Islandr

Self-hosted WireGuard management platform. Peer lifecycle, RBAC access control, nftables enforcement.

Admin[Person] Manages peers, users, roles, resources, and ACLs (Felix).End User[Person] Manages own devices and views access list in plain language(Lena).OIDC Provider[Software System] Authenticates users. Microsoft 365or Google Workspace.WireGuard[Software System] Linux kernel VPN module. Managedvia wg CLI.nftables[Software System] Linux kernel packet filter. EnforcesACL rules generated by Islandr.Cloudflare / Reverse Proxy[Software System] Fully optional edge layer Cloudflare, or a self-hosted reverseproxy (Caddy, nginx, Traefik). Islandrterminates TLS itself (dummy certuntil an admin uploads one,hot-swapped at runtime) and can bereached directly with no proxy of anykind in front of it (ADR-0015).Resource Host[Software System] A machine behind the VPN inside asite (e.g. an RDP server). Forbrowser-based RDP the hubconnects to it directly over TLS andrelays to the browser.Islandr[Software System] Self-hosted WireGuard managementplatform. Peer lifecycle, RBAC accesscontrol, nftables enforcement.Uses directly (built-in TLS)[HTTPS]Uses directly (built-in TLS)[HTTPS]Uses (optional path)[HTTPS]Uses (optional path)[HTTPS]Forwards to (optional layer)[HTTP or HTTPS]Verifies ID tokens via OIDC / JWKS[HTTPS]Configures peers[wg CLI]Generates and atomically reloads ACL ruleset[nft CLI]Proxies browser RDP over TLS (RDCleanPath)[TCP/TLS]
System Context View: Islandr
C4 Level 1 — System Context
Show legend
Person, AdminPerson, UserSoftwareSystemSoftwareSystem,ExternalRelationship