Products

Mistborn

Mistborn is a self-hosted virtual private cloud platform and Web UI that helps you run collaboration and private services behind a secure network boundary.

It secures self-hosted services with firewalling, WireGuard VPN access, DNS filtering (Pi-hole + DNSCrypt), and optional IP filtering.

Mistborn is modular: you can enable only the services you want, when you want them.

  • WireGuard
  • Pi-hole
  • DNSCrypt
  • Firewall
  • MFA
  • Self-hosted apps

What Mistborn is

Mistborn started as a way to protect a family's devices on untrusted networks, then grew into an easy button for private connectivity, safer browsing, and self-hosted collaboration. It combines secure access, network-wide DNS protection, and optional modules like file sharing, chat, video conferencing, and home automation without handing your data to a third party.

Core capabilities

Web UI to enable and manage services

WireGuard VPN for secure connectivity

Multi-factor access flow (MFA) option

Firewall and IP filtering for exposure control

Network-wide DNS filtering with Pi-hole + DNSCrypt

Reverse proxy routing for services (Traefik)

Optional SIEM/IDS integrations (Wazuh, Suricata)

Optional modules

Enable only what you need. Services can be started and stopped independently.

Collaboration

  • Nextcloud
  • Rocket.Chat
  • OnlyOffice

Sync & storage

  • Syncthing

Security & privacy

  • Tor

Home & edge

  • Home Assistant
  • RaspAP (alpha/experimental)

Media

  • Jellyfin

Remote access

  • Apache Guacamole

How it works

  1. Connect securely with WireGuard.
  2. Filter DNS at the network level (Pi-hole + DNSCrypt).
  3. Restrict exposure with firewalling and optional IP filtering.
  4. Access services behind the private boundary (only what you enable).

Try it

If you want to evaluate Mistborn quickly, start with a clean Debian host (community docs recommend Debian 12) and run the installer. For deeper configuration and module enablement, see the GitLab project and install guide.

git clone https://gitlab.com/cyber5k/mistborn.git
sudo -E bash ./mistborn/scripts/install.sh

Who it's for

  • Families and prosumers who want safer browsing and private access anywhere.
  • Small teams that want self-hosted collaboration behind a private network.
  • Builders who want an integrated bundle instead of stitching together many projects.

FAQ

Is Mistborn open source?

Yes. Mistborn is published openly with an MIT license.

Is it only a WireGuard UI?

No. WireGuard is core, but Mistborn also layers DNS protection, firewalling, and optional self-hosted modules you can enable.

Do I have to enable everything?

No. Modules are optional. Enable only the services you want.

Where are the docs?

GitLab is the source of truth; the install guide is a good quickstart for setup and DNS configuration.

Want to use Mistborn in a team setting?

If you're evaluating Mistborn for a distributed team or want guidance on architecture and deployment patterns, reach out.

Contact

Press & Independent Coverage

Mistborn has been independently featured by respected Linux and open-source communities.