Omahub
← All plugins
B

ZeroTier

by brukberhane

Manage ZeroTier client networks and local controller from the Omarchy bar. Unofficial; not affiliated with ZeroTier, Inc.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
68aef8e
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
68aef8e
Reviewed
1 month ago

The plugin is a well-structured ZeroTier management widget that talks only to the local ZeroTier service API on 127.0.0.1. The deterministic scan flagged a line in docs/intended_features.md mentioning sudo, but that is documentation text, not executable code. The backend uses secure token handling (keyring, stdin-only, no argv exposure) and includes input validation and bounded I/O.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/brukberhane/omarchy-zerotier --enable
Widgets #bar #quickshell #system

ZeroTier for Omarchy

ZeroTier client and controller admin from the Omarchy bar.

Unofficial third-party widget — not affiliated with ZeroTier, Inc.

ZeroTier panel — client networks and controller tab

Features

Client

  • Join / leave networks; connect / disconnect managed config from list
  • Network detail toggles (DNS, default route, global, managed)
  • Peers list
  • Full keyboard navigation (j/k, arrows, enter, esc)

Controller (when this node runs a controller)

  • List, create, edit, and delete networks
  • Member list: authorize, edit name/flags/IPs, remove
  • Flow rules editor (ZeroTier RDL or JSON)
  • IP pools, routes, DNS, MTU, and assignment flags

General

  • API token in OS keyring (libsecret; compatible with ztnui keyring entry)
  • Configurable refresh interval

Roadmap: docs/intended_features.md

Requirements

  • zerotier-one running locally
  • curl, python3, secret-tool (libsecret / GNOME Keyring)
  • wl-copy for copy actions
  • node on PATH (compiles RDL flow rules when creating/editing controller networks)

Install

From a git checkout:

omarchy plugin add https://github.com/brukberhane/omarchy-zerotier.git --enable

Or if the folder is already under ~/.config/omarchy/plugins/:

omarchy plugin enable io.github.brukb.omarchy-zerotier right
omarchy restart shell

On first open, paste your API token (from sudo cat /var/lib/zerotier-one/authtoken.secret). It is saved to the keyring only.

Validate before publishing:

omarchy plugin validate ~/.config/omarchy/plugins/io.github.brukb.omarchy-zerotier

Backend

No build step. bin/ztn-api is bash calling the local ZeroTier Service API on 127.0.0.1:9993.

~/.config/omarchy/plugins/io.github.brukb.omarchy-zerotier/bin/ztn-api auth status
~/.config/omarchy/plugins/io.github.brukb.omarchy-zerotier/bin/ztn-api networks

Settings

omarchy bar set io.github.brukb.omarchy-zerotier refreshIntervalSec 30

Removal

omarchy plugin disable io.github.brukb.omarchy-zerotier   # remove from the bar
omarchy plugin remove io.github.brukb.omarchy-zerotier     # delete the plugin

To clear the stored API token from the OS keyring before removal:

~/.config/omarchy/plugins/io.github.brukb.omarchy-zerotier/bin/ztn-api auth clear

zerotier-one and any joined networks are untouched.

License

MIT — see LICENSE.