Kodachi Binaries
This is the suite map for operators and power users: see what each tool does, how the categories fit together, and where to find exact generated commands.
The signed command-line stack
What this suite is
A collection of 25 auto-documented Rust binaries plus bundled companion runtimes that form the backbone of Kodachi OS's privacy, anonymity, and intelligence infrastructure. Security and control binaries deliver enterprise-level protection and policy enforcement; AI binaries provide natural-language command execution, trusted agent orchestration, and machine-safe execution, all processed locally by default.
How to read this page
Use the tabs above to move between the category map, the per-binary descriptions, the architecture and dependency view, the generated command surface, practical workflows, and the security model. For the big-picture pitch and comparison, see the Kodachi overview.
Suite taxonomy at a glance
oniux (process isolation helper) and tun2socks (proxy tunnel bridge).Core architecture principles
Zero-trust
Authentication-first design with granular authorization and certificate pinning.
Memory safe
Rust-first implementation with comprehensive error handling and rigorous safety practices.
Modular design
Independent services sharing cli-core, auth-shared, and logs-hook.
Forensic resistance
Multi-pass secure wiping, memory cleaning, and emergency data-destruction capabilities.
Privacy-first AI
The 7-tier AI engine runs locally by default. Optional cloud tiers route through VPN or Tor by preference.
Signed and verifiable
Every binary is cryptographically signed, so you can inspect and trust what you run.
Documentation hub
Complete command-line reference for all 25 core security and AI binaries, plus guided category hubs.
Looking for a complete solution?
These are individual security components for advanced users who want to integrate specific tools into their workflow. For a full desktop experience with GUI, Conky system monitor, LibreWolf browser, and 10 dynamic application layers, choose the Kodachi Desktop Edition (built on Debian 13 Trixie). For a headless, command-line-only environment optimized for testing, SOCKS proxy deployment, and server operations, choose the Kodachi Terminal Server. Both editions ship every binary pre-installed and configured, the KAICS AI engine, and the ai-gateway agent execution layer.
Support the project
Kodachi is built and maintained by one person since 2013. These 25 binaries and hundreds of commands are provided free. Your support keeps them maintained.
Binary categories and requirements
At-a-glance authentication, privilege, and auto-start requirements for every binary, grouped by role. Each name links to its full generated reference page.
Network and privacy tools
| Binary | Primary function | Auth | Sudo | Auto-start |
|---|---|---|---|---|
| tor-switch | Advanced Tor network orchestration (119 commands) | Mixed 67% | Required | No |
| routing-switch | Multi-protocol routing (11 protocols) plus External VPN Providers (VPN Gate, Riseup, NordVPN, IVPN, PIA, Surfshark, Mullvad-WG, and more) | Mixed 61% | Required | No |
| ip-fetch | Secure IP geolocation with multi-source verification | No 0% | No | No |
| dns-switch | DNS management with 336 bundled resolver options | Mixed 25% | Mixed | No |
| dns-leak | Real-time DNS leak detection and analysis | Mixed 25% | No | No |
System security and protection
| Binary | Primary function | Auth | Sudo | Auto-start |
|---|---|---|---|---|
| health-control | Emergency kill switches and panic modes | Mixed 84% | Required | No |
| integrity-check | Cryptographic system integrity verification | No | No | No |
| permission-guard | Real-time permission monitoring and enforcement | Mixed 75% | Required | No |
| online-auth | Secure authentication and heartbeat monitoring | Mixed 70% | Required | No |
| kodachi-soc | Host security monitoring with MITRE ATT&CK telemetry (read-only) | No 0% | Required | No |
Infrastructure and management
| Binary | Primary function | Auth | Sudo | Auto-start |
|---|---|---|---|---|
| logs-hook | Centralized secure logging infrastructure | Yes 100% | Required | Auto |
| deps-checker | Dependency validation and security auditing | No | No | No |
| global-launcher | System-wide binary deployment manager | No | No | No |
| workflow-manager | Batch command execution with conditional logic | Mixed 11% | Required | No |
| online-info-switch | Online information hub and RSS feeds | Mixed 58% | No | No |
| conky-status | Unified Rust telemetry gateway for Conky desktop panels | No | No | Auto |
GUI applications and desktop interface
| Application | Primary function | Technology | Auth | Sudo |
|---|---|---|---|---|
| kodachi-dashboard | Unified GUI control center for all security services | Native desktop app (Tauri) | Mixed | Required |
AI and intelligence
| Binary | Primary function | Type | Sudo | Auto-start |
|---|---|---|---|---|
| ai-cmd | Natural language CLI for Kodachi commands | On-demand | No | No |
| ai-trainer | ML model training and validation | On-demand | Required | No |
| ai-learner | Learning orchestration and analysis | On-demand | No | No |
| ai-admin | Database management and diagnostics | On-demand | No | No |
| ai-discovery | Binary watcher and auto-indexer daemon | Daemon | Required | Optional |
| ai-scheduler | Cron-based task scheduler | Daemon | Required | Optional |
| ai-monitor | Proactive system monitoring daemon | Daemon | Required | Optional |
| ai-gateway | Unified agent command gateway, policy firewall, and safe executor | On-demand | Policy | No |
Binary descriptions and use cases
A user-friendly overview of each binary's functionality, primary use cases, and operational capabilities. Each block links to its full generated documentation for exact command references and authentication requirements.
