Islandr
master
master
v
0.0.0
Islandr
Self-hosted WireGuard management platform. Peer lifecycle, RBAC access control, nftables enforcement.
Info
Context views
Container views
Component views
Deployment views
Dependencies
Decisions
Admin
[Person]
Manages
peers,
users,
roles,
resources,
and
ACLs
(Felix).
End
User
[Person]
Manages
own
devices
and
views
access
list
in
plain
language
(Lena).
OIDC
Provider
[Software
System]
Authenticates
users.
Microsoft
365
or
Google
Workspace.
WireGuard
[Software
System]
Linux
kernel
VPN
module.
Managed
via
wg
CLI.
nftables
[Software
System]
Linux
kernel
packet
filter.
Enforces
ACL
rules
generated
by
Islandr.
Cloudflare
/
Reverse
Proxy
[Software
System]
Fully
optional
edge
layer
—
Cloudflare,
or
a
self-hosted
reverse
proxy
(Caddy,
nginx,
Traefik).
Islandr
terminates
TLS
itself
(dummy
cert
until
an
admin
uploads
one,
hot-swapped
at
runtime)
and
can
be
reached
directly
with
no
proxy
of
any
kind
in
front
of
it
(ADR-0015).
Resource
Host
[Software
System]
A
machine
behind
the
VPN
inside
a
site
(e.g.
an
RDP
server).
For
browser-based
RDP
the
hub
connects
to
it
directly
over
TLS
and
relays
to
the
browser.
Islandr
[Software
System]
Self-hosted
WireGuard
management
platform.
Peer
lifecycle,
RBAC
access
control,
nftables
enforcement.
Uses directly (built-in TLS)
[HTTPS]
Uses directly (built-in TLS)
[HTTPS]
Uses (optional path)
[HTTPS]
Uses (optional path)
[HTTPS]
Forwards to (optional layer)
[HTTP or HTTPS]
Verifies ID tokens via OIDC / JWKS
[HTTPS]
Configures peers
[wg CLI]
Generates and atomically reloads ACL ruleset
[nft CLI]
Proxies browser RDP over TLS (RDCleanPath)
[TCP/TLS]
System Context View: Islandr
C4 Level 1 — System Context
Show legend
Person,
Admin
Person,
User
Software
System
Software
System,
External
Relationship
Admin
[Person]
Manages
peers,
users,
roles,
resources,
and
ACLs
(Felix).
End
User
[Person]
Manages
own
devices
and
views
access
list
in
plain
language
(Lena).
OIDC
Provider
[Software
System]
Authenticates
users.
Microsoft
365
or
Google
Workspace.
WireGuard
[Software
System]
Linux
kernel
VPN
module.
Managed
via
wg
CLI.
nftables
[Software
System]
Linux
kernel
packet
filter.
Enforces
ACL
rules
generated
by
Islandr.
Cloudflare
/
Reverse
Proxy
[Software
System]
Fully
optional
edge
layer
—
Cloudflare,
or
a
self-hosted
reverse
proxy
(Caddy,
nginx,
Traefik).
Islandr
terminates
TLS
itself
(dummy
cert
until
an
admin
uploads
one,
hot-swapped
at
runtime)
and
can
be
reached
directly
with
no
proxy
of
any
kind
in
front
of
it
(ADR-0015).
Resource
Host
[Software
System]
A
machine
behind
the
VPN
inside
a
site
(e.g.
an
RDP
server).
For
browser-based
RDP
the
hub
connects
to
it
directly
over
TLS
and
relays
to
the
browser.
Islandr
[Software
System]
Self-hosted
WireGuard
management
platform.
Peer
lifecycle,
RBAC
access
control,
nftables
enforcement.
Uses directly (built-in TLS)
[HTTPS]
Uses directly (built-in TLS)
[HTTPS]
Uses (optional path)
[HTTPS]
Uses (optional path)
[HTTPS]
Forwards to (optional layer)
[HTTP or HTTPS]
Verifies ID tokens via OIDC / JWKS
[HTTPS]
Configures peers
[wg CLI]
Generates and atomically reloads ACL ruleset
[nft CLI]
Proxies browser RDP over TLS (RDCleanPath)
[TCP/TLS]
Person,
Admin
Person,
User
Software
System
Software
System,
External
Relationship
System Context View: Islandr [
svg
|
png
|
puml
] [legend:
svg
|
png
|
puml
]