The Next VPN Works Prototype: A 14-Week Beta That Puts Real AI Agents Under vpnw
The Alpha answered one question. Can a small program seal an AI agent in and control every connection it makes? On Linux, on one machine, with a stand-in agent, the answer was yes. The next prototype, the Beta, takes on the harder question: does it hold up with real agents doing real work, on the machines where agents actually run?
The Beta is planned at about 14 weeks with two or three people. It keeps the same engine and the same four commands: run, trace, guard and learn. What it adds is what real use needs, from a WireGuard route and limits on files to more systems and packages that install in one step. Then three coding agents that developers use every day work under it for four weeks.
For someone trying it, the change is easy to picture. Today you unzip the Alpha on a Linux machine and run a demo with a pretend agent. After the Beta you’d install a package, run vpnw doctor and put the agent you already use under guard, with a policy drafted from its own run.

What Gets Added
A WireGuard route, inside vpnw. Today vpnw reaches other networks only through a proxy. The Beta adds WireGuard, brought up inside vpnw’s own process with no root, no new network interface and nothing changed for other programs. An agent can join the office network on its own while the laptop stays off it. That would be the engine’s first code from outside the project, so it gets reviewed and weighed before it goes in; the goal is a binary still under 10 MB. Proxies reached over TLS come in the same step.
Limits on files. The Alpha limits the network only. The Beta adds the folders an agent may read and write, so it can’t read keys it has no business with, and the local sockets it may use. A program that needs ssh-agent would get that one socket, instead of a switch that opens all of them. The likely base is Landlock, the Linux kernel’s own sandbox for ordinary programs.
Walls that report. When a program tries to go around vpnw today, it fails quietly and the record shows nothing. The Beta tries to record those refused attempts as events, because the attempt itself is often the most useful fact in a run.
macOS. Macs have nothing like Linux’s network namespaces. The Beta tries to build the same sealed room with the system sandbox that other agent tools use on macOS, and tests it against the same list of ways out. If it can’t be made as tight as on Linux, guard stays off on the Mac and the Beta report says why. A weaker guard that looks like the Linux one would be worse than none.
One-step install. Packages for Debian and Ubuntu, Fedora and macOS, a signed archive, and a profile that lets Ubuntu run vpnw without sudo. vpnw doctor checks each of these and says what’s missing.
Recipes and CI steps. A reviewed policy and notes for each agent the Beta runs, tests of the common tools agents call, and ready-made steps for GitHub Actions and GitLab CI that fail a job on a denial and keep its record.
The Demo, for Real
The Alpha’s demo used a stand-in agent. The Beta uses three coding agents that developers use every day, from different makers and built on different language runtimes. Each one works under vpnw guard every working day for four weeks, on a laptop and in CI. Its policy starts as a draft that learn writes from a clean run, and a person reviews it.
Each agent also gets a poisoned task, like the one in the Alpha demo, carrying a canary token: a fake secret that’s worthless, but easy to spot if it ever arrives anywhere. The test passes only if the canary never arrives and the rest of the work goes through.
| What gets counted | Why it matters |
|---|---|
| Canary tokens that arrived | The one number that has to be zero |
| Real work blocked by the policy, per week | How often vpnw gets in the way. After the first review, it should hardly ever |
| Time to review a draft from learn | Whether a person will actually read it |
| Time and memory vpnw adds to each task | What the protection costs in daily use |
| Tools that fail because they ignore proxy settings | What the recipes and routes still need to cover |
Six Kinds of Machine
The Alpha ran on one Linux virtual machine with two CPUs and no IPv6. The Beta spreads out, and every Alpha measurement runs again on each machine:
| Machine | Why this one |
|---|---|
| A developer laptop with Ubuntu 24.04 | The most common Linux desktop. Ubuntu restricts the kernel feature vpnw relies on, so it tests the profile that lifts that restriction |
| A second laptop with Fedora | A newer kernel, SELinux and another package format |
| A Raspberry Pi 5 | The Alpha’s arm64 build compiles but has never run |
| A cloud virtual machine with IPv6 | The two IPv6 checks the Alpha had to skip, and a real cloud metadata service |
| CI runners on GitHub Actions and GitLab CI | Where many agents run with nobody watching |
| A Mac with Apple silicon | guard on macOS |
Fourteen Weeks
| Weeks | Work |
|---|---|
| 1 to 2 | Packages and the Ubuntu profile. The machines set up, with the Alpha’s tests and measurements run on all of them |
| 3 to 6 | The WireGuard route. The first real agent under guard on a laptop |
| 5 to 9 | Limits on files and walls that report. The CI steps |
| 7 to 10 | guard on macOS, with its own tests |
| 9 to 12 | Four weeks of daily use by three agents, and the fixes they call for |
| 13 to 14 | Beta release: packages, documentation and a report with every figure measured again |
The team is two or three people: a lead engineer, a second engineer who knows Linux isolation, and part-time help for macOS and packaging. Apart from laptops and a Mac the team already has, the machines cost well under $1,000.
What Counts as Done
- Every way out of the sandbox stays blocked on every Linux machine, x86-64 and arm64, with the IPv6 checks run on a machine that has IPv6.
- guard on macOS passes its own tests, or stays switched off with the reasons published.
- Three real agents worked under guard for four weeks, every run recorded and each canary token blocked.
- The WireGuard route works with a real WireGuard server, with its speed measured.
- The packages install on Ubuntu, Debian, Fedora and macOS, and
vpnw doctorpasses on each without sudo. - Every Alpha figure is measured again on each machine and published, and every planted bug, old and new, is caught.
- Fuzz testing runs every night with no open crash.
What Waits Until After
The Beta leaves out Windows, a graphical interface, a hosted service, UDP and QUIC, and the team features: shared policies, logs kept centrally, managed exits and settings pushed to every machine. Those team features are where the money is, and they only make sense once the engine has proven itself with real agents. The Beta’s job is that proof, and the first conversations with teams who’d pay for the rest. The roadmap has the full plan, and the Alpha page has what exists today.
If the Beta works, the prototype after it is the one people pay for.