GUI control center
kodachi-dashboardUnified GUI control center
Modern desktop application providing a unified graphical interface for all Kodachi security services. Built for native performance and an elegant user experience. Features comprehensive control panels for authentication management (online-auth), network routing configuration (routing-switch with 11 protocols plus the External VPN Providers tab covering VPN Gate, Riseup, NordVPN, IVPN, PIA, Surfshark, AirVPN, Mullvad-WG, Windscribe, ProtonVPN, ExpressVPN, TorGuard), Tor network operations (tor-switch with 119 commands), DNS management (dns-switch), and system health monitoring (health-control). Provides real-time status displays, visual feedback for operations, and streamlined workflows for complex security tasks. Eliminates the need for multiple terminal windows by consolidating all binary operations into an intuitive dashboard interface. Supports dark and light themes, system tray integration, and keyboard shortcuts for power users. Ideal for users who prefer graphical interfaces while maintaining full access to all CLI capabilities.
Key features
- Centralized authentication: visual monitoring and management of online-auth service status and API key validation.
- Network protocol control: easy switching between VPN, WireGuard, Shadowsocks, V2Ray, Xray, Hysteria2, and Tor routing.
- Tor management: GUI access to 119 tor-switch commands including circuit rotation, exit node selection, and load balancing.
- DNS configuration: visual DNS server selection, DNSCrypt management, and real-time leak detection.
- System health dashboard: emergency kill switches, panic modes, integrity verification, and security scoring.
- Centralized notification center: one place for every alert (admin messages, SOC findings, command queue results, auto command runner, hardening and emergency alerts, updates, device status), reached from a bell in the sidebar. Per item you can mark read, dismiss, snooze, or play a sound if it recurs; a settings panel controls which severities are kept and per-category muting.
- Modern tech stack: a Rust backend for security with a native desktop runtime for a responsive, reactive UI.
Use cases
- Quick access to all security features without memorizing CLI commands.
- Visual monitoring of system security status and active connections.
- Rapid protocol switching for different anonymity requirements.
- Dashboard-style overview of all Kodachi services in one window.
- Ideal for users transitioning from GUI-based privacy tools.
AI suite (KAICS)
ai-cmdAI-powered command interface
Natural language command-line interface for Kodachi OS powered by a 7-tier AI engine (TF-IDF, ONNX, ONNX-Classifier, Local LLM, Mistral.rs, GenAI/Ollama, Claude CLI). Translates plain English queries into precise Kodachi commands with real-time streaming responses and native tool calling across 9 system tools. Works out of the box with zero configuration: the built-in TF-IDF engine provides immediate command matching. Supports interactive REPL mode, voice input via whisper-cpp or vosk, dry-run preview, confidence thresholds, and proactive command suggestions based on usage patterns. Mistral.rs integration provides local GGUF model inference supporting 29+ architectures, while GenAI/Ollama enables multi-provider LLM access (local or cloud via Tor) with privacy-safe operation.
ai-gatewayUnified agent command gateway
Machine-facing gateway for AI agents and automation. Provides unified command discovery (list, search, help), machine invocation metadata in search results, policy-enforced execution, per-agent capability controls, audit logging, rate limiting, and trusted batch execution. Supports JSON argument payloads (--args-json) and explicit approval semantics for dangerous commands, while keeping dry-run planning available for safe automation.
