A lightweight, modern, and asynchronous Terminal User Interface (TUI) for managing VPN connections on Linux, built in Rust with Ratatui and Tokio.
vpn_tui provides a unified dashboard to configure, authenticate, and monitor OpenConnect (Cisco AnyConnect / ocserv) and OpenVPN connections with real-time log streaming, traffic monitoring, preflight SSL certificate probing, and interactive certificate pinning.
- Multi-Protocol Support: Seamlessly configure and connect to both OpenConnect and OpenVPN gateways.
- Account Vault: Securely manage multiple credentials (username, password, authgroup) and link them to connection profiles.
- Interactive TUI Dashboard:
- Split-pane layout: Accounts, Profiles, Configuration Details/Flags, and Real-Time Logs.
- Live network throughput metrics (Upload/Download speeds) directly sampled from
/proc/net/dev. - Latency testing with an integrated multi-threaded TCP pinger.
- SSL Certificate Verification & Pinning:
- Preflight SSL probe inspects remote gateways before launching root processes.
- Interactive certificate warning modal displays the server subject, SHA-256 fingerprint, and reason for failure.
- One-click certificate pinning (
--servercert=pin-sha256:...) persisted directly into the profile. - Policy enforcement: Choose between
Strict,Prompt(interactive approval), orInsecure(--no-cert-check).
- Interactive File Picker:
- Built-in filesystem browser for selecting
.ovpnconfiguration files. - Supports inline path autocompletion (
Tab) and tilde (~) home directory expansion.
- Built-in filesystem browser for selecting
- Robust Clean Architecture: Hexagonal domain separation ensuring rock-solid state management, channel isolation, and 100% testable port adapters.
- Non-blocking Async Streaming: Full async event pipeline ensures terminal stays fluid while capturing stdout, stderr, and tunnel state transitions.
- Graceful Teardown: Automatically terminates background VPN processes and restores terminal state on exit (
qorCtrl+C).
vpn_tui runs on Linux and requires the appropriate VPN clients installed on your system along with sudo privileges to configure network interfaces (tun0, tun1).
| Tool | Purpose | Required |
|---|---|---|
| Rust toolchain | Rust compiler (edition 2024 / 1.85+) and cargo |
To compile from source |
| openconnect | Backend runner for Cisco AnyConnect / ocserv protocols | Optional (for OpenConnect profiles) |
| openvpn | Backend runner for OpenVPN tunnels | Optional (for OpenVPN profiles) |
| sudo | Elevated permissions to spawn network tunnels | Yes |
-
Debian / Ubuntu / Linux Mint:
sudo apt update sudo apt install openconnect openvpn
-
Arch Linux / Manjaro:
sudo pacman -S openconnect openvpn
-
Fedora / RHEL:
sudo dnf install openconnect openvpn
-
openSUSE:
sudo zypper install openconnect openvpn
Ensure you have Rust and Cargo installed (rustup.rs):
# Clone the repository
git clone https://github.com/your-username/vpn_tui.git
cd vpn_tui
# Build the release binary
cargo build --releaseThe compiled binary will be placed at target/release/vpn_tui.
cargo install --path .Ensure ~/.cargo/bin is in your $PATH.
sudo install -m 755 target/release/vpn_tui /usr/local/bin/vpn_tuiWhen connecting to a VPN, vpn_tui spawns openconnect or openvpn using sudo. If sudo credentials are not already cached in your terminal session, vpn_tui will prompt you with an interactive in-terminal password modal.
If you prefer seamless, passwordless connection launches, add the following entry using sudo visudo:
# Allow your user (or wheel/sudo group) to run VPN binaries without entering password
your_username ALL=(ALL) NOPASSWD: /usr/sbin/openconnect, /usr/sbin/openvpn
(Verify the exact binary paths on your distribution with which openconnect and which openvpn.)
Launch the application in any terminal emulator:
vpn_tui- Press
Tabuntil the Accounts pane is focused (highlighted border). - Press
ato open the New Account dialog. - Fill in the fields (
TaborDownto navigate,Enterto save):- Account Name: Label (e.g.
Work Credentials,Personal VPN). - Username: Gateway login username.
- Password: Gateway login password.
- Authgroup: (Optional) Gateway group/realm for OpenConnect.
- Account Name: Label (e.g.
- Press
eto edit orxto delete an existing account.
- Press
Tabto switch focus to the Configurations pane. - Press
nto open the Config Adder modal. - Select your protocol using
SpaceorLeft/Rightarrow keys:- OpenConnect: Enter Gateway Endpoint (e.g.,
vpn.example.com:443), choose SSL Verification Policy, and select an associated account. - OpenVPN: Enter Profile Name,
.ovpnConfiguration File path, and optional remote address overrides.- Tip: When on the
.ovpnpath field, pressF2to launch the interactive file picker, or pressTabfor inline path autocomplete!
