Network
Mullvad VPN without a store
Keep locked Mullvad VPN only — not Mullvad Browser (that is a different, looser house browser). Same wizard as IVPN / Proton. Watched and healed with every other vendors{} key.
Secure default. ujust install-mullvad option 1: import their WireGuard file. No extra daemon, no extra repo. Flathub stays off. Firewalld stays on.
-
WireGuard import (recommended)
ujust install-mullvadAccount number (no email) → WireGuard config generator → download
.conf. GNOME: keep the filename ≤ 15 characters. Then Settings → Network → VPN → Import, ornmcli connection import type wireguard file …. Keep Mullvad DNS. No Trivalent DoH. VPN without DNS leaks. -
Official app only if you need their GUI
Option 3 adds their Fedora repo (
gpgcheck=1) and layersmullvad-vpn. Extra RPM origin. After reboot, enablemullvad-daemonif it is not already running. -
What we will not automate
Snap, Flathub wrappers, Mullvad Browser (use
*-trivalent), COPR repacks. Search GNOME for “Mullvad” after the next overlay bake (generated launcher + this wizard).
From the vendor list (watched and healed twice a day).
ujust install-vendor NAME or Setup → Strict apps. Group: mullvad.
- Mullvad WireGuard (
mullvad_account, recommended) — WireGuard import. No extra daemon.ujust install-vendor mullvad_account - Mullvad VPN official app repo (
mullvad_repo, asked) — Official repo after you accept gpgcheck=1.ujust install-vendor mullvad_repo
Probe: ujust check-vendor-installers. New app = stanza in vendor-installers.json, not a one-off tutorial fork.