Features
Everything to run WireGuard for a team — in one binary.
Manage peers, users, group-based access and self-service from one console. Real WireGuard and nftables underneath — self-hosted, no SaaS control plane, no config files emailed around.
The core
Stop hand-editing a config for every device.
Past a handful of peers, raw WireGuard turns into a spreadsheet of who holds which key and who may reach what. Islandr replaces that with users, groups and per-resource rules — then generates and applies the WireGuard config and the nftables ruleset for you.
What you get
One console for the whole access layer.
Everything below runs on your server. No seat licences, no external control plane, no vendor account.
Peers & devices
Add client and site peers in the UI: IP suggestion from the WG subnet, CIDR-overlap checks, keys generated server-side or imported. No more editing wg0.conf by hand.
Group-based access
Decide who reaches what. Put users in groups and grant access per resource and port — real segmentation instead of “everyone reaches everything” on a flat network.
Self-service portal
Users enroll their own devices: QR code, .conf download, rotate keys — no admin ticket for routine tasks. They only see what they're allowed to reach.
Real WireGuard & nftables
It drives the tools you already trust — wg/wg-quick and nftables — not a new overlay protocol. Rules apply atomically when you save. Auditable, standard, yours.
Device discovery
Point Islandr at a site and it scans that subnet, resolves names by reverse DNS, and lets you adopt what's really there as resources in one click — instead of typing IPs and ports.
Auth & identity
A local recovery admin plus OIDC for Microsoft 365 and Google — one provider active at a time. Provider config lives in the DB and is editable at runtime, no restart.
Audit & operations
An audit log of who changed what, config import/export, and bulk actions on peers and resources — the everyday operations a growing setup needs.
Native delivery
A Quarkus GraalVM binary that starts in milliseconds and runs under systemd on x86_64 and ARM64 — one file, no JVM at runtime. SQLite for the lab, PostgreSQL for production.
Who it's for
Sized for small teams and homelabs — not the enterprise.
Islandr is VPN management plus role-based access in one binary — for teams of 5 to 50 who self-host on a small VM, a home server or bare metal, and don't want a control plane calling home.
It is not Zero Trust and not an enterprise SASE product. It is the calm, right-sized option for people who want to own the whole stack — real WireGuard, self-hosted.
- Small team (5 – 50), self-hosted stack
- Multiple sites or remote workers behind CG-NAT
- Need users, groups and ACLs — not just keys
- Microsoft 365 or Google for identity (OIDC)
- Want one binary — no npm, no JVM at runtime
- Need peer-to-peer mesh (use Tailscale/ZeroTier)
- Need enterprise compliance certs or SSO beyond OIDC
- Running hundreds of peers or dozens of admins
Solid network security, without the enterprise overhead. Islandr encrypts every connection with WireGuard®, segments access by group, and enforces rules at the hub — fully under your control, no vendor in the loop.