Portly v1.0.0 Release Notes
Overview
Portly is a unified management tool for configuring NAT rules, firewall services, and security policies across multiple operating systems.
Supported Platforms
- RHEL / Rocky / Alma / Fedora (firewalld + SELinux)
- Ubuntu / Debian (nftables + AppArmor)
- macOS (pfctl + SIP awareness)
Installation
Linux (x86_64)
# Download the binary
curl -L -o portly https://github.com/YOUR_USERNAME/unified-firewall/releases/download/v1.0.0/portly-linux-amd64
# Make it executable
chmod +x portly
# Move to PATH
sudo mv portly /usr/local/bin/
# Run
sudo portlyFrom Source
git clone https://github.com/YOUR_USERNAME/unified-firewall.git
cd unified-firewall
go build -o portly cmd/orchestrator/*.go
sudo ./portlyFeatures
1. Interactive TUI
Run without arguments to launch the interactive interface:
sudo portly2. Rule Types
- NAT Rule: Forward external port to internal IP:port
- Open Port: Open a port for all incoming traffic
- IP Restricted Port: Open a specific port only for a specific IP
- Trust IP: Allow all traffic from a specific IP address
3. Firewall Management
- Start/stop firewall service
- Install firewall packages
- View service status
4. Security Management
- SELinux (RHEL): View and toggle booleans
- AppArmor (Debian): View profiles, toggle enforce/complain modes, disable profiles
5. CLI Commands
# Add NAT rule
sudo portly add-nat --product nginx --external-port 8080 --internal-ip 10.88.0.1 --internal-port 80
# Open a port
sudo portly open-port --port 5432 --product postgres
# Open port for specific IP
sudo portly open-port --port 22 --source-ip 192.168.1.100
# List all rules
sudo portly list
# List open ports
sudo portly list-ports
# Check system status
sudo portly status
# Manage firewall service
sudo portly firewall status
sudo portly firewall start
sudo portly firewall stop
# Manage SELinux/AppArmor
sudo portly security statusKeyboard Shortcuts
General Navigation
↑/↓orj/k: Navigate up/downEnter: Select / ConfirmESC: Go backqorCtrl+C: Quit
List Views (Rules, Security)
↑/↓orj/k: ScrollPgUp/PgDn: Page up/downHome/End: Jump to top/bottomr: Refreshd: Delete first item (rules)
Security Rules
SpaceorEnter: Toggle boolean / Change AppArmor moded: Disable AppArmor profile
Architecture
Provider Pattern
Portly uses a provider pattern to automatically detect and use the appropriate firewall backend:
- Detects OS family (RHEL, Debian, macOS)
- Automatically selects firewalld, nftables, or pf
- Common interface across all platforms
Modular Codebase
- All files under 150 lines for maintainability
- Clear separation of concerns (drivers, TUI, models)
- Reusable components
System Requirements
- Linux kernel 3.10+ or macOS 10.12+
- Root/admin privileges for firewall modifications
- For SELinux:
policycoreutils-python-utils(RHEL) - For AppArmor:
apparmor-utils(Debian)
Known Limitations
- macOS: SIP cannot be disabled from within the running system
- Some operations require the firewall service to be running
- State management requires
/var/lib/orchestratordirectory (created automatically with sudo)
Contributing
Contributions are welcome! Please ensure:
- Code follows Go best practices
- All files remain under 150 lines
- Tests pass (
go test ./...) go vetshows no issues
License
MIT License
Acknowledgments
Built with:
- Bubble Tea - TUI framework
- Lipgloss - Styling
- Cobra - CLI framework