GTK Control Center
Kodachi turns hundreds of command-registry actions into a consistent native GTK3 interface. The left rail chooses a page or section. The body shows live state and controls. The footer applies staged changes and keeps results visible.
One interaction model across every window
Background refresh protects your pending choice
A refresh may update the live baseline while you work, but it does not overwrite a switch or radio choice you have already staged. If live state changes underneath you, the pending indicator continues to show the difference.
The 13 GTK windows launched by the dock
Quick
Frequent Kodachi actions collected into one small window.
Isolation Manager
Application runtime choice, catalog, custom apps, containers, running state, images, and profiles.
Status
Read-only summaries for current privacy, network, service, and machine state.
Network
Nine pages for VPN, routing, Tor, exit and avoid lists, Tor service, kill switch, DNS, and tuning.
Identity
MAC, hostname, timezone, IPv6, and decoy-traffic state and actions.
Devices
Wi-Fi, Bluetooth, webcam, microphone, USB storage, USBGuard, modem, encrypted storage reports, and USB inspection.
Harden
Standard, Medium, and Paranoid profiles plus individual defenses, swap, and verification.
Verify
Integrity and security checks whose output should be reviewed before acting.
Services
Remote access, peer-to-peer services, intrusion guard, logs, exposure, and maintenance.
Account
Authentication, license, and account status controls.
System
Desktop, power, display, update, and system maintenance operations.
Recipes
Reviewed multi-step workflows with visible progress and stop-on-failure behavior.
Emergency
Panic response, network containment and recovery, individual mechanism stops, disk-key destruction, and session ending.
Repository Manager is also a custom GTK application, but it is a separate storefront rather than a command-window surface. See the Repository Manager guide.
Example: change a network path safely
- Open More -> Network.
- Choose VPN Connect for the tunnel, VPN Routing for how traffic reaches it, or one of the four adjacent Tor pages for Tor behavior.
- Read the current status before changing a mode. No selected radio is a valid state when the producer did not report one.
- Choose one compatible mode and press the contextual Connect or Apply action.
- Wait for the result. Then use Kill Switch, DNS, or a Show control to verify the state you care about.
A green button press is not a connectivity test
Use the result panel and a status or leak check. A backend can accept a request while the network, VPN provider, Tor circuit, or resolver remains unavailable.
Network page order
VPN Connect and VPN Routing are together first. The four Tor controls follow together: Tor, Tor Exit Country, Tor Avoid, and Tor Service. Kill Switch, DNS, and Tuning follow them.
Know which actions deserve extra care
| Area | Consequence to review |
|---|---|
| Devices | Disabling Wi-Fi, a modem, camera, microphone, or USB storage affects every application using it. |
| Services | Turning off SSH can end remote access. Turning off logs reduces later diagnostic evidence. Auto login and screen lock affect physical security. |
| Hardening | Paranoid mode can disable conveniences. Reset removes hardening changes. Swap and USB policies can affect active work and devices. |
| Identity | Changing MAC, hostname, timezone, IPv6, or decoy traffic can interrupt connections or change what peers observe. |
| Emergency | Network cuts stop connectivity. Panic and session controls interrupt work. Arm LUKS Nuke requires the explicit device and password form, then runs without a separate yes or no confirmation dialog. |
Do not test destructive controls to learn what they do
Read the row note, tooltip, and this guide first. In these grouped command windows, Logout, Reboot, and Shutdown currently confirm. Other red actions can run immediately, so red means consequential rather than another prompt is coming. Use Status, Verify, or other read-only reports for routine checks.
What each symptom means
| Symptom | Interpretation and next step |
|---|---|
| State says sign-in needed | The status producer requires an authenticated session. Open Account, sign in, then reopen or retry the control. |
| State says no status | The action has no status producer. This is distinct from off and from a failed read. |
| State says unreadable | The status producer failed or returned an answer the window could not interpret. Press refresh or Show and read the exact output. |
| Apply is disabled | Nothing differs from known live state, or a required status/prerequisite is unavailable. |
| A control is insensitive | Read the adjacent reason or tooltip. Do not infer that the feature is absent. |
| Progress appears stuck | Keep the window open and read elapsed time. A bounded timeout eventually returns control and a failure explanation. |
| An Open action reports failure | The external program, profile, terminal, or helper may be missing. The inline result names the attempted surface. |
| Already running | The same direct action still holds its single-flight slot. Bring its window forward or wait for it to finish instead of starting a duplicate. |
| One staged item failed | The window stops at the first failure. Successful items leave the pending set; failed and unattempted items remain available for retry. |
For application runtimes, continue to Isolation Manager. For package operations, use Repository Manager.