A production-grade GUI manager for Cloudflare WARP with per-application split tunneling support on macOS and Linux.
- System Tray / Menu Bar Integration β Quick toggle with status indicator
- Per-App Split Tunneling β Route individual apps through or around WARP
- Auto App Detection β Scans installed apps and .desktop files automatically
- Two Tunneling Modes β Proxy-based (no root) and IP rule-based (with root)
- Real-time Process Monitoring β Detects newly launched apps instantly
- Cross-Platform β macOS (Intel + Apple Silicon) + Linux (Debian/Ubuntu/Fedora/Arch)
- Persistent Config β Settings survive reboots via
~/.config/warp-gui/
βββββββββββββββββββββββββββββββββββ
β π‘οΈ WARPture [β] ON β
βββββββββββββββββββββββββββββββββββ€
β Search apps... π β
βββββββββββββββββββββββββββββββββββ€
β Chrome [INCLUDE β] β
β Firefox [INCLUDE β] β
β Zoom [EXCLUDE β] β
β Slack [DEFAULT ~] β
β Discord [INCLUDE β] β
β Steam [EXCLUDE β] β
βββββββββββββββββββββββββββββββββββ€
β Preset: [Work] [Gaming] [Stream]β
βββββββββββββββββββββββββββββββββββ€
β βοΈ Settings π Stats β
βββββββββββββββββββββββββββββββββββ
ββββββββββββββββ IPC/WS ββββββββββββββββββββ
β warp-gui ββββββββββββββββββΊβ tunnel-agent β
β (Electron+ β β (Go REST+WS) β
β React) β β β
ββββββββββββββββ ββββββββββ¬ββββββββββ
β gRPC/REST
ββββββββββΌββββββββββ
β process-monitor β
β (Python) β
ββββββββββββββββββββ
β
ββββββββββΌββββββββββ
β warp-cli β
β (Cloudflare) β
ββββββββββββββββββββ
See docs/ARCHITECTURE.md for full details.
# Install via DMG
open WARPture-v1.0.0.dmg
# Or install via Homebrew (coming soon)
brew install --cask warpture
# Manual build
make build-macossudo dpkg -i warpture_1.0.0_amd64.deb
# or
sudo apt install ./warpture_1.0.0_amd64.debsudo rpm -i warpture-1.0.0.x86_64.rpmgit clone https://github.com/mehranredrose/WARPture.git
cd WARPture
make install-deps
make dev- Cloudflare WARP CLI β Install from cloudflareclient.com
- Node.js β₯ 18 (for warp-gui)
- Go β₯ 1.21 (for tunnel-agent)
- Python β₯ 3.11 (for process-monitor)
Config is stored at ~/.config/warp-gui/split-tunnel.json:
{
"version": 1,
"defaultPolicy": "warp",
"includedApps": [
{
"name": "Firefox",
"bundleId": "org.mozilla.firefox",
"path": "/Applications/Firefox.app"
}
],
"excludedApps": [
{
"name": "Zoom",
"bundleId": "us.zoom.xos",
"path": "/Applications/zoom.us.app"
}
]
}| Mode | Root Required | How it Works |
|---|---|---|
| Proxy Mode (default) | β No | WARP local proxy on 127.0.0.1:40000, env injection |
| IP Rule Mode | β Yes | ip rule / pfctl routing rules per-app |
App traffic is forced through WARP regardless of default policy.
App traffic bypasses WARP entirely β direct internet connection.
Apps not in either list follow the global default: warp, bypass, or system.
# Start all services (dev mode)
docker-compose up
# Or run individually:
cd services/warp-gui && npm run dev
cd services/tunnel-agent && go run cmd/server/main.go
cd services/process-monitor && python monitor.py
# Run tests
make test
# Lint
make lint# Unit tests
make test-unit
# Integration tests
./scripts/integration-test.sh
# Test split tunnel logic only
cd services/tunnel-agent && go test ./internal/split/...WARPture/
βββ services/
β βββ warp-gui/ # Electron + React frontend
β βββ tunnel-agent/ # Go REST+WebSocket middleware
β βββ process-monitor/ # Python process scanner
βββ scripts/ # Install/uninstall scripts
βββ packaging/ # Platform packaging configs
βββ docs/ # Architecture & API docs
βββ Makefile # Build automation
- No hardcoded credentials
- Proxy mode requires no elevated privileges
- IP rule mode uses a minimal privileged helper (
warp-helper) via SMJobBless (macOS) or polkit (Linux) - All IPC communication is local-only
MIT β see LICENSE
mehranredrose β github.com/mehranredrose
- Fork the repo
- Create a feature branch:
git checkout -b feature/my-feature - Follow Git-Flow
- Submit a PR to
develop