- Profiler: when not root, render server.conf to the staging dir and let the root helper validate (directive allowlist) and install it; control the openvpn service through the helper (doas, fixed commands). - Add ovpmon-helper and doas rules under DOCS/General/privilege-separation. - Document the design, rollout, results and limitations. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
OpenVPN Profiler Module (APP_PROFILER)
The Profiler module is a FastAPI-based service (port 8000) dedicated to management tasks:
- Public Key Infrastructure (PKI) management (EasyRSA wrapper).
- Client Profile (
.ovpn) generation. - Server Configuration management.
- Process control (Start/Stop OpenVPN service).
Documentation
- API Reference: See
DOCS/Profiler_Management/API_Reference.md. - Overview: See
DOCS/Profiler_Management/Overview.md.
Quick Start (Dev)
# Setup
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# Run
python3 main.py
# Swagger UI available at http://localhost:8000/docs