Network
IVPN without a store
Keep locked IVPN (ivpn.net) is a VPN. AntiTracker and multi-hop live in their official app — they do not ship Mail/Pass/Drive. Same wizard pattern as Proton and stock ujust install-steam.
Secure default. ujust install-ivpn option 1: import their WireGuard file in Network Settings. No extra daemon, no extra repo, no Snap. Flathub stays off. Firewalld stays on.
-
WireGuard import (recommended)
ujust install-ivpnSign in at ivpn.net → VPN Accounts → WireGuard → download a
.conf. GNOME rejects filenames longer than 15 characters (“Cannot Import VPN”). Then Settings → Network → VPN → Import, or:nmcli connection import type wireguard file /path/to/short.confKeep the VPN’s DNS. Do not enable Trivalent DoH. If you customized Unbound:
ujust dns-selector→ system default. See also VPN without DNS leaks. -
Official CLI / UI only if you need in-app AntiTracker
Option 3 follows their Silverblue doc: HTTPS Fedora repo (
gpgcheckchecked), thenrpm-ostree install ivpn, optionalivpn-ui, reboot, thenrun0 systemctl enable --now ivpn-service. That is an extra RPM origin. Weaker than WireGuard; stronger than Snap. -
What we will not automate
Snap (
snap install ivpn), a GUI store, turning off firewalld for their UFW kill-switch notes, unfiltered Flathub. Search GNOME/KDE for “IVPN” to open this wizard.
From the vendor list (watched and healed twice a day).
ujust install-vendor NAME or Setup → Strict apps. Group: ivpn.
- IVPN WireGuard (
ivpn_account, recommended) — WireGuard import. No extra daemon.ujust install-vendor ivpn_account - IVPN official CLI/UI repo (
ivpn_repo, asked) — Official repo after you accept gpgcheck=1.ujust install-vendor ivpn_repo
Probe: ujust check-vendor-installers. New app = stanza in vendor-installers.json, not a one-off tutorial fork.