Validated integration points
search --jsonexposesinvocation(service,command) for deterministic agent calls.run --args-jsonaccepts object payloads for shell-quote-safe invocation.- dangerous commands require explicit confirmation for live execution.
- dangerous
--dry-runremains available for planning. - recognized agent profiles include:
nullclaw,agentzero,openclaw,picoclaw,nanoclaw,claude-code,gpt,gemini,open-interpreter(unauthenticated callers fall back to theanonymousdefault identity).
ai-trainerML model training and validation
Machine learning model management tool for the KAICS system. Downloads pre-trained ONNX semantic models, trains intent classifiers from training data, performs incremental updates, validates model accuracy, and exports trained models for deployment. Essential for upgrading from Tier 1 (TF-IDF) to Tier 2 (ONNX semantic) accuracy. All training happens locally with no cloud dependency.
ai-learnerLearning orchestration and analysis
Continuous improvement engine for the KAICS AI system. Learns from accumulated user feedback and command usage patterns to improve intent classification accuracy over time. Supports incremental learning, period-based analysis, and report generation in markdown or JSON format. Can be scheduled via ai-scheduler for automated periodic learning cycles.
ai-adminDatabase management and diagnostics
Administrative tool for KAICS AI infrastructure. Provides full system diagnostics, database statistics and integrity checks, backup and restore operations, and performance tuning capabilities. Essential for maintaining AI system health and troubleshooting issues.
ai-discoveryBinary watcher and auto-indexer
inotify-based binary watcher daemon that automatically detects and indexes new or updated Kodachi binaries. Maintains a real-time service registry used by ai-cmd for command resolution. Supports hot-reload of the AI command index without requiring service restart. Essential for keeping the AI system aware of all available commands.
ai-schedulerCron-based task scheduler
Cron-based task scheduler for automated Kodachi operations. Uses a strict command whitelist for security, supports standard cron expressions, and provides persistent task storage that survives service restarts. Ideal for scheduling recurring security checks, Tor circuit rotations, DNS leak tests, and AI learning cycles.
ai-monitorProactive system monitoring daemon
Background monitoring daemon that continuously tracks VPN connections, Tor circuit health, DNS leak status, and system security scores. Runs checks every 30 seconds and generates actionable suggestions categorized by network, DNS, Tor, and security domains. Provides early warning of potential issues before they impact privacy or security.
Core services
online-authAuthentication and heartbeat monitoring
Provides authentication services for Kodachi OS through cryptographic API validation and secure session management. Handles service heartbeats for connection monitoring and manages API keys for authorized access. Implements privacy-preserving authentication protocols with encrypted credential storage and secure token rotation. Ensures anonymous communication channels between local services and authentication endpoints. Maintains session persistence across restarts while adhering to anti-forensic principles.
routing-switchMulti-protocol network routing
Comprehensive encrypted routing service supporting 11 auto-scored anonymization protocols (WireGuard, OpenVPN, Tor, Xray VLESS, Xray VLESS-Reality, Hysteria2, Xray Trojan, V2Ray, Shadowsocks, Mita, Dante), plus xray-vmess available in the factory as a legacy fallback. Provides traffic obfuscation to bypass Deep Packet Inspection, multi-layer encryption tunneling, and anti-forensic network routing. Ensures complete privacy protection through protocol layering, encrypted tunnel management, and anonymization. Features intelligent routing tables for maximum anonymity while maintaining connection stability. Critical component of Kodachi's security infrastructure for high-anonymity communications.
tor-switchAdvanced Tor network orchestration
Manages Tor network connections and circuit isolation for Kodachi OS. Provides control over Tor instances, exit node selection, and circuit rotation. Features multi-instance Tor management, load balancing across circuits, DNS leak prevention, and traffic routing configuration. Supports transparent proxy setup, bridge configuration, and country-based exit node selection. Includes monitoring capabilities for circuit health and connection status.
ip-fetchSecure IP geolocation
Fetches IP geolocation data with multi-provider support and fallback mechanisms. Retrieves current IP address information including location, ISP, and connection details. Features automatic provider rotation when services are unavailable, response caching for efficiency, and verification through multiple sources. Supports both IPv4 and IPv6 addresses with JSON output format. Integrates with VPN and Tor connections to verify routing status.
