Files

3.6 KiB

yt-downloader

Download a single YouTube video through an isolated Mullvad WireGuard tunnel.

Built as the video equivalent of music-gatherer's download phase: the only thing that talks to YouTube is the download command, and when a WireGuard config is configured it re-runs itself inside a dedicated network namespace whose only egress is the tunnel — so YouTube never sees your home IP. Everything else on your machine stays on the normal network.

Install

pip install -e .

Requires yt-dlp (pulled in automatically) and ffmpeg (used to mux separate video + audio streams into a single file).

Usage

yt-downloader init                 # write a starter config
yt-downloader download <url>       # download one video (auto-wraps into the VPN)
yt-downloader vpn up               # create the namespace + bring the tunnel up (sudo)
yt-downloader vpn status           # handshake time, routes, DNS
yt-downloader vpn down             # tear it all down

Download options:

yt-downloader download <url> -q 720                 # quality preset
yt-downloader download <url> -q best                # best video+audio (default)
yt-downloader download <url> -q audio               # audio only (no muxing needed)
yt-downloader download <url> -q 1080 -o ~/Videos    # custom output dir
yt-downloader download <url> -f 'bestvideo[height<=480]+bestaudio'   # raw yt-dlp format

Quality presets: best, 1080, 720, 480, audio. The -f/--format flag takes any yt-dlp format string and overrides the preset.

Downloads through a Mullvad VPN

By default downloads go through your normal connection. To route only the yt-dlp traffic through a WireGuard (Mullvad) tunnel, give the tool a WireGuard config:

[vpn]
wireguard = "~/.config/yt-downloader/mullvad.conf"   # Mullvad .conf
# namespace = "mullvad"   # optional: network namespace name
# interface = "mv0"       # optional: WireGuard interface name

When set, yt-downloader download re-runs itself inside a dedicated network namespace whose only egress is the WireGuard tunnel. The namespace has no fallback route, so a dead tunnel means a failed download, never a leak. Bring-up is automatic (ensure_up); use yt-downloader vpn up/down/status to manage it by hand.

It uses a Mullvad .conf ([Interface] + [Peer]), which you get from mullvad.net; the private key is copied into /etc/wireguard/mv0.conf.

Requirements: Linux, wireguard-tools + iproute2, and sudo. Interactive runs prompt for the sudo password once; for unattended runs add passwordless sudo entries:

# /etc/sudoers.d/yt-downloader   (run: sudo visudo -f /etc/sudoers.d/yt-downloader)
magerbeton ALL=(root) NOPASSWD: /usr/bin/ip, /usr/bin/wg, /usr/bin/wg-quick, \
  /usr/sbin/iptables, /usr/sbin/sysctl, /bin/mkdir, /bin/rm, /bin/chmod, /bin/sh

The download process drops back to your user inside the namespace, so downloaded files stay owned by you.

Bot-check mitigation

YouTube sometimes challenges downloads. Like music-gatherer, you can pass your browser cookies to yt-dlp:

[download]
# cookies_file = "/path/to/cookies.txt"
# cookies_from_browser = "firefox"   # e.g. chromium, firefox, safari

Configuration

See yt_downloader.toml after init for the full template (~/.config/yt-downloader/).

[download]
out = "~/Videos/yt-downloader"   # where videos land
quality = "best"                 # best | 1080 | 720 | 480 | audio
# format = ""                    # raw yt-dlp -f string, overrides quality

[vpn]
# wireguard = "~/.config/yt-downloader/mullvad.conf"
# namespace = "mullvad"
# interface = "mv0"