Open source · macOS 13+

Turn your Mac into a
whole-home gateway.

OpenSurge is a Surge-style macOS gateway and control plane powered by mihomo. Route phones, TVs, consoles, and other devices through one observable, recoverable network path.

Open source · GitHub · Apple Silicon and Intel

ONE MAC · MANY DEVICES · INDEPENDENT ROUTES
OpenSurge Control
OpenSurge whole-home gateway dashboard
Gateway readyTUN activeDevices observed
3network topologies
1auditable control plane
IPv4 / IPv6experimental
GPL3.0-only

NETWORK CONTROL, NOT APP SETTINGS

Proxy the household at the gateway layer

Devices such as game consoles and TVs cannot run the same proxy client as a Mac. OpenSurge moves routing policy to the Mac gateway so downstream devices use ordinary IP networking.

01

DHCP & DNS gateway

Start with selected-device bypass routing, take over LAN DHCP when you are ready, or serve an isolated downstream network.

Explore gateway modes
02

Per-device routing

Give a phone, TV, PS5, or VR headset a dedicated selector while keeping local and private traffic direct.

See device policy
03

mihomo control plane

Import compatible proxies and rules while OpenSurge retains ownership of gateway-critical DNS, TUN, and recovery state.

Understand the architecture

START SMALL, SCALE DELIBERATELY

One product, three clearly distinguished network topologies

The setup changes with the network you actually control. All three topologies start with IPv4 and can optionally enable experimental IPv6 takeover. OpenSurge explains the operational impact before it changes DHCP, routes, or advertisements.

V0.2.2 · MORE WAYS TO CONNECT

Reach further. Prepare before you start.

Connect to your Tailnet, or build your own routes without importing a subscription.

OpenSurge Tailscale setup with private targets and an Exit Node; fictional demo data

Give selected devices access to your Tailnet

Reach private services through a managed Tailscale or Headscale node. Choose a configured remote Exit Node when you need an internet route, too.

Outbound access; the local LAN is not advertised to the Tailnet.Explore Tailscale outbound
OpenSurge prepared policy configuration while the gateway is stopped; fictional demo data

Prepare your policies before going live

Add nodes, groups and rules through Global Extension. With the gateway stopped, preview the composed policies, select nodes and test latency—no imported subscription required.

Start from the Web GUI to validate and apply the configuration.Build and preview a configuration

Screenshots use isolated fictional demo data. Open an image to see it at full size.

Per-device routing controls

ONE ENGINE, DEVICE-SCOPED POLICY

A PS5 can choose a region while the TV chooses a streaming route

OpenSurge compiles stable device identity into source-scoped mihomo rules. Mac-local mode stays independent, and the connection view shows the outbound chain that traffic actually used.

Read the PS5 gateway guide

WIND ROSE · EXPERIMENTAL IPV6

Two ingress paths. One policy model.

Bring IPv6 connections into the same device rules and outbound choices. Automatic or manual client setup connects to a dedicated macOS packet path, with TCP and UDP forwarding through mihomo.

Explore the IPv6 architecture
Wind Rose IPv6 artwork

BUILT FOR NETWORKS THAT MUST RECOVER

Validation is part of the product story

Unit tests protect business rules. Virtual LAN labs exercise DHCP, DNS, TUN, NAT, rollback, and topology-specific IPv6 paths. Public claims stay bounded by the evidence that was actually collected.

Explore the Virtual Lab design
01Unit & configuration tests
02Virtual host-network lab
03Topology-specific device evidence

Make the Mac the network control point.

Start with one device, verify the path, and expand only when the topology is ready.