Skip to content

About

Self-hosted family internet access control for OpenWrt routers: LuCI app, Android companion, emergency-useful access, and AdGuard Home/Podkop-friendly flow.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

631 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Sheepfold logo

Sheepfold Family Internet Control

Русский | English

Automatic cloud configuration backups are temporarily unavailable. Use the safe manual export in router Settings. Journal snapshot uploads remain separate. Current limitations · Review decisions (Russian).

Project presentation

Encrypted parent-app bug reports · Legacy LuCI channel: Yandex Cloud + YDB

How official IPK and OpenWrt APK packages are built

Sheepfold is a family internet access control system for an OpenWRT router.

It is being built as an OpenWRT router application with a LuCI web interface, backend service, Android companion app named Sheepfold, and messenger bot integration for managing household internet access.

Installation

The installer performs the first-run questions, detects AdGuard Home/Podkop, downloads the matching package from the latest stable release, and installs it with the native OpenWrt package manager: .ipk through opkg on 24.10 and older, or an OpenWrt .apk through apk v3 on 25.12 and newer. It first asks for application language (ru by default, en for English), country profile, the Sheepfold product, user-agreement consent, and automation mode. Maximum automation is the default and applies the coherent recommended profile for new-device access, full detection, automatic system groups, and identity monitoring. Selective automation exposes the individual choices in LuCI and starts with reduced device detection.

wget -O /tmp/sheepfold-install.sh https://raw.githubusercontent.com/kva4991/luci-app-sheepfold-family-internet-control/main/install.sh &&
sh /tmp/sheepfold-install.sh

Update

The parent Android app has a separate Information → App update button. It checks published parent APK releases and asks Android to confirm installation. See the update and release guide for signing requirements and current availability. This does not update the router package.

After the OpenWrt package is installed, the update script delegates to the installed Sheepfold updater. The updater checks the latest stable GitHub Release, compares versions, downloads the package format used by the current OpenWrt release, validates its internal metadata, and installs it only when a newer version is available.

Optional Participate in beta testing at the bottom of General settings enables hourly automatic updates from those published releases after confirmation and Save. It also enables SIM/new child Wi-Fi notifications, without enabling new location collection. It is off by default. See the beta-testing contract.

wget -O /tmp/sheepfold-update.sh https://raw.githubusercontent.com/kva4991/luci-app-sheepfold-family-internet-control/main/update.sh &&
sh /tmp/sheepfold-update.sh

Uninstall From OpenWRT

The uninstaller removes the OpenWRT package, keeps Sheepfold settings and client lists, and prints a report of remaining router settings.

wget -O /tmp/sheepfold-uninstall.sh https://raw.githubusercontent.com/kva4991/luci-app-sheepfold-family-internet-control/main/uninstall.sh &&
sh /tmp/sheepfold-uninstall.sh

Project Names

  • GitHub repository: luci-app-sheepfold-family-internet-control
  • OpenWRT package: luci-app-sheepfold-family-internet-control
  • LuCI EN: Sheepfold Family Internet Control
  • LuCI RU: Sheepfold : контроль доступа в интернет для семьи
  • Android app: Sheepfold
  • Android package: app.sheepfold.android

Goals

  • Manage internet access for home devices through an OpenWRT router and its LuCI web interface.
  • Provide an Android companion app with quick actions and widgets.
  • Support Telegram/VK messenger bot controls, with VK as the default first-run choice and MAX as an experimental adapter.
  • Keep device allowlists, blocklists, schedules, temporary access tokens, and access to emergency-useful sites.
  • Sync device names and static IP addresses with the OpenWRT router DHCP static leases.
  • Work safely with fw4 / nftables.
  • Coexist with AdGuard Home and Podkop.

Target Android Scope

Both Android applications target Android 9.0 Pie / API 28 and newer.

Older Android versions are intentionally out of scope.

Target OpenWRT Scope

Sheepfold targets modern OpenWRT routers with firewall4 / nftables.

Legacy firewall3 / iptables support is intentionally out of scope. The expected installation targets are reasonably recent routers and firmware builds, for example devices in the class of Xiaomi Mi Router AX3000T.

Planned Traffic Flow

  1. Sheepfold decides whether a device is allowed to access the network.
  2. Allowed DNS traffic can continue through AdGuard Home.
  3. Allowed and filtered traffic can then continue through Podkop routing.

The project should not break AdGuard Home, Dnsmasq, Podkop, sing-box, or standard OpenWRT firewall rules.

Rule Priority

  1. Blocklisted devices are always blocked.
  2. Allowlisted devices are never blocked by global/schedule rules.
  3. One device must not be present in both allowlist and blocklist.
  4. Temporary access tokens must not bypass the blocklist.
  5. Schedules apply only to devices that are not allowlisted or blocklisted.

Repository Layout

package/luci-app-sheepfold-family-internet-control/  OpenWRT package skeleton
android/                                             Android companion app
bot/                                                 Telegram/VK bot adapters, experimental MAX
docs/                                                Product and technical docs
install.sh                                           Router installer entrypoint
update.sh                                            Router updater entrypoint
uninstall.sh                                         Router uninstaller that preserves settings

Status

This repository is an experimental build, not a stable release. LuCI and the router backend already implement device access control, schedules, secure Android pairing, site-list integration, and basic Telegram control. Before a stable release, the project still requires the documented live OpenWrt/integration matrix, physical Android validation, and an owner-controlled production signing key.

See:

Support

If you find Sheepfold useful and want to support development, see Donation.

License

MIT License.

Local r297 audit and regression evidence.

About

Self-hosted family internet access control for OpenWrt routers: LuCI app, Android companion, emergency-useful access, and AdGuard Home/Podkop-friendly flow.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages