Fwg-yubikey-manager","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilia-ae%2Fwg-yubikey-manager/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilia-ae%2Fwg-yubikey-manager/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilia-ae%2Fwg-yubikey-manager/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ilia-ae","download_url":"https://codeload.github.com/ilia-ae/wg-yubikey-manager/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ilia-ae%2Fwg-yubikey-manager/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":34278190,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-26T15:22:16.424Z","status":"online","status_checked_at":"2026-06-13T02:00:06.617Z","response_time":62,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["2026","blog","hardware-token","macos","swift","vpn","wireguard","yubikey"],"created_at":"2026-06-13T09:04:49.361Z","updated_at":"2026-06-13T09:04:50.066Z","avatar_url":"https://github.com/ilia-ae.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n# 🔐 WG YubiKey Manager\n\n**Secure WireGuard VPN management with hardware-backed key storage on YubiKey**\n\n[![Go](https://img.shields.io/badge/Go-1.25-00ADD8?style=flat-square\u0026logo=go\u0026logoColor=white)](https://go.dev/)\n[![Wails](https://img.shields.io/badge/Wails-v3_alpha-DF0000?style=flat-square\u0026logo=wails\u0026logoColor=white)](https://v3alpha.wails.io/)\n[![Svelte](https://img.shields.io/badge/Svelte-4.2-FF3E00?style=flat-square\u0026logo=svelte\u0026logoColor=white)](https://svelte.dev/)\n[![Vite](https://img.shields.io/badge/Vite-5.4-646CFF?style=flat-square\u0026logo=vite\u0026logoColor=white)](https://vitejs.dev/)\n[![Platform](https://img.shields.io/badge/platform-macOS%2012%2B-000000?style=flat-square\u0026logo=apple\u0026logoColor=white)](https://www.apple.com/macos/)\n[![YubiKey](https://img.shields.io/badge/YubiKey-5%20Series-84BD00?style=flat-square\u0026logo=yubico\u0026logoColor=white)](https://www.yubico.com/)\n[![License](https://img.shields.io/badge/license-MIT-blue?style=flat-square)](LICENSE)\n\n[**English**](README.md) | [**Русский**](README_RU.md)\n\n\u003cbr\u003e\n\n\u003cimg src=\"resources/appicon.png\" alt=\"WG YubiKey Manager\" width=\"128\"\u003e\n\n*A macOS native desktop application that combines WireGuard VPN tunnel management with YubiKey hardware security — your private keys never touch the disk.*\n\n\u003c/div\u003e\n\n---\n\n## ✨ Features\n\n### 🔑 Hardware Key Security\n- **YubiKey PIV Storage** — WireGuard private keys are encrypted and stored on YubiKey PIV slots (`5f0001`–`5f00ff`)\n- **PIN-Protected Decryption** — keys are decrypted in-memory only at connection time using GPG + AES-256\n- **Zero Disk Exposure** — private keys are never written to disk, only held in RAM during active sessions\n- **Slot Registry** — automatic metadata management in YubiKey slot `5fc10f`\n\n### 🌐 VPN Tunnel Management\n- **One-Click Connect/Disconnect** — seamless WireGuard tunnel lifecycle management\n- **Live Connection Stats** — real-time handshake, transfer (RX/TX), latency, peer info, uptime\n- **Multi-Tunnel Support** — manage multiple WireGuard configurations from a single interface\n- **Config Import** — paste or upload `.conf` files with automatic validation\n- **Auto-Discovery** — scan YubiKey for stored configurations and sync to local state\n\n### 🖥️ Native macOS Experience\n- **Translucent Window** — native glassmorphism UI with dark/light theme support\n- **Menu Bar Tray** — persistent status indicator (● connected / ◯ disconnected)\n- **Privilege Escalation** — one-time sudoers setup via `osascript`, passwordless afterwards\n- **macOS App Bundle** — distributable `.app` with proper `Info.plist` and icon\n\n---\n\n## 🏗️ Architecture\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│                    WG YubiKey Manager                       │\n├──────────────────────┬──────────────────────────────────────┤\n│    Frontend (Svelte) │         Backend (Go)                 │\n│                      │                                      │\n│  ┌────────────────┐  │  ┌──────────────────────────────┐   │\n│  │   App.svelte   │──┼──│  internal/app/app.go          │   │\n│  │   StatusBar    │  │  │    ├── Connect / Disconnect   │   │\n│  │   TunnelList   │  │  │    ├── Import / Delete        │   │\n│  │   TunnelCard   │  │  │    └── GetStatus / emitStatus │   │\n│  │   PinDialog    │  │  ├──────────────────────────────┤   │\n│  │   ImportDialog │  │  │  internal/yubikey/            │   │\n│  │   TokenInfo    │  │  │    ├── PIV slot read/write    │   │\n│  └────────────────┘  │  │    ├── GPG encrypt/decrypt    │   │\n│                      │  │    └── Registry management    │   │\n│  Wails Runtime       │  ├──────────────────────────────┤   │\n│  (JS bindings)       │  │  internal/wireguard/          │   │\n│                      │  │    ├── Config parsing (INI)   │   │\n│                      │  │    └── Validation             │   │\n│                      │  ├──────────────────────────────┤   │\n│                      │  │  internal/tunnel/             │   │\n│                      │  │    └── Active tunnel state    │   │\n│                      │  ├──────────────────────────────┤   │\n│                      │  │  internal/privilege/          │   │\n│                      │  │    └── sudo + sudoers setup   │   │\n│                      │  ├──────────────────────────────┤   │\n│                      │  │  internal/tray/               │   │\n│                      │  │    └── macOS NSStatusItem     │   │\n│                      │  └──────────────────────────────┘   │\n├──────────────────────┴──────────────────────────────────────┤\n│           macOS (wireguard-go, wg, ykman, gpg)              │\n└─────────────────────────────────────────────────────────────┘\n```\n\n---\n\n## 📋 Prerequisites\n\n| Dependency | Version | Installation |\n|---|---|---|\n| **macOS** | 12.0+ (Monterey) | — |\n| **Go** | 1.25+ | [go.dev/dl](https://go.dev/dl/) |\n| **Node.js** | 18+ | `brew install node` |\n| **YubiKey** | 5 Series (PIV) | [yubico.com](https://www.yubico.com/) |\n| **ykman** | latest | `brew install ykman` |\n| **GnuPG** | 2.x | `brew install gnupg` |\n| **WireGuard** | latest | `brew install wireguard-go wireguard-tools` |\n| **Wails CLI** | v3 alpha | `go install github.com/wailsapp/wails/v3/cmd/wails3@latest` |\n\n### Quick Install (Homebrew)\n\n```bash\nbrew install go node ykman gnupg wireguard-go wireguard-tools\ngo install github.com/wailsapp/wails/v3/cmd/wails3@latest\n```\n\n---\n\n## 🚀 Getting Started\n\n### Clone\n\n```bash\ngit clone https://github.com/razqqm/wg-yubikey-manager.git\ncd wg-yubikey-manager\n```\n\n### Development Mode\n\n```bash\nwails dev\n```\n\nThis starts the app with hot-reload for both frontend and backend.\n\n### Build\n\n```bash\nmake build\n```\n\nProduces a binary at `build/wg-yubikey-manager`.\n\n### Build macOS App Bundle\n\n```bash\n./build-app.sh\n```\n\nCreates `build/WG YubiKey Manager.app` — drag to `/Applications/` to install.\n\n### Install\n\n```bash\ncp -r \"build/WG YubiKey Manager.app\" /Applications/\n```\n\n---\n\n## 📖 Usage\n\n### First Launch\n\n1. **Insert your YubiKey** into a USB port\n2. **Launch the app** — it will prompt once for admin password to install a sudoers rule\n3. The menu bar shows ◯ (disconnected)\n\n### Import a WireGuard Config\n\n1. Click **Import** in the app\n2. Paste your `.conf` file content or select a file\n3. Enter a name for the tunnel\n4. Enter your **YubiKey PIN** — the config is encrypted and stored on the YubiKey\n5. The config is validated automatically before import\n\n### Connect to a Tunnel\n\n1. Click **Connect** on a tunnel card\n2. Enter your **YubiKey PIN**\n3. The app decrypts the key from YubiKey → sets up `wireguard-go` → configures routes and DNS\n4. Menu bar changes to ● (connected) with tunnel name\n5. Live stats appear: handshake time, transfer, latency, peer info\n\n### Disconnect\n\nClick **Disconnect** — the tunnel is torn down, routes removed, DNS resolver cleaned up.