online-info-switchInformation hub and RSS feeds
Information aggregation service providing RSS feed monitoring and data collection. Manages various information sources including security feeds, cryptocurrency data, and paste services. Features scheduled feed updates, content filtering, and data categorization. Supports multiple RSS sources with configurable refresh intervals. Provides structured output for collected information with timestamp tracking and source attribution.
conky-statusUnified Conky telemetry gateway
Rust telemetry gateway that unifies data collection for Kodachi Conky desktop panels. Replaces fragmented shell polling with a single snapshot cache and compatibility aliases, while preserving Conky-friendly outputs. Supports JSON, panel batching, key lookup, and refresh and TTL controls for stable desktop monitoring without script storms.
health-controlEmergency kill switches and panic modes
System health monitoring and emergency control service for Kodachi OS. Provides network connectivity checks, panic mode operations, and system state management. Features multiple emergency response levels (soft, medium, hard), network kill switches using iptables and nftables, secure data wiping capabilities, and MAC address randomization. Includes system scoring for security posture assessment, hardware monitoring, and USB device protection. Supports recovery operations for restoring network connectivity after emergency procedures.
dns-switchDNS management with 336 resolvers
DNS management service supporting multiple secure resolver configurations. Manages system DNS settings with support for 336 bundled resolvers including privacy-focused options. Features DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), and DNSCrypt protocol support. Provides automatic resolver switching, fallback mechanisms, and Pi-hole integration. Includes DNS cache management and resolver health monitoring. Supports custom resolver configuration and automatic optimal server selection.
dns-leakDNS leak detection and prevention
DNS leak detection and prevention service for network privacy verification. Performs comprehensive leak tests across all network interfaces to identify DNS configuration issues. Features real-time leak detection, multi-provider verification, and automated alert generation. Monitors DNS queries to ensure they route through configured secure channels. Provides detailed reports on DNS resolver usage and potential privacy issues.
kodachi-socHost security monitoring
Read-only host security monitoring service that powers the dashboard SOC page. Collects host-security telemetry across file and critical-binary integrity, boot-autoload monitoring, rootkit and account-integrity checks, and CIS hardening posture, tagging findings with MITRE ATT&CK techniques. It is hardening-aware, so Kodachi's own protections never read as compromise, and it never modifies system state. Exposes two commands: snapshot (a one-shot telemetry capture) and refresh (re-run the collection).
integrity-checkCryptographic system verification
System integrity verification service using cryptographic checksums and digital signatures. Validates file integrity through BLAKE3 hashing (SHA-256 as fallback) and signature verification. Features binary authentication, configuration file monitoring, and tamper detection. Provides scheduled integrity scans and on-demand verification. Maintains baseline checksums for critical system files and detects unauthorized modifications. Supports custom file lists and exclusion patterns for targeted verification.
permission-guardReal-time permission monitoring
File permission monitoring and enforcement service for system security. Monitors file system permissions and ownership to detect unauthorized changes. Features real-time permission tracking, automated correction of insecure permissions, and privilege escalation detection. Provides scheduled scans and on-demand verification of critical directories. Maintains permission baselines and reports deviations. Supports custom permission policies and automated remediation workflows.
logs-hookCentralized logging infrastructure
Provides centralized logging infrastructure with secure log collection, rotation, and deletion capabilities. Features encrypted log storage, automatic rotation schedules, and secure deletion protocols. Supports multiple log levels, filtering algorithms, and privacy-aware logging practices. Includes log aggregation from all system services and real-time monitoring. Offers multi-pass secure deletion and log anonymization for privacy protection.
deps-checkerDependency validation and auditing
Validates system dependencies and performs security auditing of installed packages. Features automated dependency scanning, version conflict detection, and security vulnerability identification. Provides package relationship analysis, compatibility verification, and installation script generation. Includes system configuration validation and dependency tree analysis. Maintains databases of tested configurations for optimal system security.
global-launcherSystem-wide binary deployment
Deploys Kodachi binaries system-wide while maintaining proper execution contexts and security validation. Features intelligent shortcut creation, environment variable management, and working directory preservation. Provides binary integrity verification and automated rollback capabilities. Includes security validation protocols and comprehensive deployment logging. Enables global accessibility without compromising security isolation.
