Islandr

Self-hosted WireGuard management platform. Peer lifecycle, RBAC access control, nftables enforcement.

ID Date Status Title
1 30-05-2026 Accepted Quarkus as the backend framework
2 30-05-2026 Accepted Vue 3 frontend without the npm toolchain
3 30-05-2026 Accepted nftables replaces ufw on the hub VM
4 30-05-2026 Accepted SQLite for dev, PostgreSQL for prod
5 30-05-2026 Accepted Firewall enforcement stays on the hub VM; no UCG API access from the hub
6 30-05-2026 Accepted Resource-level ACL with NIST RBAC0
7 30-05-2026 Accepted Private-key retention policy (instance-wide, two modes in v1)
8 30-05-2026 Accepted Runtime settings live in the database, not in application.properties
9 01-06-2026 Accepted License: EUPL-1.2
10 04-06-2026 Accepted Font and icon asset self-hosting
11 06-06-2026 Accepted Process privilege model: unprivileged user + scoped sudo for nft and wg
12 06-06-2026 Accepted Docker deployment via Unix socket proxy (v1 line, 0.11.0)
13 10-07-2026 Accepted Default "Everyone" role with auto-membership
14 10-07-2026 Accepted Device discovery by unprivileged TCP-connect scan of a site's own CIDR (0.12.0)
15 19-07-2026 Accepted Built-in TLS termination (no mandatory reverse proxy)
16 19-07-2026 Proposed Daily-aggregated storage for the peer activity heatmap, not raw time series
17 19-07-2026 Proposed Split tunnel lists all known networks, not just the peer's current grants
18 20-07-2026 Proposed WebSocket-tunnel fallback for WireGuard traffic (wstunnel-inspired)
19 21-07-2026 Accepted ACME (Let's Encrypt) auto-provisioning via a hand-rolled client, not a library
20 26-07-2026 Accepted DNS-01 challenge support, with a manual no-API-token mode alongside Cloudflare
21 26-07-2026 Accepted World-map topology view: air-gapped SVG projection, manual geocoding only
22 28-07-2026 Accepted ACL grants by resource type within a site, additive-only, always all-ports
23 02-08-2026 Accepted Resource-name DNS resolver: hand-rolled UDP/TCP server, not a library