New connections wait for your answer.

Peephole is an outbound application firewall for Linux desktops. It holds each new connection, shows which program, which host and which port, and asks you once.

Get notifiedHow it works

A decorative feed of example outbound connections runs behind this section. Each row shows a program, a destination, a protocol and a status such as held, allowed by rule or blocked. When you answer the demo alert, your answer is added to the feed.

Interactive demo: answer the alert, then watch the feed.

Interactive demo loads here.

The top of the Peephole alert: curl, started by Ghostty, wants to connect to api.github.com on port 443.
A new connection is held and the alert asks: curl wants to reach api.github.com on port 443.
The Lasts menu open, listing Once, 1 minute, 15 minutes, 1 hour, Until the app quits, Until logout, Until restart and Forever.
Lasts sets how long your answer holds, from Once to Forever.
The Started by chain for python3 running sync.py: the app first, then the programs that started it, nearest first.
More opens the details, including the chain of programs that started this one.
Your rules, listing the earlier Allow answer for curl.
Your answer is saved as a rule, listed here under Your rules.
  • held
  • allowed
  • blocked

Anatomy of the alert

Nine parts. Point at a label or a part of the alert to read what it does.Nine parts. Each number on the alert matches an entry in the list below it.

An example alert, a curl connection to api.github.com. Its nine parts are numbered 1 to 9 and listed below.
  1. Program

    The program asking. A rule is about an executable, a Flatpak app by its app ID, or an interpreter running a specific script, such as python3 running sync.py.

  2. Destination

    Which host and which port. If the hostname is unknown, the alert shows the IP address and its reverse-DNS name, labelled Unverified.

  3. Applies to

    How far the answer reaches: any connection, only this domain, this domain and port, or only this port.

  4. Lasts

    How long it holds: Once, Forever, Until quit, Until logout, Until restart, or 1 minute, 15 minutes, 1 hour.

  5. Match

    Spells out what the chosen scope matches, for example domain github.com, so you see the rule before you commit to it.

  6. More

    Opens the details: the program's path and the process tree that started it, then the connection's hostname, IP address, port and protocol.

  7. Countdown

    If nobody answers, the alert blocks automatically after 60 s by default. You can set it to allow instead. The time runs down inside the Block button.

  8. Block

    Rejects the connection, so the program fails at once instead of hanging.

  9. Allow

    Lets the connection through, for the scope and duration you chose.

The interactive alert loads here. The part descriptions are below it.

Program

The program asking. A rule is about an executable, a Flatpak app by its app ID, or an interpreter running a specific script, such as python3 running sync.py.

Destination

Which host and which port. If the hostname is unknown, the alert shows the IP address and its reverse-DNS name, labelled Unverified.

Applies to

How far the answer reaches: any connection, only this domain, this domain and port, or only this port.

Lasts

How long it holds: Once, Forever, Until quit, Until logout, Until restart, or 1 minute, 15 minutes, 1 hour.

Match

Spells out what the chosen scope matches, for example domain github.com, so you see the rule before you commit to it.

More

Opens the details: the program's path and the process tree that started it, then the connection's hostname, IP address, port and protocol.

Countdown

If nobody answers, the alert blocks automatically after 60 s by default. You can set it to allow instead. The time runs down inside the Block button.

Block

Rejects the connection, so the program fails at once instead of hanging.

Allow

Lets the connection through, for the scope and duration you chose.

What happens to a new connection

  1. Your desktop makes connections you never see.

    Programs open connections all the time, and most are ordinary.

    Examples
    A browser, a package manager, a sync script, even a single ping
    Asks permission
    Almost never
    Without Peephole

    Connected, never asked

  2. Peephole pauses each new connection until you answer.

    The alert shows the program, the host and the port.

    If there's only an IP
    The alert adds its reverse DNS name, marked Unverified
    If you block
    The app gets an error right away instead of hanging
    If you don't answer
    Blocked after 60 seconds. You can make it allow instead.
    Held
    curlstarted by Ghostty

    wants to connect to api.github.com on port 443

    python3 running sync.pystarted by Konsole

    wants to connect to 203.0.113.45 Unverified on port 8443

    Reverse DNS: host-45.example.net

    Blocks automatically in 60 sBlockAllow
  3. You choose the scope, and how long it lasts.

    The alert spells out the exact rule before you answer.

    Applies to
    Any connection, a domain, a domain and port, or a port
    Lasts
    Once, 1, 15 or 60 minutes, until quit, logout or restart, or forever
    Tied to
    The executable, the Flatpak app ID, or the script an interpreter runs
    Try it
    curl wants to connect to api.github.com on port 443
    Applies to
    Lasts

    Your rule

    curlgithub.com · Allowed · Until quitAllowed

    Allow curl to connect to github.com on any port, until no curl process is running.

  4. Then it remembers, and stays out of the way.

    Alerts queue up, and Peephole keeps a record you can review later.

    Silent modes
    Silent Allow and Silent Block skip the alert but still log every connection
    Review
    Past connections, grouped. Any group can become a rule.
    When no one can answer
    Blocked by a temporary rule and tagged with why, like Before login
    Waiting alerts · 1 waiting, 1 answered

    Waiting

    • ssh198.51.100.88 · port 2239 s

    Answered

    • ping192.0.2.1 · ICMPAllowed once
    Review · tagged with the reason
    • python3 running sync.py198.51.100.23 · port 443Before login
    • ssh203.0.113.7 · port 22Full-screen app

    Any group can become a rule.

  5. It is safe to run on the machine you use every day.

    Peephole is a system service that enforces from boot.

    If the service stops
    Traffic keeps flowing (fail-open). You can choose fail-closed instead.
    To turn it off
    sudo peephole stop opens the network at once
    Resource use
    Next to nothing on an idle desktop
    From power-on
    1. 1Power on
    2. 2peepholed starts and enforcesShips rules for systemd-resolved, systemd-timesyncd and NetworkManagerEnforcing
    3. 3The network comes up
    4. 4You log inThe agent can now ask

    Before login, with no one to answer, new connections are blocked and tagged for review.

What it covers

Rules
A rule is about one executable, one Flatpak app by its app ID, or one script run by an interpreter such as Python.
Updates
When a package update replaces a program, its rules carry over. If the file changes any other way, Peephole asks again.
Protocols
TCP, UDP, ICMP, SCTP and raw sockets, over IPv4 and IPv6.
No one there
When nobody can answer, for example before you log in, Peephole blocks new connections with a temporary rule that records why.
Desktop
Built with Qt 6 and Kirigami for KDE Plasma 6, so it follows your theme.
Moving
Export your rules to a JSON file and import them on another machine. Peephole also keeps a history of past connections.

A CLI for everything the agent does

The peephole command, also ph, has a subcommand for each part, and every one takes --json.

alex@workstation: ~
[alex@workstation ~]$ peephole status
Output of peephole status: ● Enforcing · Alert mode
  Daemon down     open: traffic passes while the daemon is down
  Prompt timeout  60 s, then block
  History         30 days, at most 100000 records
  Agent           registered for alex (uid 1000)
  Rules           3 user, 1 automatic; limit 4096 each
  Version         0.1.0
[alex@workstation ~]$ 

Requirements today

  • Desktop: KDE Plasma 6 on Wayland.
  • Distribution: Arch or an Arch-based distribution such as CachyOS or EndeavourOS.
  • Kernel: a recent kernel.

More distributions and desktops are planned.

Built with a Rust daemon (peepholed), a native Qt 6 and Kirigami desktop agent, and the peephole CLI.

Not out yet.

Peephole isn't released yet. Leave your address and we'll email you once when it's ready, nothing else.

We keep your address only for this, and you can remove it any time. Details on the privacy page.

Questions

Will it run on my distribution?

Today it needs KDE Plasma 6 on Wayland, an Arch-based distribution (Arch, CachyOS, EndeavourOS and the like) and a recent kernel. More distributions and desktops are planned.

What happens if I don't answer an alert?

After a countdown, 60 seconds by default, the alert blocks automatically. You can set it to allow automatically instead. A blocked connection is rejected, so the app fails at once instead of hanging.

What if the daemon crashes, or I need the network now?

If the daemon crashes, the network stays open (fail-open), unless you chose fail-closed. sudo peephole stop opens the network at once.

What happens when a program updates?

Peephole accepts an update from the same pacman package or Flatpak and notes it. Any other change to a program suspends its rules and asks again.

Will it slow my computer down?

No. Peephole is built to stay out of the way. It does nothing until a program opens a new connection, and once you've answered, connections you've already decided on pass straight through. When nothing new is happening, it sleeps instead of checking in the background, so on an idle desktop it uses next to no CPU, and its background service keeps a small memory footprint.

Does Peephole send anything about me anywhere?

Only what you agree to. If Peephole crashes or you report a bug, it shows you the report and sends it only if you say yes, or you can let it send reports automatically. You can also choose to share usage statistics without personal details. They are off unless you turn them on, and they are the most useful thing you can give the next version: they show which parts of the alert people rely on and where they get stuck.

Peephole never sends your rules, your connection history, or which programs and hosts it sees. Its own connections go through its own alerts like any other program's.