Files
OpenGFW/README.ja.md
T
meiandClaude Opus 5 5a7722d1d2 feat: add embedded web UI
Adds an optional web dashboard served by OpenGFW itself, enabled with a new
`web` section in the config file.

Backend (web package, decoupled from engine/io so it builds on any OS):
- hub.go collects statistics off the engine logger callbacks: atomic counters,
  two ring-buffered time series (10s and 1min buckets), top N hosts/blocked
  destinations/rules/analyzers, and a 512 entry event buffer fanned out to
  connected clients over SSE. Slow clients drop frames instead of blocking
  the engine.
- api.go exposes /api/v1 for info, meta, metrics, events, the SSE stream and
  ruleset read/validate/replace.
- auth.go implements password login with in-memory session tokens and login
  rate limiting. Mutating endpoints require the bearer token (the session
  cookie is only accepted for GET), which makes them CSRF-safe.
- cmd/web.go implements the rule manager: rules are compiled before anything
  is written, the file is replaced atomically and the engine is hot reloaded.
  The SIGHUP handler now shares that same path.
- web/devserver serves the UI with synthetic traffic for frontend work on
  machines where the engine itself cannot be built.

Frontend (web/frontend, Vue 3 + Vite + Tailwind CSS v4 + Reka UI):
dashboard, live event feed with analyzer property inspection, visual and YAML
rule editors, analyzer overview and settings. Responsive down to phone sizes
with a bottom tab bar and bottom-sheet dialogs, plus light/dark themes and
English/Chinese translations.

The built UI in web/dist is committed and embedded with go:embed so that
`go build` works without Node; CI builds the frontend and checks that the
committed output is up to date.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-27 08:09:11 +08:00

3.4 KiB

OpenGFW

Quality check status License

OpenGFW は、あなた専用の DIY 中国のグレートファイアウォール (https://en.wikipedia.org/wiki/Great_Firewall) です。Linux 上で利用可能な柔軟で使いやすいオープンソースプログラムとして提供されています。なぜ権力者だけが楽しむのでしょうか?権力を人々に与え、検閲を民主化する時が来ました。自宅のルーターにサイバー主権のスリルをもたらし、プロのようにフィルタリングを始めましょう - あなたもビッグブラザーになることができます。

ドキュメントウェブサイト: https://gfw.dev/

Telegram グループ: https://t.me/OpGFW

Caution

本プロジェクトはまだ初期開発段階にあります。テスト時のリスクは自己責任でお願いします。私たちは、このプロジェクトを一緒に改善するために貢献者を探しています。

特徴

  • フル IP/TCP 再アセンブル、各種プロトコルアナライザー
    • HTTP、TLS、QUIC、DNS、SSH、SOCKS4/5、WireGuard、OpenVPN、その他多数
    • Shadowsocks、VMess の「完全に暗号化されたトラフィック」の検出など (https://gfw.report/publications/usenixsecurity23/en/)
    • Trojan プロキシプロトコルの検出
    • [WIP] 機械学習に基づくトラフィック分類
  • IPv4 と IPv6 をフルサポート
  • フローベースのマルチコア負荷分散
  • 接続オフロード
  • expr に基づく強力なルールエンジン
  • ルールのホットリロード (SIGHUP を送信してリロード)
  • 柔軟なアナライザ&モディファイアフレームワーク
  • 拡張可能な IO 実装 (今のところ NFQueue のみ)
  • リアルタイムのトラフィックダッシュボードとルールエディタを備えたウェブ UI

ウェブ UI

OpenGFW にはオプションのウェブダッシュボードが同梱されています。リアルタイムのトラフィック統計、 アナライザのプロパティを含むイベントフィード、そしてルールを検証してホットリロードできるルールエディタが利用できます。 スマートフォンでもデスクトップでも使えるレスポンシブ対応です。

設定ファイルで有効にします:

web:
  enabled: true
  listen: :8080
  secret: パスワード # 空の場合は起動時にランダム生成されログに出力されます
  # cert: /path/to/fullchain.pem
  # key: /path/to/privkey.pem

UI はバイナリに埋め込まれているため、追加のファイルを配置する必要はありません。 パスワードを知る人はルールを変更できるため、信頼できるネットワークにのみ公開してください。 開発方法は web/README.md を参照してください。

ユースケース

  • 広告ブロック
  • ペアレンタルコントロール
  • マルウェア対策
  • VPN/プロキシサービスの不正利用防止
  • トラフィック分析(ログのみモード)
  • 独裁的な野心を実現するのを助ける