Host-local defense
Validated policy decisions are enforced through an authoritative nftables ruleset, with local telemetry and operational evidence.
SysWarden is a host-local security orchestrator combining authoritative nftables policy, HIDS/HIPS telemetry, bounded threat intelligence, out-of-band WAAP log analysis, authenticated high availability and a native terminal dashboard.
SysWarden keeps enforcement close to the protected host and keeps its operating boundaries explicit.
Validated policy decisions are enforced through an authoritative nftables ruleset, with local telemetry and operational evidence.
SysWarden is not an inline HTTP proxy, a traffic sanitizer or a regulatory certification product.
Canonical IP, CIDR and service-scoped policy with persistent blocklists, whitelists and bounded SSH exceptions.
Local security telemetry, log analysis and a native TUI without a browser service or an additional listening port.
Analysis of logs written by supported upstream services, without claiming to proxy or sanitize application traffic.
Validated external feeds, operator-defined ASN and country controls, and last-known-good publication behavior.
TLS 1.3, bearer authentication, peer-scoped synchronization, explicit ownership and migration fences.
Checksummed native packages, signed update metadata, SBOMs and release qualification evidence.
SysWarden separates observation, decision and enforcement so each security boundary remains visible to operators.
Review the architectureCollect host and supported upstream log signals without inserting SysWarden into the application data path.
Canonicalize inputs, apply signatures and operator policy, and reject ambiguous state before publication.
Publish validated decisions through authoritative nftables rules while preserving explicit firewall ownership.
Operational procedures, package verification and lifecycle guidance are centralized in the project wiki.
| Family | Supported lines | Package |
|---|---|---|
| Debian | 13 | DEB |
| Ubuntu | 24.04, 26.04 | DEB |
| Fedora | 44 | RPM |
| AlmaLinux | 9, 10 | RPM |
| Alpine Linux | 3.22, 3.24 | APK |
ARM64/AArch64 and FreeBSD packages are not part of the supported release matrix.
Verify a package, install, configure, upgrade, roll back, audit or uninstall SysWarden with the release-bound documentation.
Ambiguous configuration, identity, feed or HA state is rejected before security policy is published.
Release assets expose checksums, signed update metadata, software bills of materials and qualification outputs.
Existing firewall service ownership is preserved, and host mutation remains reviewable through native package lifecycles.
Infrastructure, multi-distribution qualification and security review require continuous work. Community support helps fund the next verified improvements.
Support SysWarden on Ko-fiSource code and project documentation are available on GitHub.