I have binary program named wstunnel.
That program has no option to specify outgoing traffic. By default it will use ens3. I expect the program will use warp interface.
I'm not sure iptables can solve this, if we make ALLOW rule to warp interface exclusively for wstunnel, the process/program doesn't care whether it's exclusive for him or not.