Proton VPN (WireGuard) for Omarchy
An Omarchy (Quattro / 4.x) shell plugin that drives Proton VPN through your own
WireGuard configs and wg-quick — no Proton CLI, no GUI app.
Why WireGuard instead of the official CLI? On the Proton Free plan the
official proton-vpn-cli refuses any --country, --city, or server argument
(RequiresHigherTierError: "Location selection is not available on the free
plan"). Proton's website, however, lets free accounts download WireGuard
configs for any free server. Drop those configs in /etc/wireguard and this
widget lets you pick a country from the bar. Paid accounts work the same way.
If you have a paid plan and want the CLI's richer features (NetShield, kill switch, per-city picks without pre-downloading configs), use nameless312/protonvpn-plugin-omarchy instead.
Features
- Monochrome Proton VPN mark drawn natively (
ProtonIcon.qml) so it follows your theme like the other bar icons; dimmed when disconnected, tooltip shows the active server - Left click: panel · right click: toggle last-used tunnel · middle click: refresh
- Panel: current server, country flag, endpoint; live uptime, tunnel IP, download/upload rate and totals
- Searchable list of your configs labeled by country and Proton server name
(
🇺🇸 United States — US-FREE#58 · omarchy-US) - Switching tunnels tears the current one down first, in one step
- Desktop notifications on connect/disconnect/error
- Remembers the last tunnel you used
Requirements
- Omarchy 4.x (Quattro shell)
wireguard-tools,libnotify,iproute2,bash(standard on Omarchy)- Your user in the
wheelgroup - Proton VPN WireGuard configs in
/etc/wireguard/*.conf
Install
1. Add the plugin
omarchy plugin add https://github.com/lajosdeme/protonvpn-omarchy-wg.git --enable
2. System setup (once, asks for your password)
~/.config/omarchy/plugins/io.github.lajosdeme.protonvpn-wireguard/install.sh
The script:
- installs
wireguard-tools/libnotifyif missing - installs
bin/protonvpn-wg-toggleas root into/usr/local/lib/protonvpn-omarchy-wg/and writes/etc/sudoers.d/protonvpn-omarchy-wgsowheelcan run that one wrapper without a password — neverwg-quickitself (see Security notes) - offers to remove the older
/etc/sudoers.d/wg-quickrule if you had one - sets
/etc/wireguardtoroot:wheel 750and the configs to640, so the widget can read server names while private keys stay hidden from other users
Re-run it after omarchy plugin update if the release notes say the helper changed.
After any omarchy plugin update, run omarchy restart shell — the shell does not always
hot-reload a widget whose files were replaced by a git pull.
3. Get configs
- Sign in at https://account.protonvpn.com/downloads
- WireGuard configuration → platform GNU/Linux → pick servers → download
- Install them:
sudo install -o root -g wheel -m 640 ~/Downloads/*.conf /etc/wireguard/
Name them however you like (omarchy-US.conf, nl-1.conf, ...) — letters,
digits, -, _, .; up to 15 characters (a kernel interface-name limit). The
widget reads the country from the Proton server comment inside the file.
Move the widget with omarchy bar move io.github.lajosdeme.protonvpn-wireguard --section right.
Remove
~/.config/omarchy/plugins/io.github.lajosdeme.protonvpn-wireguard/uninstall.sh
omarchy plugin remove io.github.lajosdeme.protonvpn-wireguard
uninstall.sh brings down any active tunnel, deletes the sudoers rule and the
helper, and leaves /etc/wireguard alone. Removing the plugin without running it
leaves the passwordless rule in place — don't skip it.
Settings
Per-widget settings live in ~/.config/omarchy/shell.json on the widget entry:
| Key | Default | Meaning |
|---|---|---|
configDir |
/etc/wireguard |
Directory scanned for *.conf |
refreshIntervalSec |
15 |
Status poll interval while the panel is closed |
Security notes
- The plugin runs unsandboxed inside
omarchy-shelllike every Omarchy plugin. ReviewPanel.qml,Model.js, andbin/protonvpn-wg-togglebefore enabling. - What the sudoers rule grants. Only
/usr/local/lib/protonvpn-omarchy-wg/protonvpn-wg-toggle(root-owned, not writable bywheel). The wrapper accepts exactlyup|down <name>, requires<name>to match^[A-Za-z0-9_][A-Za-z0-9_.-]{0,14}$(no slashes, so it can never be a path), and requires/etc/wireguard/<name>.confto exist, be owned by root, and not be group/world-writable before itexecswg-quick. That closes the obvious hole of grantingwg-quickdirectly, where any wheel process could point it at its own config file and havePreUphooks run as root. - Residual risk you accept: any process running as your user can toggle
your VPN tunnels without a password. It cannot pick which config file runs,
only which of the root-owned ones in
/etc/wireguard— and it can't write there. - Every subprocess is an argv vector. The two bash snippets in
Panel.qmlare constant strings that read inputs only from positional parameters. - Only comment lines and
Endpointare read from your configs. Private keys never leave the files. - Trust model of
install.sh. It elevates withsudo, so run it only from a checkout you trust — a cleanomarchy plugin addof this repository. It reads the helper into memory before the first password prompt, installs those exact bytes from stdin, and verifies the installed file's SHA-256 as root, so nothing on disk is re-read after you authenticate (no swap-during- prompt window). It cannot protect against code that already runs as your user before you start it; no user-run installer can, and such code already has root through sudo's credential cache or a hijackedsudoin your PATH. uninstall.shremoves the grant; the plugin dir alone never held it.
Development
node --test tests/model.test.js # unit tests for Model.js
tests/toggle.test.sh # input validation of the privileged wrapper (no root needed)
tests/install.test.sh # install.sh under DESTDIR with a sudo shim, incl. a swap-during-install attempt
omarchy plugin validate . # manifest check
ln -s "$PWD" ~/.config/omarchy/plugins/io.github.lajosdeme.protonvpn-wireguard
omarchy restart shell # symlinked dirs are not hot-reloaded; restart after edits
omarchy plugin enable io.github.lajosdeme.protonvpn-wireguard
Credits
UI structure and the tunnel-stats helpers follow nameless312/protonvpn-plugin-omarchy (MIT). The original waybar/WireGuard approach came from rulonder's Omarchy discussion.
License
MIT — see LICENSE.