<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Chris</title>
    <description>The latest articles on DEV Community by Chris (@chriscohnen).</description>
    <link>https://dev.to/chriscohnen</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4032526%2F1fac19ff-3cc0-4518-a272-eef0ef9f4e09.png</url>
      <title>DEV Community: Chris</title>
      <link>https://dev.to/chriscohnen</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/chriscohnen"/>
    <language>en</language>
    <item>
      <title>Introducing islandr: Self-Hosted WireGuard Access Management Without the SaaS Tax</title>
      <dc:creator>Chris</dc:creator>
      <pubDate>Tue, 04 Aug 2026 15:03:15 +0000</pubDate>
      <link>https://dev.to/chriscohnen/introducing-islandr-self-hosted-wireguard-access-management-without-the-saas-tax-2hka</link>
      <guid>https://dev.to/chriscohnen/introducing-islandr-self-hosted-wireguard-access-management-without-the-saas-tax-2hka</guid>
      <description>&lt;p&gt;I've used WireGuard on my homelab for years, mostly through PiVPN — run a command, add a peer, hand someone a QR code. Raw WireGuard is excellent, but PiVPN gets you tunnels, not access control. Past two or three peers the real problem shows up: who has what keys, who's authorized to reach what, who do you revoke when someone leaves?&lt;/p&gt;

&lt;p&gt;The market answer is: pay for Tailscale, or wrestle with a complex self-hosted stack. Neither sat right — I didn't want my traffic routed through someone else's control plane, and I didn't want a Kubernetes-grade setup for a dozen peers.&lt;/p&gt;

&lt;p&gt;So I built &lt;strong&gt;&lt;a href="https://islandr-gateway.net" rel="noopener noreferrer"&gt;islandr&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Problem with Existing Options
&lt;/h2&gt;

&lt;p&gt;If you've tried to self-host WireGuard management, you know the landscape:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Tailscale / Headplane / NetBird&lt;/strong&gt;: great UX, but SaaS-dependent or still complex to operate&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Headscale&lt;/strong&gt;: solid, but requires separate ACL tooling and has a learning curve&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;WireGuard alone&lt;/strong&gt;: you end up maintaining handcrafted config files and a mental model of who-has-what&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;What I wanted was straightforward: a single binary I could drop on a €1 VPS, point at WireGuard, and get user management, group-based ACLs, and a self-service portal — with zero cloud dependency.&lt;/p&gt;

&lt;p&gt;islandr is that binary.&lt;/p&gt;




&lt;h2&gt;
  
  
  What islandr Does
&lt;/h2&gt;

&lt;p&gt;islandr runs as a &lt;strong&gt;hub-and-spoke VPN manager&lt;/strong&gt;. Your public VM (the hub) runs both WireGuard and islandr. Peers — road warriors, home devices, site gateways — connect to the hub through encrypted tunnels.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe4swkf7174tt8hd7eks4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fe4swkf7174tt8hd7eks4.png" alt="islandr hub dashboard — peers, status, and live topology" width="800" height="570"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;On top of that, islandr gives you:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;User accounts&lt;/strong&gt; with local auth or OIDC (Microsoft 365 or Google — one provider active at a time)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Group-based ACLs&lt;/strong&gt; with per-port resource rules, enforced via nftables&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Self-service portal&lt;/strong&gt; — users enroll their own devices, download configs, scan QR codes, rotate keys, no admin required for routine tasks&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Device discovery&lt;/strong&gt; — scan a site's own CIDR to map what's reachable and adopt real hosts as resources in one click&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Browser-based RDP&lt;/strong&gt; via IronRDP WebAssembly, directly in the UI&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Geo map&lt;/strong&gt; — a world map dashboard tab showing where your gateways and sites actually are&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit logging&lt;/strong&gt;, config import/export, bulk operations&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj7b81tx4yaw7vdm702d6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fj7b81tx4yaw7vdm702d6.png" alt="Self-service portal — a user enrolling a device and downloading its config by QR code" width="800" height="512"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It's targeted at teams of 5–50 people or serious homelabbers who've outgrown flat key distribution but don't need enterprise mesh networking.&lt;/p&gt;




&lt;h2&gt;
  
  
  Getting Started
&lt;/h2&gt;

