Omahub
← All plugins
T

Omarchy OpenVPN Connect

by tug-benson

OpenVPN client for Omarchy — multi-profile .ovpn import, username/password + TOTP (MFA) challenge/response auth, live tunnel traffic graph, and full network info (IP, gateway, DNS, routes, search domains).

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
cad2831
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S networkmanager openvpn python3 polkit zenity`.
  • Docs sudo README.md:56

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S networkmanager networkmanager-openvpn openvpn python3 polkit zenity

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
cad2831
Reviewed
1 month ago

The plugin is a legitimate OpenVPN client that drives NetworkManager via nmcli using the user's existing PolicyKit privileges; no sudo is used in the executable code. Credentials are passed through environment variables and stdin and are never persisted, and the only files written are non-secret settings in ~/.config/openvpn. The deterministic scan flagged sudo commands in README/SUBMISSION.md, but those are documentation-only install instructions for external dependencies, not part of the plugin's runtime behavior.

  • The plugin writes a log file to /tmp/omarchy-openvpn-up.log which may contain nmcli output, but it is not expected to contain secrets and is not a security issue.
  • The plugin relies on external dependencies (networkmanager, openvpn, python3, polkit, zenity) that must be installed by the user; the README's sudo command is standard package installation and not part of the plugin itself.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tug-benson/omarchy-openvpn --enable
System #bar #quickshell #security

Omarchy OpenVPN Connect

An Omarchy plugin to manage an OpenVPN connection from the bar: import multiple .ovpn profiles, authenticate with username/password and a TOTP (MFA) code via challenge/response, view a real-time traffic graph, and inspect a network info panel (tunnel IP, interface, gateway, DNS, routes, search domains).

No sudo / NOPASSWD is required — the plugin drives NetworkManager (nmcli) using the user's existing PolicyKit privileges. Credentials are passed through the environment; only the username is persisted to disk, never the password.

Preview

OpenVPN Connect panel

Features

  • Multiple profiles — import several .ovpn files, selectable from the config panel. Import is idempotent by name: re-importing reuses the existing connection instead of creating duplicates.
  • User/pass + TOTP auth — the server's dynamic challenge (CRV1) is handled by feeding the password and the raw OTP through nmcli connection up --ask on stdin (the colon-keyed challenge secret cannot be expressed via a passwd-file). The TOTP code is entered at connect time and is never stored.
  • OpenVPN Access Server compatible — works against OpenVPN Access Server (AS), which uses the same CRV1 dynamic-challenge for username/password + TOTP; the password and OTP are fed through nmcli connection up --ask exactly as above.
  • Live traffic graph — up/down throughput (mirrored ↑/↓) across the panel width.
  • Network info — status, tunnel IP, interface (e.g. tun0), gateway, DNS, search domains, routes, latency, remote endpoint.
  • Split tunnel — keep personal traffic on the physical interface (the VPN does not become the default route) while professional routes still go through the tunnel.
  • mssfix — optional mssfix 1360 for HTTPS/MTU issues.

Installation

omarchy plugin add https://github.com/tug-benson/omarchy-openvpn

Or symlink during development:

ln -s /path/to/omarchy-openvpn ~/.config/omarchy/plugins/openvpn

To remove:

omarchy plugin remove io.github.tug-benson.openvpn

Dependencies

sudo pacman -S networkmanager networkmanager-openvpn openvpn python3 polkit zenity
  • networkmanager / nmcli — manages the VPN connection (no root needed).
  • networkmanager-openvpn — the NetworkManager OpenVPN plugin; required so that nmcli connection import type openvpn can create the VPN connection. Without it the import fails (the UI will now report the error instead of failing silently).
  • openvpn (>= 2.6) — the underlying client launched by NetworkManager.
  • python3 — generates the connection config and gathers traffic/network info.
  • zenity — file picker for .ovpn import.
  • polkit — grants the user permission to modify NetworkManager connections.

Usage

  1. Click the VPN icon in the bar to open the panel.
  2. Click ⚙ to import a .ovpn, enter credentials, and enable TOTP if the server asks.
  3. Press Connect; enter the TOTP code when prompted, then connect.
  4. The traffic graph and network info appear once connected.

How it works

  • bin/omarchy-openvpn-import copies a .ovpn into ~/.config/openvpn/profiles and creates a NetworkManager connection (idempotent by name).
  • bin/omarchy-openvpn-connect applies the chosen port/protocol, mssfix and split-tunnel settings, then brings the connection up. For TOTP, the password and the raw OTP are piped to nmcli connection up --ask on stdin.
  • bin/omarchy-openvpn-disconnect brings the connection down.
  • bin/omarchy-openvpn-info reads traffic counters and network details (ip, resolvectl, nmcli) for the active tunnel device and returns them as JSON.
  • bin/omarchy-openvpn-status reports the connection state.
  • bin/omarchy-openvpn-config stores non-secret settings (selected profile, username, TOTP/mssfix/split flags); the password is never written to disk.

Layout

omarchy-openvpn/
├── manifest.json
├── BarWidget.qml        # bar icon + panel host
├── Panel.qml            # panel: title, Connect/Disconnect, graph, info, TOTP prompt
├── ConfigPanel.qml      # profile import, credentials, TOTP, split tunnel, mssfix
├── Service.qml          # shared state, polling, connect/disconnect
├── Sparkline.qml        # traffic graph (adapted from harshith.system-monitor, MIT)
└── bin/
    ├── omarchy-openvpn-status      # connection state (JSON)
    ├── omarchy-openvpn-info        # network info + traffic counters (JSON)
    ├── omarchy-openvpn-profiles    # list imported profiles
    ├── omarchy-openvpn-import      # copy a .ovpn into ~/.config/openvpn/profiles
    ├── omarchy-openvpn-remote      # extract the remote endpoint
    ├── omarchy-openvpn-static-challenge  # detect a forced static-challenge
    ├── omarchy-openvpn-config      # non-secret settings (profile, TOTP, etc.)
    ├── omarchy-openvpn-connect     # bring the connection up (handles TOTP)
    └── omarchy-openvpn-disconnect  # bring the connection down

License

MIT