workflow-managerBatch command execution and automation
Comprehensive workflow automation service for batch command execution with advanced conditional logic and state management. Features template-based workflow creation and a hybrid conditional system combining success and fail states with pattern matching and JSON path evaluation. Provides interactive pause controls for manual checkpoints, comprehensive telemetry logging in JSONL format, and configurable timeout protection. Supports concurrent execution within workflows, retry logic for failed operations, and dry-run mode for safe testing. Enables complex multi-step automation with regex pattern matching, substring searching, and JSON response evaluation for precise control flow. Ships with 96+ ready-to-use built-in profiles stored in dashboard/hooks/config/profiles/, and users can create custom profiles for their specific automation requirements. Critical for system maintenance workflows, batch operations, and automated diagnostic procedures requiring conditional execution paths.
Inter-binary dependencies matrix
How the services call each other. online-auth gates protected operations and logs-hook is the shared logging spine used by every binary.
Binary communication flow
| Service | Calls these binaries | Called by these binaries |
|---|---|---|
| online-auth | logs-hook | Authentication required by: ip-fetch, tor-switch, routing-switch, dns-switch, dns-leak, health-control, online-info-switch |
| logs-hook | None | Integrated by all services for centralized logging |
| ip-fetch | logs-hook, online-auth, routing-switch | tor-switch, routing-switch, dns-switch, dns-leak |
| tor-switch | logs-hook, online-auth, ip-fetch | routing-switch |
| routing-switch | logs-hook, online-auth, tor-switch, ip-fetch | health-control, ip-fetch |
| dns-switch | logs-hook, online-auth, ip-fetch | None |
| dns-leak | logs-hook, online-auth, ip-fetch | None |
| health-control | logs-hook, online-auth, routing-switch | dns-switch, online-info-switch |
| integrity-check | logs-hook | None |
| permission-guard | logs-hook | Can be used alongside online-auth for permission checks |
| kodachi-soc | logs-hook (read-only telemetry) | Consumed by the dashboard SOC page |
| deps-checker | logs-hook | None |
| global-launcher | logs-hook | Can be orchestrated by online-auth for deployments |
| workflow-manager | logs-hook | None (user-initiated batch operations) |
| online-info-switch | logs-hook, online-auth, health-control | None |
| conky-status | logs-hook, online-auth, ip-fetch, dns-switch, health-control | None (consumed by Conky desktop panels) |
| ai-gateway | logs-hook | ai-cmd, external agents |
Critical service dependencies
| Dependency type | Description | Affected services |
|---|---|---|
| Authentication chain | Services requiring valid authentication before operation | ip-fetch, tor-switch, routing-switch, dns-switch, dns-leak, health-control, online-info-switch |
| Logging infrastructure | All services use logs-hook for centralized logging | All binaries |
| IP verification | Services that call ip-fetch for network testing | tor-switch, routing-switch, dns-switch, dns-leak |
| System management | Services that may interact with online-auth | permission-guard, global-launcher |
System requirements and permissions
Privilege escalation requirements
| Operation type | Required permissions | Affected binaries |
|---|---|---|
| Network configuration | sudo / root | tor-switch (iptables/nftables), routing-switch, dns-switch |
| System security | sudo / root | health-control (network/MAC/hostname operations), kodachi-soc (host telemetry collection) |
| Authentication management | sudo / root | online-auth (system-wide operations) |
| Read-only operations | Standard user | ip-fetch, dns-leak, integrity-check, logs-hook, conky-status |
| AI operations | Standard user | ai-cmd, ai-trainer, ai-learner, ai-admin, ai-discovery, ai-scheduler, ai-monitor, ai-gateway |
Service daemon capabilities
| Service | Daemon mode | Command | Purpose |
|---|---|---|---|
| online-auth | Heartbeat daemon | online-auth authenticate --keep-alive or --relogin | Maintains authentication session |
