share
warren share 22 --to laptopMake a local port reachable, optionally only by named machines. Until you do, nothing is.
Through a relay you run yourself.
warren is one Rust binary. Your machines dial out to a relay you run and reach only the ports you share, end-to-end encrypted. No inbound ports, no kernel driver, no third-party account.
One outbound connection to your relay, on 443 by default. No inbound ports, so it works behind NAT.
It sees who talks to whom and when, never what.
Default deny: it checks its own share list for every stream.
iPhone and iPadcoming Not in v0.1, and not part of the recorded run.
1
binary
The relay, the node daemon and the CLI are one file you can read, build and run yourself.
0
inbound ports on your machines
Everything rides one outbound WebSocket on port 443, with default-deny shares checked at the destination.
0.07ms
added median round trip, on loopback*
0.07 to 0.08 ms added, and 1.6 to 1.9 Gbit/s through a private link, both measured on loopback.
Measured on loopback on an Apple M-series machine, relay and both nodes on one host, TLS and Noise on. Not measured over the internet; for that, see the field report below.
The relay runs on a small Ubuntu server (1 GB of RAM) behind nginx, with a certificate from certbot; the hub runs on a Mac that publishes it through the relay. Until then the hub was reached through a hosted tunnel, which stays up as the fallback. The product’s web front end forwards every request over one of the two routes, so they can be compared like for like: in the 30 minutes after the switch, four kinds of request went through it 120 times each over warren and, at the same moments, over the hosted tunnel. Every request was a fresh connection from the same client, and every one succeeded.
| route | requests | p50 | p95 |
|---|---|---|---|
| warren relay | 480 | 148 ms | 311 ms |
| hosted tunnel | 480 | 154 ms | 595 ms |
The medians are about the same; at the 95th percentile warren took about half as long. One client over half an hour on a busy evening, not a benchmark. The whole setup, with backups, health checks and how to remove it: docs/production-relay.md.
01The run
Three shells on one Mac run the v0.1.0 release binary against a relay on 127.0.0.1. Commands and output are verbatim; captions, highlights and drawings are added to explain them.
01 / 09Download and start a relay
The v0.1.0 release binary from GitHub, then a relay on 127.0.0.1 with a self-signed certificate.
Playback is paced for reading; the run itself took 18 seconds. Run it yourself.
02Security model
Each machine keeps one outbound TLS connection to your relay. Inside it, the two machines run their own Noise_IK_25519_ChaChaPoly_BLAKE2s handshake, so a private stream crosses the relay sealed. Public names are the one exception, and warren says so every time you use one.
Private link: laptop and desktop each hold their own TLS connection to the relay, and one Noise_IK stream runs end to end inside them, passing through the relay sealed. The relay sees who, which port, when and how many bytes. desktop checks its own share list before it opens 127.0.0.1:8000. Public name: any browser connects over HTTPS. TLS ends at the relay, which reads the HTTP and passes it to desktop inside desktop's own TLS connection.
warren join; files are 0600 in a 0700 directory03Commands
A handful of verbs cover it. Every command also speaks --json, with documented exit codes.
Relay certificates: ACME HTTP-01, your own --cert and --key, or --self-signed for a trial.
warren share 22 --to laptopMake a local port reachable, optionally only by named machines. Until you do, nothing is.
warren forward 2222 desktop:22Listen on 127.0.0.1 and carry each connection to a port on another machine.
warren ssh desktopssh without a forward, or put warren nc %h 22 in your ssh config as a ProxyCommand.
warren publish 3000 --name webPut a local port on https://web.<your relay>/, WebSockets and long polling included. TLS for it ends at the relay.
warren relay revoke laptopDisconnect a machine at once, even mid-handshake, and refuse it from then on.
warren trust desktop --expect FPKeys are pinned. A changed key is refused until you check the new fingerprint.
04Download
Apple silicon
aarch64-apple-darwin4.8 MB
Not notarized, so macOS quarantines a browser download: use the curl line in the quick start, or run xattr -d com.apple.quarantine warren once.
x86_64
x86_64-unknown-linux-gnu5.4 MB
Built and tested in CI on Linux. Not yet run on real Linux machines, so please report what you find.