\n\n### Sync from YubiKey\n\nClick **Sync** — the app scans all PIV slots, discovers stored configs, rebuilds the registry, and syncs to local state. Useful when moving to a new machine.\n\n---\n\n## 📁 Project Structure\n\n```\nwg-yubikey-manager/\n├── cmd/\n│   └── wg-yubikey-manager/\n│       └── main.go                 # Wails app initialization (480×640 window)\n├── internal/\n│   ├── app/\n│   │   └── app.go                  # Core logic: Connect, Disconnect, Import, Stats\n│   ├── config/\n│   │   └── manager.go              # JSON config persistence (~/.config/wg-yubikey-manager/)\n│   ├── privilege/\n│   │   └── escalation.go           # Sudoers install + passwordless sudo execution\n│   ├── tray/\n│   │   ├── tray.go                 # Wails v3 SystemTray (pure Go)\n│   │   └── dialogs.go              # PIN dialog + error alerts (osascript)\n│   ├── tunnel/\n│   │   └── manager.go              # Thread-safe active tunnel state (mutex-protected)\n│   ├── wireguard/\n│   │   └── wireguard.go            # WireGuard INI parser + validator\n│   └── yubikey/\n│       └── manager.go              # YubiKey PIV operations (ykman + gpg)\n├── pkg/\n│   └── models/\n│       ├── tunnel.go               # TunnelDefinition, TunnelInfo, AppStatus\n│       ├── wireguard.go            # WireGuardConfig, Interface, Peer\n│       └── yubikey.go              # YubiKeyInfo, KeySlot, TokenInfo\n├── frontend/\n│   ├── embed.go                    # Go embed for production assets\n│   ├── index.html                  # HTML entry point\n│   ├── package.json                # Svelte + Vite dependencies\n│   ├── vite.config.js              # Vite + Svelte plugin\n│   └── src/\n│       ├── main.js                 # Svelte mount point\n│       ├── App.svelte              # Root component, state orchestration\n│       ├── style.css               # Design system (dark/light, glassmorphism)\n│       └── components/\n│           ├── StatusBar.svelte    # YubiKey + tunnel status indicators\n│           ├── TokenInfo.svelte    # Slot usage, Sync/Import buttons\n│           ├── TunnelList.svelte   # Tunnel list with Add form\n│           ├── TunnelCard.svelte   # Tunnel card with live stats\n│           ├── PinDialog.svelte    # PIN entry modal (Enter/Esc)\n│           └── ImportDialog.svelte # Config import (paste/upload + validation)\n├── resources/                      # App icon (appicon.icns)\n├── build/                          # Build output\n├── go.mod                          # Go module (github.com/razqqm/wg-yubikey-manager)\n├── wails.json                      # Wails framework configuration\n├── Makefile                        # Build automation\n└── build-app.sh                    # macOS .app bundle creator\n```\n\n---\n\n## 🔒 Security Model\n\n### Key Storage\n\n```\n┌────────────┐      GPG AES-256      ┌──────────────┐\n│  WireGuard │ ──── encrypt(PIN) ──► │  YubiKey PIV  │\n│  .conf     │                       │  slot 5fXXXX  │\n└────────────┘                       └──────────────┘\n       ▲                                    │\n       │            at connect time         │\n       └────── decrypt(PIN, in-memory) ─────┘\n```\n\n- **At Import**: Config is encrypted with GPG (AES-256, PIN as passphrase) and written to a YubiKey PIV data slot\n- **At Connect**: Config is decrypted from YubiKey in-memory, parsed in Go, private key passed via stdin to `wg set`\n- **Never