| logs-hook | Integrated by all services | Automatic | Centralized logging for all operations |
| global-launcher | Service management | Standalone | Binary deployment and management |
| ai-monitor | Background daemon | ai-monitor start --daemon | Proactive VPN/Tor/DNS monitoring |
| ai-scheduler | Background daemon | ai-scheduler start | Cron-based automated task execution |
| ai-discovery | Background daemon | ai-discovery start | Binary watcher and auto-indexer |
Command surface matrix
Current command totals (generated from bin-json/*_rust_binary.json)
| Service | Commands | Privilege model | Primary use case |
|---|---|---|---|
| health-control | 236 | Mixed (many system operations require sudo) | Emergency kill switches, panic modes, system hardening |
| tor-switch | 119 | Mixed (network stack and firewall operations may require sudo) | Tor orchestration and circuit controls |
| dns-switch | 44 | Mixed (runtime checks plus privileged DNS and system updates) | DNS management and resolver control |
| routing-switch | 28 | Mixed (routing and protocol transitions may require sudo) | Multi-protocol network routing |
| online-auth | 21 | Service-auth plus local execution | Authentication service and heartbeat and session management |
| ai-cmd | 13 | Mostly user-level; delegated commands vary | Natural language command interface |
| workflow-manager | 12 | Workflow-dependent | Batch command execution and automation |
| ip-fetch | 11 | Mostly user-level | IP geolocation and network verification |
| online-info-switch | 10 | Mostly user-level | Information feeds and freshness checks |
| ai-gateway | 9 | Policy-dependent | Agent command gateway and policy firewall |
| ai-trainer | 8 | Mostly user-level | ML model training and validation |
| integrity-check | 7 | Mixed (read-only checks vs protected paths) | System integrity verification |
| deps-checker | 6 | Mostly user-level; install actions may require sudo | Dependency validation |
| conky-status | 4 | Mostly user-level | Conky telemetry gateway (legacy conky-details) |
| permission-guard | 4 | Mixed (fix operations require sudo) | Permission monitoring and remediation |
| dns-leak | 4 | Mixed | DNS leak testing |
| ai-scheduler | 4 | Mixed (scheduled command privilege follows command) | Cron-based task scheduling |
| ai-monitor | 4 | Mostly user-level | Proactive monitoring daemon |
| ai-learner | 4 | Mostly user-level | Learning orchestration and analysis |
| logs-hook | 3 | Mixed (log maintenance can require elevated access) | Logging and log maintenance |
| global-launcher | 3 | Mixed (deploy operations may require sudo) | Binary deployment and verification |
| kodachi-session-helper | 3 | Mostly user-level | Session helper utility |
| ai-discovery | 3 | Mostly user-level | Binary discovery and indexing daemon |
| ai-admin | 3 | Mostly user-level | AI database diagnostics and maintenance |
| kodachi-soc | 2 | Read-only (sudo for telemetry collection) | Host security snapshot and refresh |
flag_h.commandCategories metadata in docs/binaries/bin-json/. They map the documented CLI surface of the 25 core binaries; the published headline of 600 generated commands also counts generated flag and subcommand variants. Privilege and auth requirements are command-specific, so check each binary page for exact per-command behavior.
Authentication patterns by service type
| Pattern | Services | Description |
|---|---|---|
| No authentication | logs-hook, global-launcher, deps-checker, permission-guard, integrity-check, kodachi-soc, ai-cmd, ai-trainer, ai-learner, ai-admin, ai-discovery, ai-scheduler, ai-monitor, ai-gateway | No auth-shared library usage |
| Mixed authentication | online-info-switch, dns-leak, routing-switch, ip-fetch, dns-switch, tor-switch, health-control, workflow-manager | Selective command authentication |
| Bulk operations auth | ip-fetch | Only bulk and multi operations require auth |
| Emergency bypass | health-control | Critical recovery commands bypass auth |
| Special provider | online-auth | Authentication provider service |
- Security and auth workflows: online-auth and health-control.
- Network routing that needs cards: routing-switch, tor-switch, and dns-switch.
- Generated flags and exact command syntax: CLI Reference.
