Stock OpenWrt stays in control
The controller runs on your server, NAS, mini-PC, or Mac. Routers keep their existing firmware, LuCI, and human-managed configuration.
One self-hosted controller for visibility, adoption, safe configuration, radio planning, policy, backups, and operations across stock OpenWrt devices.
The controller runs on your server, NAS, mini-PC, or Mac. Routers keep their existing firmware, LuCI, and human-managed configuration.
Every screen separates measured values, unavailable sources, stale data, and unsupported capabilities instead of filling gaps with guesses.
Configuration is reviewed first, staged through UCI, protected by OpenWrt's rollback timer, and confirmed only after the controller reads the expected state.
See Internet health and throughput when one usable main-table WAN is proved and its exact runtime device has RX/TX history, including PPPoE, plus clients, device telemetry, topology history, radios, events, management overhead, and controller-host speed tests.
Local accounts and roles, scoped router access, encrypted stored secrets, redacted diagnostics, and no cloud broker or controller-authored router package.
Export encrypted portable backups, validate them in staging, restore through a controlled restart, and keep router writes suppressed until an owner reviews the result.
Documentation for v0.1.3
oonfeeWRT is a self-hosted controller for small OpenWrt networks. It gives a single, UniFi-inspired interface to devices that still run stock OpenWrt. The controller observes the fleet, keeps desired configuration, and makes only the changes you review and approve.
It is not firmware. Nothing is installed on a router when you start the controller, discover a device, or add an address. Adoption can create one scoped oonfeewrt login and one reviewable rpcd ACL after consent. The only optional package workflow in v0.1.3 is LLDP, with a separate plan and rollback.
Understand the fit, requirements, hardware evidence, security model, and current limitations before installing anything.
Choose a standalone binary or Docker Compose, preserve the data directory, create the first owner, and verify the controller.
Inspect capabilities first, review the scoped access payload, adopt with the minimum functions, then verify the capability report.
See which actions are read-only, which require acknowledgement, how ownership works, and what happens during rollback or recovery.
A uniquely proved, usable lowest-metric main-table IPv4 default route, exact-match runtime counters (including PPPoE), ICMP reachability, six-hour trends, recent warnings, topology summary, and bounded Cloudflare speed tests from the controller host.
On-demand IPv4 discovery, add-by-address, read-only pre-adoption inspection, independently selected Gateway/AP/Switch functions, pinned device identity, and a local sanitized compatibility-report download.
Firmware, load, memory, throughput, radio series, management overhead, adjustable polling, client presence and attribution, and a joined observability workspace.
Current and historical topology with evidence confidence, VLAN and medium filters, radio inventory, channel plans, utilization, interference, and acknowledged RF scans.
Networks, VLANs, IPv4 CIDRs, DHCP, firewall zones, WLANs, AP groups, 802.11k/v/r, mesh backhauls, wireless uplinks, and bounded per-device overrides.
Zone matrix, explicit firewall rules, port forwards, static routes, fixed client addresses, client groups, and visible compiled drafts before they enter desired state.
Redacted preview, fleet preflight, acknowledged Apply, Gateway-last ordering, OpenWrt rollback, durable operation status, ownership records, and careful un-adoption.
Owner, administrator, operator, and read-only roles; session control; audit history; stored-only redacted diagnostics; encrypted portable backups; compatibility preview; and staged restore.
See the complete capability and support matrix →


| Component | Location | Responsibility |
|---|---|---|
oonfeewrtd | Your 64-bit Linux or macOS host | UI, API, collection, desired state, encrypted secrets, SQLite history |
| Web browser | A trusted management client | Local sign-in, review, configuration, and operations |
| Stock OpenWrt | Each managed router or AP | Networking, wireless, firewall, DHCP, ubus/rpcd, rollback |
| Optional reverse proxy | Usually the controller host | Trusted TLS and secure remote access over an existing routed network or VPN |
The controller does not provide cloud access, NAT traversal, firmware, or a router-hosted agent. Remote sites need an existing management route or VPN.
oonfeeWRT v0.1.3 deliberately does not claim capabilities it cannot prove.
/22 for an unauthenticated /ubus endpoint. A bridged container may not see the LAN subnets to scan, so add devices by address.mwan3, and manual WAN selection are not modeled.Review requirements and compatibility →
The shortest safe path is to install the controller on a host that can reach your router, create the first owner, add one non-critical OpenWrt device by address, inspect it, and adopt only the functions you need.