on Disk**: Private keys exist only in RAM during the active session\n\n### Privilege Escalation\n\n1. On first launch, `EnsureSudoers()` installs `/etc/sudoers.d/wg-yubikey` via `osascript` (macOS auth dialog)\n2. All subsequent privileged operations (`wireguard-go`, `wg`, `route`, DNS resolver) use `sudo -n` (no password)\n3. YubiKey operations (`ykman`, `gpg`) run as the current user — no sudo needed\n\n### Threat Model Considerations\n\n| Threat | Mitigation |\n|---|---|\n| Key theft from disk | Keys never written to disk |\n| Key extraction from memory | Keys cleared after tunnel setup |\n| Unauthorized tunnel activation | YubiKey PIN required for every connection |\n| Physical YubiKey theft | PIN protection (lockout after retries) |\n| Privilege escalation abuse | Sudoers rule scoped to specific commands |\n\n---\n\n## ⚙️ Configuration\n\n### Application Config\n\nStored in `~/.config/wg-yubikey-manager/`:\n\n| File | Purpose |\n|---|---|\n| `tunnels.json` | Tunnel definitions (name ↔ YubiKey slot tag mapping) |\n\n### YubiKey Layout\n\n| Slot | Purpose |\n|---|---|\n| `5fc10f` | Registry — JSON array of `{name, tag}` pairs |\n| `5f0001` – `5f00ff` | Encrypted WireGuard configs (up to 255 tunnels) |\n\n### DNS Resolution\n\nPer-tunnel DNS resolvers are created at `/etc/resolver/{tunnelName}` during connection and removed on disconnect.\n\n---\n\n## 🛠️ Development\n\n### Makefile Targets\n\n| Target | Description |\n|---|---|\n| `make frontend` | Build frontend only (npm install + npm run build) |\n| `make build` | Full build (frontend + Go binary) |\n| `make run` | Build and run |\n| `make clean` | Remove build artifacts, node_modules, dist |\n| `make test` | Run Go tests |\n| `make lint` | Run golangci-lint |\n\n### Tech Stack\n\n| Layer | Technology |\n|---|---|\n| Backend | Go 1.25 |\n| Frontend | Svelte 4, Vite 5 |\n| Bridge | Wails v3 (WebView + Go service bindings) |\n| Native UI | Cocoa via CGO (NSStatusItem) |\n| Crypto | GnuPG (AES-256 symmetric) |\n| Hardware | YubiKey PIV via `ykman` CLI |\n| VPN | `wireguard-go` + `wg` CLI |\n\n### Frontend API\n\nThe frontend communicates with the Go backend through Wails-generated bindings:\n\n```javascript\n// Connection\nawait window.go.app.App.Connect(tunnelName, pin)\nawait window.go.app.App.Disconnect()\n\n// Status\nconst status = await window.go.app.App.GetStatus()\n\n// Tunnel management\nawait window.go.app.App.AddTunnel(name, tag)\nawait window.go.app.App.RemoveTunnel(name)\n\n// YubiKey operations\nconst tokenInfo = await window.go.app.App.LoadFromToken(pin)\nawait window.go.app.App.ImportConfig(pin, name, configText)\nawait window.go.app.App.DeleteFromToken(pin, name)\nconst slot = await window.go.app.App.GetNextFreeSlot(pin)\n\n// Real-time events\nwindow.runtime.EventsOn('status:update', (status) =\u003e { ... })\n```\n\n---\n\n## 🤝 Contributing\n\nContributions are welcome! Please see [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.\n\n---\n\n## 📜 License\n\nThis project is licensed under the MIT License — see the [LICENSE](LICENSE) file for details.\n\n---\n\n## 🙏 Acknowledgments\n\n- [Wails](https://wails.io/) — Go + Web frontend framework\n- [Svelte](https://svelte.dev/) — reactive UI compiler\n- [WireGuard](https://www.wireguard.com/) — modern VPN protocol\n- [Yubico](https://www.yubico.com/) — hardware security keys\n- [GnuPG](https://gnupg.org/) — encryption toolkit\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n**Built with ❤️ for security-conscious VPN users**\n\n*Your keys, your hardware, your control.*\n\n\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Filia-ae%2Fwg-yubikey-manager","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Filia-ae%2Fwg-yubikey-manager","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Filia-ae%2Fwg-yubikey-manager/lists"}