Filtering processHow a query gets resolvedStrict-by-default fallbackThe castWhere each entity is documentedVerify it in the code
What is WardenOne install, every device coveredDifferent rules for different devicesYour data stays on your hardwareOne config filePart of purge.ccWhere Warden fits
Declarative configurationFile and folder structureThe master fileMerge rulesThe CLI writes the same filesHot reload — full re-read, atomic swap
Project principlesNo registration neededOpen codeSingle binary, zero dependenciesBuilt in RustNative TUI, not GUISecurity as a cornerstone
Security by DesignDefense in depthDevices can’t escape to a public resolverExternal lists are sandboxedSafe by defaultAppend-only audit logDaemon runs sandboxed, not as root
InitializeWhat this step doesInteractive modeNon-interactive mode (--yes)What it writesCLI referenceWhat it creates
Basic configurationThe base pathWhere Warden reads the configBefore you reloadBeyond the base pathSee also
Create profilesWhat this step doesDecide which lists applyCreate a profileOne-off exceptions don’t need a profileProfiles are flatCLI reference
Create labelsWhat this step doesDeclare a vocabularyUse it on a deviceDisambiguate a shared idRemoving a labelThe TOML form
Custom rulesWhat this step doesTwo ways to write your own ruleCustom lists, end to endAdmin rulesWhich one winsCLI reference