Skip to main content

WodiMask

License: Apache 2.0

WodiMask is a network identity and policy engine.

It defines how traffic behaves on the network by modeling identity, context, and intent, then producing a deterministic routing decision.

This repository contains the control layer.

What WodiMask Does

WodiMask models network behavior before execution.

Given:

  • a network identity
  • a runtime context
  • a set of policies

WodiMask produces:

  • a behavior profile
  • IP rotation intent
  • regional intent
  • logging posture
  • risk flags

The output is a RoutingDecision.

That decision is designed to be consumed by a lower execution layer.

Core Model

Network behavior should be programmable.

Traditional VPNs operate as binary tunnels: connect or disconnect.

WodiMask is built around a single flow:

Identity + Context + Policy → RoutingDecision

This flow is pure, deterministic, and testable.

Identity

Identity represents a network persona.

It encodes:

  • how stable the identity should be
  • how exposed it is allowed to be
  • which region it prefers to appear from

Identity answers one question:

How should this traffic look from the outside?

Context

Context represents what is happening right now.

It includes:

  • which app initiated the request
  • the target domain
  • the current network environment
  • time
  • risk profile

Context is evaluated per request or per session.

Policy

Policy is declarative intent.

Policies map runtime context to behavior rules.

A rule defines:

  • which profile to use
  • whether IP rotation is allowed or required
  • how much logging is acceptable

Policies contain no execution logic. They describe intent only.

Decision Engine

The decision engine is the core.

It:

  • takes identity, context, and policy
  • applies deterministic logic
  • emits a routing decision

The engine has:

  • no network access
  • no side effects
  • no hidden state

Given the same inputs, it always produces the same output.

Execution Boundary

This repository ends at decision making.

Execution is expected to happen elsewhere:

  • a local proxy
  • a tunnel adapter
  • a routing service
  • a future data plane

The control layer remains isolated by design.

Current State

  • Identity model implemented
  • Context model implemented
  • Declarative policy system implemented
  • Deterministic decision engine implemented
  • Unit tests in place

This is the foundation layer.

License

This project is License under Apache 2.0. See LICENSE for details

Author

Caleb Wodi

Metadata

Release files for wodimask 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wodimask 0.1.0
File Size Uploaded
wodimask-0.1.0.tar.gz 8.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wodimask 0.1.0
File Interpreter ABI Platform
wodimask-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 17.0 kB

Release files / wodimask-0.1.0.tar.gz

Download URL wodimask-0.1.0.tar.gz
Size 8.1 kB
Tags Source
SHA-256 checksum
How to use checksums
d3152845a2a2ff47b02ac3105c7117af9e5b815a254fd43a807569ef2de2bd3c
BLAKE2b-256 checksum
How to use checksums
d1d6fdc205c9b030fc63f863f267ec034ca69d7f2b3a9cb6672d548d13467cf5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.9

Release files / wodimask-0.1.0-py3-none-any.whl

Download URL wodimask-0.1.0-py3-none-any.whl
Size 8.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
baa970296ff5e828b70818830339b9691a9eefcc0cef599af0d4ad8b0a8af553
BLAKE2b-256 checksum
How to use checksums
5c7f1b4cd0c1735eee57dd55e59230a994ffb6aa0b8c838994fd2f25eaea3747
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.9

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page