&lt;p&gt;Two ways in: install the native binary on a Linux box with WireGuard and nftables for full enforcement, or &lt;code&gt;docker run&lt;/code&gt; the container to click around the UI first (enforcement runs degraded without the host socket proxy — details in the &lt;a href="https://github.com/chriscohnen/islandr/blob/main/docs/install.md" rel="noopener noreferrer"&gt;install guide&lt;/a&gt;).&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;ARCH&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="nb"&gt;uname&lt;/span&gt; &lt;span class="nt"&gt;-m&lt;/span&gt; | &lt;span class="nb"&gt;sed&lt;/span&gt; &lt;span class="s1"&gt;'s/x86_64/amd64/;s/aarch64/arm64/'&lt;/span&gt;&lt;span class="si"&gt;)&lt;/span&gt;
curl &lt;span class="nt"&gt;-fsSL&lt;/span&gt; &lt;span class="s2"&gt;"https://github.com/chriscohnen/islandr/releases/latest/download/islandr-runner-linux-&lt;/span&gt;&lt;span class="k"&gt;${&lt;/span&gt;&lt;span class="nv"&gt;ARCH&lt;/span&gt;&lt;span class="k"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;-o&lt;/span&gt; /tmp/islandr
&lt;span class="nb"&gt;sudo install&lt;/span&gt; &lt;span class="nt"&gt;-m&lt;/span&gt; 0755 /tmp/islandr /usr/local/bin/islandr
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;From the UI you create a WireGuard interface, add users and groups, generate peers with QR-code enrollment, and wire up ACL rules — WireGuard config and nftables rules are applied automatically as you go.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmrb70yoi7pr2tp3hy991.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fmrb70yoi7pr2tp3hy991.png" alt="Group-based ACL matrix — which groups reach which resources, applied atomically" width="800" height="512"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Under the Hood
&lt;/h2&gt;

&lt;p&gt;islandr is built with:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;&lt;a href="https://quarkus.io/" rel="noopener noreferrer"&gt;Quarkus&lt;/a&gt; 3 + Java 21&lt;/strong&gt; — fast startup, native-compilable via GraalVM&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SQLite&lt;/strong&gt; (lab/single-node) or &lt;strong&gt;PostgreSQL&lt;/strong&gt; (production)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vue 3&lt;/strong&gt; on the frontend, served as ES modules — no npm build pipeline, no node_modules to manage&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Direct &lt;code&gt;wg&lt;/code&gt; and &lt;code&gt;nft&lt;/code&gt; CLI invocation&lt;/strong&gt; — islandr drives the tools you already trust, it doesn't replace them&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The native GraalVM binary starts in milliseconds and runs comfortably on ARM64 (Raspberry Pi, Ampere VMs) as well as x86_64.&lt;/p&gt;




&lt;h2&gt;
  
  
  Current Status
&lt;/h2&gt;

&lt;p&gt;islandr is at &lt;strong&gt;v0.15.1, early access&lt;/strong&gt;. Core functionality is complete and in daily use — I'm treating this release as a hardening and feedback phase before a stable 1.0. Beyond what's covered above, that includes built-in TLS with automatic Let's Encrypt certs and a connection activity heatmap so a device gone quiet stands out at a glance.&lt;/p&gt;

&lt;p&gt;Actively working on: documentation depth, edge case hardening, and a stable API contract.&lt;/p&gt;




&lt;h2&gt;
  
  
  Try It
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;GitHub&lt;/strong&gt;: &lt;a href="https://github.com/chriscohnen/islandr" rel="noopener noreferrer"&gt;github.com/chriscohnen/islandr&lt;/a&gt; — source, releases, and issue tracker&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Homepage&lt;/strong&gt;: &lt;a href="https://islandr-gateway.net" rel="noopener noreferrer"&gt;islandr-gateway.net&lt;/a&gt; — overview and deployment docs&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Feedback&lt;/strong&gt;: open an issue or reach out directly — early adopter input shapes what gets built next&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you've been running WireGuard the hard way and wanted a management layer that stays on your infrastructure, give islandr a try. It's the tool I wanted to find before I had to build it.&lt;/p&gt;

</description>
      <category>wireguard</category>
      <category>selfhosted</category>
      <category>homelab</category>
      <category>vpn</category>
    </item>
  </channel>
</rss>
