I built NAS Device Flow to choose which devices on my home Wi-Fi use rule-based proxy routing. The daily interaction is a switch beside each device. Shipping the first regular release, 0.1.0, made me spend more time on the path to that switch: installation, DHCP leases, and making the page explain what it actually knows.
The screenshot is a demo, with fictional devices and generated traffic.
A switch cannot repair an old gateway
The NAS runs a Linux controller and a separate Mihomo routing container. My Wi-Fi router remains the access point and upstream Internet router. For automatic onboarding, NAS DHCP advertises the routing container as the client's gateway and DNS server.
A client can retain its old gateway until it renews its DHCP lease. In my original deployment, a tablet needed to forget the Wi-Fi network and rejoin before it picked up the new configuration. Turning its proxy switch on did not change the gateway stored on the tablet.
That is why the panel separates a saved routing preference from observed gateway activity. A valid lease means the client received configuration. A sampled connection means the core saw traffic. Neither proves that a proxy request succeeded.
An address that looks tidy can still be taken
An installer can read the host interface, subnet and default route. It cannot establish that an arbitrary address is free just because a device did not answer ARP. A sleeping printer, a static assignment or a DHCP reservation can still conflict later.
In 0.1.0, I removed prefilled guesses for the core IP, panel IP and future DHCP range. Those fields start empty. Each has an explanation, and the operator checks router reservations and static devices before entering them. Validation catches invalid ranges and responsive conflicts, but does not turn silence into proof.
The two static addresses have different jobs. The core IP becomes the clients' gateway and DNS address. The panel IP opens the management page. The future DHCP pool supplies client addresses and must exclude the router, NAS, core, panel and other fixed devices. Installation leaves DHCP off; enabling it is a separate step after a single-client routing test and disabling the other DHCP servers.
Test from the client that will use the page
The temporary installer opens at the NAS management IP on port 9088. The production panel has its own macvlan address.
Linux macvlan restricts direct host-to-container communication. A failed test from a browser running on the NAS can be misleading. The installation guide now explicitly asks for a test from another device on the same LAN. Changing the NAS gateway to work around that test can create another problem.
What shipped
The main panel still puts devices first: direct or smart routing per device, upload/download charts, sampled proxy traffic in decimal MB, and subscription controls tucked away from the everyday switches. It now supports Chinese, English, Japanese, Spanish, French and Korean, plus system, light and dark appearance. The installer is Chinese/English.
The release includes a prebuilt Linux x86-64 controller image and a NAS Compose installation file. I checked 105 automated tests, container startup and isolated DHCP exchanges in CI. The image and downloadable attachments have verified checksums. Router name provenance also follows the configured adapter instead of falling back to Huawei when a source is absent.
The original deployment runs on a UGREEN DXP4800. Fresh full-LAN installations on other NAS hardware remain unverified; OpenWrt and MikroTik naming adapters have simulated tests only. This is IPv4, with no automatic gateway failover. Docker Desktop on macOS or Windows is not a supported gateway host. The included regional routing preset targets mainland China and needs review for other regions.
Source and release ยท NAS installation guide
I would like feedback on how the installer explains the network changes, especially where a label might suggest more certainty than the program has. That has been a useful lesson from building this: a simple switch still needs an honest description of the network underneath it.
This article and the implementation were developed with substantial Codex assistance under my direction. Automated tests are not an independent security audit.

Top comments (0)