iclaoudezinandClaude Sonnet 5.5 6f9e800779 Run API services unprivileged; add root helper for OpenVPN config and service control
- Profiler: when not root, render server.conf to the staging dir and let
  the root helper validate (directive allowlist) and install it; control
  the openvpn service through the helper (doas, fixed commands).
- Add ovpmon-helper and doas rules under DOCS/General/privilege-separation.
- Document the design, rollout, results and limitations.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:33:15 +00:00
2026-01-09 01:05:50 +03:00

OpenVPN Monitor & Profiler

Web suite for OpenVPN servers: real-time traffic monitoring, history/analytics, PKI and client-profile management, one UI.

Component Dir Stack Default port
UI APP_UI/ Vue 3 + Vite, served by Nginx 80 (Docker) / 8088 (native, TLS)
Monitoring API APP_CORE/ Flask (gunicorn) 5001 (internal)
Data gatherer APP_CORE/ Python daemon -
Profiler API APP_PROFILER/ FastAPI (uvicorn) 8000 (internal)

Nginx is the only public entry point: / UI, /api/ Monitoring API, /profiles-api/ Profiler API.

Quick start

After the first start: sign in, open PKI Configuration → Initialize PKI, generate the server config, start OpenVPN, create profiles.

First login and credentials

No default user is created. Seed the initial admin with OVPMON_INITIAL_ADMIN_USER / OVPMON_INITIAL_ADMIN_PASSWORD on first start (empty users table only), then remove them. Change the username and password and enable 2FA in Account.

Configuration

config.ini per component; overridden by OVPMON_{SECTION}_{KEY} environment variables.

Variable Purpose
OVPMON_API_SECRET_KEY JWT secret shared by both APIs (must be random)
OVPMON_INITIAL_ADMIN_USER / _PASSWORD One-time admin seed
OVPMON_CORS_ORIGINS Extra allowed CORS origins, comma-separated (empty = same-origin only)
OVPMON_OPENVPN_MONITOR_DB_PATH Monitoring DB
OVPMON_PROFILER_DB_PATH Profiler DB
OVPMON_OPENVPN_MONITOR_LOG_PATH openvpn-status.log path
OVPMON_LOGGING_LEVEL INFO / DEBUG

Documentation

Changes and results

Date Change Document
2026-09-30 Security hardening: path traversal, 2FA token bypass, CORS, log leak, HTTPS, SSH, fail2ban Security hardening
2026-09-30 Admin username change (API + UI), no built-in default admin Admin username change
2026-09-30 Validation of server/PKI settings (config injection into the root-written OpenVPN config) Settings validation
2026-09-30 API services run as an unprivileged user; root helper validates and installs the OpenVPN config Privilege separation
2026-09-30 Route OpenVPN clients through a Hysteria2 tunnel to an exit node Egress via Hysteria2

Notes

  • Native deployments run the APIs as user ovpmon; OpenVPN config install and service control go through a root helper (doas, fixed commands): see Privilege separation.
  • Keep easy-rsa/, client-config/, databases and *.env out of git: they contain private keys and secrets.
S
Description
No description provided
Readme
665 KiB
0 Stars 1 Watchers 0 Forks
Languages
Python 48.7%
Vue 35.2%
CSS 12%
JavaScript 2.3%
Jinja 0.8%
Other 1%