- Tip: When on the
- OpenConnect: Enter Gateway Endpoint (e.g.,
- Customize protocol-specific flags (e.g.,
--no-dtls, custom CLI flags). - Press
Enterto save the profile.
- Connect: Select a profile and press
Enter.- If the profile uses OpenConnect and connects to a server with a self-signed or untrusted SSL certificate,
vpn_tuiwill pause and display a Certificate Warning Modal with the server fingerprint. PressEnterorato accept and automatically pin the certificate fingerprint, orEsc/rto abort. - If required, enter your
sudopassword in the secure password modal.
- If the profile uses OpenConnect and connects to a server with a self-signed or untrusted SSL certificate,
- Live Logs: Watch the bottom-right Connection Logs pane populate with server messages, IP allocation, and handshake progress.
- Traffic Stats: Upon successful tunnel creation (
tun0), the top banner displaysCONNECTED, the allocated VPN IP address, and real-time upload/download speeds. - Ping Latency: Press
pat any time to probe the TCP latency of all configured gateway endpoints. - Disconnect: Press
dto safely terminate the active tunnel and restore routing.
| Key | Action |
|---|---|
Tab / BackTab |
Cycle focus between panes (Accounts → Profiles → Flags → Logs) |
j / Down |
Move selection down in the active pane |
k / Up |
Move selection up in the active pane |
Enter |
Connect to the currently selected profile |
d |
Disconnect active VPN session |
p |
Ping all profile endpoints for latency |
n |
Create a new VPN configuration (in Profiles pane) |
a |
Create a new Account (in Accounts pane) |
e |
Edit selected profile or account |
x |
Delete selected profile or account |
q / Ctrl+C |
Clean up active connections and quit |
| Modal | Key | Action |
|---|---|---|
| Config Adder | Tab / Down |
Move to next field |
Shift+Tab / Up |
Move to previous field | |
Space / Left / Right |
Cycle protocol, cycle account, toggle flags, cycle SSL policy | |
F2 |
Open interactive file browser (on .ovpn file field) |
|
Tab |
Inline directory and file autocompletion (on .ovpn path) |
|
Enter |
Save profile | |
Esc |
Cancel and close modal | |
| File Browser | Up / Down |
Navigate directory entries |
Enter |
Enter directory / select file | |
Backspace |
Navigate up to parent directory | |
Esc |
Close file browser | |
| Cert Warning | Enter / a |
Accept and permanently pin server certificate fingerprint |
Esc / r |
Reject certificate and abort connection | |
| Delete Confirm | y / Enter |
Confirm deletion |
n / Esc |
Cancel deletion | |
| Sudo Password | Enter |
Submit password |
Esc |
Cancel authentication |
vpn_tui persists your profiles and accounts in human-readable TOML files adhering to the XDG Base Directory specification:
~/.config/vpn-tui/
├── accounts.toml # Account credentials (usernames, encrypted passwords, authgroups)
├── openconnect/ # OpenConnect configuration profiles
│ ├── munich-gw.toml
│ └── corporate-vpn.toml
└── openvpn/ # OpenVPN configuration profiles
├── client.ovpn
└── office-vpn.toml
(Note: If a ./configs/ directory exists in the working directory, vpn_tui will operate in portable local mode).
To run the complete automated test suite (unit tests, architecture boundary tests, and end-to-end flow tests):
cargo testTo run linter and formatting checks:
cargo clippy -- -D warnings
cargo fmt -- --checkvpn_tui follows the Hexagonal (Ports and Adapters) Architecture:
+-------------------------+
| Ratatui / Crossterm |
| (Terminal User UI) |
+------------+------------+
|
v
+-----------------------------------------------------------------------+
| DOMAIN LAYER (Core Entities & Pure State) |
| - Profile, Account, Credentials, SslPolicy, ConnectionState |
+-----------------------------------------------------------------------+
^ ^
| |
+-------+-----------------------+ +---------------+---------------+
| PORTS (Interfaces) | | INFRASTRUCTURE (Adapters) |
| - ConfigStorage trait | <--- | - FsConfigStorage (TOML) |
| - VpnRunner trait | <--- | - SudoProcessRunner (Async) |
| - Pinger trait | <--- | - TcpPinger (Multi-threaded) |
+-------------------------------+ | - NetMonitor (/proc/net/dev) |
+-------------------------------+
- Zero Coupling: Core domain rules and state machine do not depend on Ratatui or process execution.
- Port Swappability: Testing uses in-memory storage, mock VPN runners, and mock pingers without needing root privileges or network connectivity.
MIT License. See LICENSE for details.