About this project
MikroTik OpenVPN GUI is a self-hosted control plane for an OpenVPN service running on RouterOS 7. It deploys as a container directly on supported MikroTik routers (arm64 validated, amd64 available for CHR/x86 evaluation) and provides a WinBox-inspired web dashboard for day-to-day VPN administration.
**Core capabilities:**
- Administrator authentication delegated to RouterOS—no separate dashboard password database.
- Full VPN user lifecycle: add, edit, suspend, duplicate, and remove users.
- Per-device client certificate issuance with password-protected profile archives.
- Safe CA migration: discover legacy certificates, issue replacements without disconnecting devices, then revoke old identities only after the new profile is tested.
- Mobile onboarding via short-lived QR hand-offs or ZIP downloads.
- Active session inspection including traffic counters, source addresses, and connection history.
- Access presets for device limits, expiry, schedules, speed limits, DNS, and quotas.
- Reusable policy templates with user previews before an auditable, checkpointed apply.
- Filtered bulk actions (suspend, revoke, tag) with per-user outcomes and safe retry.
- Reusable router-local user views (queries, status, tag filters) that never enter the public image.
- Read-only service-health view covering RouterOS REST, OpenVPN, certificate, storage, and capacity readiness.
**Administrator roles:** RouterOS groups map to five dashboard roles—Owner, Security operator, Administrator, Auditor, and Read-only—enforced by every API route, not just visible UI. Change History records sign-in events, role assignments, denied actions, and session revocation without storing passwords, tokens, private keys, or certificate contents.
**Security and privacy boundary:** The public repository contains only source code, tests, and architecture-neutral container images. All private data—RouterOS credentials, VPN users, certificates, private keys, generated profiles, SQLite metadata, and audit history—stays on the router's local persistent mounts and never enters GitHub or the public image. Dashboard metadata and sanitized audit events are kept in SQLite; no VPN passwords or private keys are stored.
**Deployment:** A router-local scheduler selects an immutable GHCR image, validates it in canary, and promotes to production only after health checks pass. Failed canary or readiness checks leave production untouched, and the previous image remains available for rollback. Operators pin immutable sha tags rather than following mutable branches.
**Enterprise operations line:** Adds a capability-gated administrator session center, short-lived read-only API tokens, live SSE connection events, profile diagnostics, immutable release verification, segmentation planning, and redacted compliance exports. A web-app manifest and reduced-motion styles support mobile use without a native client.
**Optional OpenVPN foundations planner:** For otherwise empty supported routers, generates a reviewable CA, server-certificate, address-pool, PPP-profile, and OpenVPN server plan. It never applies commands automatically or stores secrets in the public project.
The runtime uses the Python standard library. Licensed under Apache 2.0. Independent project, not affiliated with MikroTikls SIA.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.