dnsmasq (6 new, 30.8% → 32%): - Empty instances, multiple instances, nil config, configured IP - No leaked empty entries (address=//, local=//) - Empty fields don't produce broken entries Also fixed a bug: empty Domain/InternalDomain fields in commented-out entries (no LB IP case) now guarded against producing # local=// and # address=// directives. haproxy (7 new): - No HTTPS frontend with no routes - HTTP-only and L4-only route scenarios - CertsDir customization and default - Custom TCP route ports - Health check directive in L7 backends services (8 new, 72.7% → 75.8%): - Not-found errors for Get, Deregister, Update - DeregisterBySource partial match (source AND backend) - Overwrite preserves file count - Empty dir and non-YAML file handling Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Wild Central
Wild Central is a networking platform for your LAN. It manages DNS, proxy routing, TLS certificates, VPN, firewall, and dynamic DNS — providing a unified networking layer for self-hosted services.
What it does
Wild Central runs on a device on your LAN (e.g., a Raspberry Pi) and manages:
- DNS (dnsmasq) — internal name resolution, split DNS, DHCP
- Gateway (HAProxy) — L4 SNI passthrough for k8s clusters, L7 reverse proxy for HTTP services
- TLS (certbot) — certificate provisioning via Let's Encrypt DNS-01
- VPN (WireGuard) — remote access with peer management
- Firewall (nftables) — host firewall rules
- DDNS (Cloudflare) — dynamic DNS A record management
- Security (CrowdSec) — intrusion detection
- NATS JetStream — coordination bus for service registration and events
Two sources of truth
Central config drives Central's own services — its UI domain, VPN, firewall, DHCP. These are managed through Central's web UI and config file.
Service registrations drive external consumer services. Wild Cloud registers its k8s instance domains. Wild Works registers its program services. Each registration is a domain that needs routing through Central's networking stack.
See docs/registrations.md for the full registration API reference.
Quick start
# Install
apt install wild-central
# Start
systemctl enable --now wild-central
# Access the web UI
open http://<device-ip>:5055
Development
make dev # Run with live reloading (requires air)
make build # Build binary
make test # Run tests
make check # Lint + test
Environment variables
| Variable | Default | Description |
|---|---|---|
WILD_CENTRAL_ENV |
— | Set to development for dev mode (Vite proxy) |
WILD_CENTRAL_DATA_DIR |
/var/lib/wild-central |
Data directory |
WILD_CENTRAL_PORT |
5055 |
API listen port |
WILD_CENTRAL_NATS_PORT |
4222 |
NATS JetStream port |
WILD_CENTRAL_VITE_URL |
http://localhost:5173 |
Vite dev server URL |
Architecture
Wild Central (this service)
├── Config-driven: DNS, VPN, firewall, DHCP, TLS for Central's own domain
├── Registration-driven: DNS, proxy, TLS, DDNS for consumer domains
├── NATS JetStream: coordination bus
└── Web UI: management interface
Wild Cloud ──registers domains──→ Wild Central
Wild Works ──registers domains──→ Wild Central
Wild Cloud and Wild Works are separate services that register their domains with Central. Central handles all the networking — DNS resolution, proxy routing, TLS certificates, and external DNS records.