Network

Mullvad VPN without a store

Keep locked Mullvad VPN only — not Mullvad Browser (that is a different, looser house browser). Same wizard as IVPN / Proton. Watched and healed with every other vendors{} key.

Secure default. ujust install-mullvad option 1: import their WireGuard file. No extra daemon, no extra repo. Flathub stays off. Firewalld stays on.

  1. WireGuard import (recommended)

    ujust install-mullvad

    Account number (no email) → WireGuard config generator → download .conf. GNOME: keep the filename ≤ 15 characters. Then Settings → Network → VPN → Import, or nmcli connection import type wireguard file …. Keep Mullvad DNS. No Trivalent DoH. VPN without DNS leaks.

  2. Official app only if you need their GUI

    Option 3 adds their Fedora repo (gpgcheck=1) and layers mullvad-vpn. Extra RPM origin. After reboot, enable mullvad-daemon if it is not already running.

  3. What we will not automate

    Snap, Flathub wrappers, Mullvad Browser (use *-trivalent), COPR repacks. Search GNOME for “Mullvad” after the next overlay bake (generated launcher + this wizard).

From the vendor list (watched and healed twice a day). ujust install-vendor NAME or Setup → Strict apps. Group: mullvad.

Probe: ujust check-vendor-installers. New app = stanza in vendor-installers.json, not a one-off tutorial fork.