Network

IVPN without a store

Keep locked IVPN (ivpn.net) is a VPN. AntiTracker and multi-hop live in their official app — they do not ship Mail/Pass/Drive. Same wizard pattern as Proton and stock ujust install-steam.

Secure default. ujust install-ivpn option 1: import their WireGuard file in Network Settings. No extra daemon, no extra repo, no Snap. Flathub stays off. Firewalld stays on.

  1. WireGuard import (recommended)

    ujust install-ivpn

    Sign in at ivpn.net → VPN Accounts → WireGuard → download a .conf. GNOME rejects filenames longer than 15 characters (“Cannot Import VPN”). Then Settings → Network → VPN → Import, or:

    nmcli connection import type wireguard file /path/to/short.conf

    Keep the VPN’s DNS. Do not enable Trivalent DoH. If you customized Unbound: ujust dns-selector → system default. See also VPN without DNS leaks.

  2. Official CLI / UI only if you need in-app AntiTracker

    Option 3 follows their Silverblue doc: HTTPS Fedora repo (gpgcheck checked), then rpm-ostree install ivpn, optional ivpn-ui, reboot, then run0 systemctl enable --now ivpn-service. That is an extra RPM origin. Weaker than WireGuard; stronger than Snap.

  3. What we will not automate

    Snap (snap install ivpn), a GUI store, turning off firewalld for their UFW kill-switch notes, unfiltered Flathub. Search GNOME/KDE for “IVPN” to open this wizard.

From the vendor list (watched and healed twice a day). ujust install-vendor NAME or Setup → Strict apps. Group: ivpn.

Probe: ujust check-vendor-installers. New app = stanza in vendor-installers.json, not a one-off tutorial fork.