Key capabilities overview
Advanced network operations
| Feature | Capability | Details |
|---|---|---|
| Tor operations | 119 commands | Complete control over instances, circuits, and exit nodes |
| Load balancing | Native kernel-level | Traffic distribution across multiple Tor instances |
| Protocol support | 11 protocols | OpenVPN, WireGuard, Tor, Shadowsocks, V2Ray, Xray variants, and more |
| DNS resolvers | 336 bundled | DNSCrypt, DoT, DoH, Pi-hole integration |
Security and protection
| Feature | Implementation | Purpose |
|---|---|---|
| Emergency kill switch | health-control kill-network | Instant network termination |
| Panic system | 3 levels (soft, medium, hard) | Progressive data destruction |
| Data wiping | Multi-pass shredding | Secure deletion with verification |
| MAC randomization | Auto and manual modes | Hardware address anonymization |
| Hostname management | Random generation | System identity protection |
System integration
| Aspect | Approach | Benefit |
|---|---|---|
| Memory safety | Rust-first implementation | Robust error handling, no crashes |
| Performance | Optimized binaries | Fast response for critical operations |
| Output format | JSON-first design | Easy automation and scripting |
| Path detection | Dynamic resolution | Works on any Linux environment |
| Containment | Execution folder only | Enhanced security isolation |
Performance metrics
Total on-disk size is about 198 MB across the 25 documented CLI binaries, and about 256 MB for the full signed set including the Kodachi dashboard and the two third-party companions (oniux, tun2socks). The 11 routing protocols are auto-scored, with a legacy xray-vmess fallback available in the factory. The 336 bundled DNS resolvers span encrypted, fallback, normal, fetched, and reputable categories.
Common workflows
Practical command sequences for everyday privacy operations. Copy any block and adapt it to your setup.
Network anonymization setup
# Authenticate and configure Tor
sudo online-auth authenticate # Basic authentication
# Or use --relogin for automatic reconnection on session expiry
sudo online-auth authenticate --relogin
sudo tor-switch start-tor
sudo tor-switch torrify-system-nftables # Prefer nftables (modern)
# sudo tor-switch torrify-system-iptables # Alternative: iptables (legacy)
ip-fetch fetch # Fetch current IP info through Tor (ISP/ASN shows Tor exit node)Multi-protocol routing
# Connect through various protocols
sudo routing-switch connect openvpn
sudo routing-switch connect shadowsocks
sudo routing-switch connect wireguard
sudo routing-switch status # Check active routing
sudo routing-switch list-protocols # List available protocols with scores
sudo routing-switch disconnect # Disconnect current protocolSecurity hardening
# System hardening workflow
sudo health-control set-random-hostname
sudo health-control mac-change-all
sudo permission-guard scan
sudo integrity-check check-integrity --jsonDNS configuration
# Secure DNS setup
dns-switch status --json # Read current DNS mode/status (no sudo)
dns-switch dnscrypt-monitor-status --json # Monitor DNSCrypt watchdog state
sudo dns-switch switch --category encrypted # Use encrypted DNS
dns-leak discover --json # Discover and analyze DNS configuration
sudo dns-switch random --type encrypted --count 3 # Use random encrypted resolvers
sudo dns-switch fix-dns # Emergency DNS repair fallback
sudo dns-switch fix-dns --force # Run complete DNS repair chainEmergency response
# Quick privacy mode
sudo health-control panic-soft
sudo tor-switch restart-tor # Get new Tor circuit
sudo health-control recover-internet --check-dns # Recover connectivity + DNS if needed
sudo health-control fast-recover-internet --force # Force quick recovery then escalate if still unhealthy
# Complete shutdown
sudo health-control kill-network
sudo health-control wipe-logsKeep internet alive (auto-recovery loop)
Security considerations
Security implementation details
| Feature | Implementation |
|---|---|
| Authentication | Services use KODACHI_CALLING_SERVICE environment variable for identity |
| Certificate pinning | TLS 1.3 with pinned certificates for network operations |
| Error handling | Comprehensive error propagation without crashes |
| Audit trail | All operations logged through centralized logs-hook service |
Example JSON error response structure:
{
"status": "error", "error": {
"code": "AUTH_FAILED", "message": "Authentication required", "details": "Service requires valid authentication token", "timestamp": "2026-06-28T10:00:00Z"
}
}
Authentication flow
| Step | Command | Purpose |
|---|---|---|
| 1 | sudo online-auth authenticate --keep-alive or --relogin | Initial authentication (--relogin includes keep-alive) |
| 2 | online-auth check-login | Check authentication status |
| 3 | Service usage | Authenticated services automatically verify before execution |
| 4 | online-auth logout | Logout when finished |
System information
The authoritative version stamp is the release banner in the Overview tab. Values below track the current signed build.
| Component | Version | Build date | License |
|---|---|---|---|
| Kodachi OS | 9.8.4 | 2026 | Proprietary |
| Rust binaries | 9.8.4 (build #319) | 2026-06-28 | Proprietary |
| Documentation | 9.8.4 | 2026 | (c) 2026 Kodachi OS |
| Author | Warith Al Maawali | n/a | All rights reserved |