Products
Mistborn
Mistborn is a self-hosted virtual private cloud platform and Web UI that helps you run collaboration and private services behind a secure network boundary.
It secures self-hosted services with firewalling, WireGuard VPN access, DNS filtering (Pi-hole + DNSCrypt), and optional IP filtering.
Mistborn is modular: you can enable only the services you want, when you want them.
- WireGuard
- Pi-hole
- DNSCrypt
- Firewall
- MFA
- Self-hosted apps
What Mistborn is
Mistborn started as a way to protect a family's devices on untrusted networks, then grew into an easy button for private connectivity, safer browsing, and self-hosted collaboration. It combines secure access, network-wide DNS protection, and optional modules like file sharing, chat, video conferencing, and home automation without handing your data to a third party.
Core capabilities
WireGuard VPN for secure connectivity
Multi-factor access flow (MFA) option
Firewall and IP filtering for exposure control
Network-wide DNS filtering with Pi-hole + DNSCrypt
Reverse proxy routing for services (Traefik)
Optional SIEM/IDS integrations (Wazuh, Suricata)
Optional modules
Enable only what you need. Services can be started and stopped independently.
Collaboration
- Nextcloud
- Rocket.Chat
- OnlyOffice
Sync & storage
- Syncthing
Security & privacy
- Tor
Home & edge
- Home Assistant
- RaspAP (alpha/experimental)
Media
- Jellyfin
Remote access
- Apache Guacamole
How it works
- Connect securely with WireGuard.
- Filter DNS at the network level (Pi-hole + DNSCrypt).
- Restrict exposure with firewalling and optional IP filtering.
- Access services behind the private boundary (only what you enable).
Try it
If you want to evaluate Mistborn quickly, start with a clean Debian host (community docs recommend Debian 12) and run the installer. For deeper configuration and module enablement, see the GitLab project and install guide.
git clone https://gitlab.com/cyber5k/mistborn.git
sudo -E bash ./mistborn/scripts/install.sh Who it's for
- Families and prosumers who want safer browsing and private access anywhere.
- Small teams that want self-hosted collaboration behind a private network.
- Builders who want an integrated bundle instead of stitching together many projects.
FAQ
Is Mistborn open source?
Yes. Mistborn is published openly with an MIT license.
Is it only a WireGuard UI?
No. WireGuard is core, but Mistborn also layers DNS protection, firewalling, and optional self-hosted modules you can enable.
Do I have to enable everything?
No. Modules are optional. Enable only the services you want.
Where are the docs?
GitLab is the source of truth; the install guide is a good quickstart for setup and DNS configuration.
Want to use Mistborn in a team setting?
If you're evaluating Mistborn for a distributed team or want guidance on architecture and deployment patterns, reach out.
Press & Independent Coverage
Mistborn has been independently featured by respected Linux and open-source communities.
- Linux Pro Magazine (Nov 2020)
- Awesome Open Source (Jul 2020)
- DB Tech (May 2021)