Rust 1.88+
cargo install --locked --git https://github.com/willykeenan/warren
cargo install warren installs an unrelated crate with the same name.
comingWindows. A Windows build is in progress and will appear on the releases page.Watch the repository
comingiPhone and iPad. Not in v0.1. The plan is an app that joins your warren by scanning a QR code.
05Quick start
The run above, on one machine, in three shells.
For Linux, use the x86_64-unknown-linux-gnu tarball instead.
mkdir -p /tmp/warren-demo && cd /tmp/warren-democurl -fsSL https://github.com/willykeenan/warren/releases/download/v0.1.1/\warren-v0.1.1-aarch64-apple-darwin.tar.gz | tar xzexport PATH=$PWD:$PATH
A self-signed certificate is fine for a trial. invite prints a one-time code and the certificate pin.
warren relay --domain localhost --self-signed --listen 127.0.0.1:8443 --state relay &warren relay invite --state relay
In a second shell, as desktop. For laptop, run warren relay invite --state relay again for a fresh code, then repeat this in a third shell with WARREN_HOME=$PWD/laptop and --name laptop.
cd /tmp/warren-demo && export PATH=$PWD:$PATH WARREN_HOME=$PWD/desktopwarren join CODE --relay https://localhost:8443 \--insecure-relay-cert-sha256 PIN --name desktopwarren up &
On desktop: a tiny web server that listens only on 127.0.0.1.
mkdir site && echo "hello from desktop" > site/hello.txtpython3 -m http.server 8000 --bind 127.0.0.1 --directory site &
desktop shares port 8000 with laptop only; laptop forwards a local port to it. Run the forward and curl before the share, and desktop refuses, as in the run.
# desktopwarren share 8000 --to laptop# laptopwarren forward 9000 desktop:8000curl http://127.0.0.1:9000/hello.txt
Optional. A public name (TLS ends at the relay; -k because the certificate is self-signed), then revoke laptop from the relay shell.
# desktopwarren publish 8000 --name web# laptopcurl -sSk https://web.localhost:8443/hello.txt# relaywarren relay revoke laptop --state relay
Use a name you control. The wildcard is only needed for warren publish.
relay.example.com. A <server IP>*.relay.example.com. A <server IP>
Somewhere sudo finds it.
curl -fsSL https://github.com/willykeenan/warren/releases/download/v0.1.1/\warren-v0.1.1-x86_64-unknown-linux-gnu.tar.gz | tar xzsudo install -m 755 warren /usr/local/bin/warren
It listens on 443, and on 80 for certificate challenges. ACME has not yet run against a live CA: start with Let's Encrypt staging (--acme-directory) or bring a certificate with --cert/--key. Running it as a service: docs/relay.md.
sudo warren relay --domain relay.example.com --acme YOUR_EMAIL --state /var/lib/warrensudo warren relay invite --state /var/lib/warren
One code per machine. install starts warren at login (launchd on macOS, a systemd user unit on Linux). share 22 admits every enrolled machine; --to a limits it to machine a.
warren join CODE --relay https://relay.example.com --name bwarren installwarren share 22
Then run warren devices on both machines. The fingerprints must match: that is what makes first contact trustworthy.
warren join CODE --relay https://relay.example.com --name awarren installwarren ssh b
06Status and limits
Read this before relying on it. Full notes: Status and limitations in the README.
The relay, the node daemon and the login service have been used on macOS.
A relay has run on an Ubuntu server in production since October 2026 (see the field report). Linux nodes are supported by the code and pass the test suite in CI, but none has run on a real machine yet.
Coming. There is no Windows build in v0.1.
Coming. There is no phone or tablet build in v0.1; the plan is an app that enrolls by QR code.
The ACME pieces are tested, but the exchange with a live CA has not run end to end. Use staging first, or your own certificate.
warren install is tested with a stand-in service manager; the real launchctl and systemctl calls are not run by the tests.
The first key a machine sees for a peer comes from the relay. Compare warren devices on both machines after enrolling.
warren share PORT without --to admits every enrolled machine, and whoever controls the relay can enroll one. Use --to for anything sensitive.
All traffic goes through your relay. If it is down, nothing connects.
No UDP. The relay's default listeners are IPv4; IPv6 is covered in docs/relay.md.