Skip to content

Portly v1.0.0

Latest

Choose a tag to compare

@InSelfControll InSelfControll released this 30 Jan 17:12

Portly v1.0.0 Release Notes

Overview

Portly is a unified management tool for configuring NAT rules, firewall services, and security policies across multiple operating systems.

Supported Platforms

  • RHEL / Rocky / Alma / Fedora (firewalld + SELinux)
  • Ubuntu / Debian (nftables + AppArmor)
  • macOS (pfctl + SIP awareness)

Installation

Linux (x86_64)

# Download the binary
curl -L -o portly https://github.com/YOUR_USERNAME/unified-firewall/releases/download/v1.0.0/portly-linux-amd64

# Make it executable
chmod +x portly

# Move to PATH
sudo mv portly /usr/local/bin/

# Run
sudo portly

From Source

git clone https://github.com/YOUR_USERNAME/unified-firewall.git
cd unified-firewall
go build -o portly cmd/orchestrator/*.go
sudo ./portly

Features

1. Interactive TUI

Run without arguments to launch the interactive interface:

sudo portly

2. Rule Types

  • NAT Rule: Forward external port to internal IP:port
  • Open Port: Open a port for all incoming traffic
  • IP Restricted Port: Open a specific port only for a specific IP
  • Trust IP: Allow all traffic from a specific IP address

3. Firewall Management

  • Start/stop firewall service
  • Install firewall packages
  • View service status

4. Security Management

  • SELinux (RHEL): View and toggle booleans
  • AppArmor (Debian): View profiles, toggle enforce/complain modes, disable profiles

5. CLI Commands

# Add NAT rule
sudo portly add-nat --product nginx --external-port 8080 --internal-ip 10.88.0.1 --internal-port 80

# Open a port
sudo portly open-port --port 5432 --product postgres

# Open port for specific IP
sudo portly open-port --port 22 --source-ip 192.168.1.100

# List all rules
sudo portly list

# List open ports
sudo portly list-ports

# Check system status
sudo portly status

# Manage firewall service
sudo portly firewall status
sudo portly firewall start
sudo portly firewall stop

# Manage SELinux/AppArmor
sudo portly security status

Keyboard Shortcuts

General Navigation

  • ↑/↓ or j/k: Navigate up/down
  • Enter: Select / Confirm
  • ESC: Go back
  • q or Ctrl+C: Quit

List Views (Rules, Security)

  • ↑/↓ or j/k: Scroll
  • PgUp/PgDn: Page up/down
  • Home/End: Jump to top/bottom
  • r: Refresh
  • d: Delete first item (rules)

Security Rules

  • Space or Enter: Toggle boolean / Change AppArmor mode
  • d: Disable AppArmor profile

Architecture

Provider Pattern

Portly uses a provider pattern to automatically detect and use the appropriate firewall backend:

  • Detects OS family (RHEL, Debian, macOS)
  • Automatically selects firewalld, nftables, or pf
  • Common interface across all platforms

Modular Codebase

  • All files under 150 lines for maintainability
  • Clear separation of concerns (drivers, TUI, models)
  • Reusable components

System Requirements

  • Linux kernel 3.10+ or macOS 10.12+
  • Root/admin privileges for firewall modifications
  • For SELinux: policycoreutils-python-utils (RHEL)
  • For AppArmor: apparmor-utils (Debian)

Known Limitations

  • macOS: SIP cannot be disabled from within the running system
  • Some operations require the firewall service to be running
  • State management requires /var/lib/orchestrator directory (created automatically with sudo)

Contributing

Contributions are welcome! Please ensure:

  • Code follows Go best practices
  • All files remain under 150 lines
  • Tests pass (go test ./...)
  • go vet shows no issues

License

MIT License

Acknowledgments

Built with: