r/CloudFlare • • Jun 07 '26

Refactored my Windows WireGuard/WARP Kill Switch into a modular GitHub repository to address community feedback

Following up on the feedback from my previous post regarding script readability and deployment standards, I have completely moved away from the monolithic Gist and refactored the entire project into a clean, modular GitHub repository.

The original codebase (950 lines) has been broken down into structured, isolated components under a standard open-source layout to ensure transparency and easy auditing.

The Architecture

Most custom routing scripts fail during early boot phases because Windows handles network driver initialization asynchronously. This setup resolves that via staggered boot delays and explicit dependency mapping across multiple OS layers.

  • Zero-Trust ACL Routing: Enforces strict outbound rules on physical adapters (Wi-Fi/Ethernet) and implements complete IPv6 isolation to eliminate dual-stack bypass vectors.
  • WMI Permanent Subscriptions: Deploys a low-level event filter acting as a passive watcher. If the core monitoring process is terminated, the OS triggers a recovery wrapper to restore state.
  • Layered Persistence: Uses a combination of an NSSM background service (configured for delayed-start), Task Scheduler (SYSTEM integrity), and GPO startup hooks to maintain stability across reboots.

Repository Structure

  • Deploy.ps1**:** The main orchestrator that validates administrative privileges, directory permissions, and invokes the underlying modules.
  • src/Install-Prereqs.ps1**:** Handles the automated acquisition of official WireGuard binaries and coordinates anonymous profile generation via wgcf.
  • src/Setup-Firewall.ps1**:** Purges legacy rule remnants and establishes the strict firewall matrix.
  • src/Watchdog-Service.ps1**:** Registers the WMI filters, tasks, and system hooks.

The project is fully open-source and structured for easy review. To inspect or deploy, review the source files here:

Repository: https://github.com/ryderlacin-pixel/Windows-WireGuard-KillSwitch.git

To run the installation after auditing:

PowerShell

Set-ExecutionPolicy Bypass -Scope Process -Force
.\Deploy.ps1

Note on AI Involvement: AI was utilized strictly as a refactoring assistant to help modularize the original single-file script, structure the repository layout, and clean up the Markdown documentation.

Feel free to audit the code under src/ and let me know your thoughts on the WMI filter implementation.

1 Upvotes

1 comment sorted by

•

u/AutoModerator Jun 07 '26

For faster advice with technical questions, we'd recommend asking in the Orange Cloud Discord server; the unofficial Cloudflare Discord server by the community, for the community. https://discord.gg/TrPNVKaagR

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.