Requirements
Gateway
honk runs on Linux as root. It loads eBPF programs, creates the dae0 link and the daens namespace, and changes sysctls, so keep a second way into the machine, such as a console, during the first start.
- Linux 6.12 or later. honk rejects an older kernel before it attaches anything.
- The kernel options below. Desktop and server distributions usually enable them; OpenWrt, Armbian and VyOS need checking.
- cgroup v2 for
pname(...)rules. Without it honk starts, and process-name routing stays off. - bpffs mounted at
/sys/fs/bpf. - CA certificates, such as the
ca-certificatespackage. Without them honk stops with “subscription network startup failed”. - With
geoiprules on a honk build beforedebug.2026.9.28.native-api.4, use at least 512 MB RAM: the older OpenWrt test ran out of memory during a geodata update on a 256 MB VM. From that build on, honk streams geodata updates to disk. For OpenWrt, keepMIMALLOC_PURGE_DELAY=0in the procd service.
uname -r
zcat /proc/config.gz 2>/dev/null || cat /boot/config-$(uname -r)
CONFIG_BPF=y
CONFIG_BPF_SYSCALL=y
CONFIG_BPF_JIT=y
CONFIG_CGROUP_BPF=y
CONFIG_NET_CLS_BPF=y|m
CONFIG_NET_SCH_INGRESS=y|m
CONFIG_NET_CLS_ACT=y
CONFIG_NET_NS=y
# Held-first-packet UDP (NFQUEUE, on by default) also needs:
CONFIG_NF_TABLES=y|m
CONFIG_NF_TABLES_INET=y
CONFIG_NETFILTER_NETLINK_QUEUE=y|m
CONFIG_NFT_QUEUE=y|m
Mount bpffs if the system does not:
sudo install -d -m 0755 /sys/fs/bpf
mountpoint -q /sys/fs/bpf || sudo mount -t bpf bpf /sys/fs/bpf
mountpoint /sys/fs/bpf
# To mount it at boot, add this line to /etc/fstab:
# bpf /sys/fs/bpf bpf defaults 0 0
honk version
- Only builds from the
feat/native-apibranch of Glassyiris/honk and its rollingdebugrelease have the native API. On that branch,native-apiis an opt-in build feature; release anddebugbuilds include it. doona beta.12 attachesdebug.2026.9.30.native-api.5(commit25377686).HONK-SOURCE.txtin each doona release from beta.8 onward names its honk tag and commit. - Builds of daeuniverse/honk
mainhave no native API. honk rejects everynative_apisetting asunknown experimental setting, and/apiand/ui/answer 404. - A build from
feat/native-apiwithout thenative-apifeature stops startup withnative-api feature is requiredwhennative_apiis enabled. - Early
feat/native-apibuilds update geodata but have no configurable sources. The builds attached to doona beta.8 and beta.9 have both.
Run honk-core --version to check the installed binary. To check the running version, use the Engine card on Overview or the bottom of the side navigation.
Browser and build
| Component | Requirement |
|---|---|
| Backend | An engine implementing the native API contract pinned in SOURCE.md, with its API listener enabled |
| Browser | Chrome or Edge 120, Firefox 121, Safari 17 or later. These are the CSS build targets; the JavaScript target is ES2022. Automated tests use Chromium, and CI adds WebKit |
| Build | Node ^22.18.0 || ^24.0.0 || >=26.0.0 and pnpm 11.15.1, only to build doona from source; GNU tar, gzip and sha256sum for the archives |