Documentation

How to set up juist and use each of its features, step by step.

Basics

How juist works
The ideas the other pages build on, in plain words, from the network and its devices to freshness.
Install
Install juist's released package on Debian, Ubuntu, Fedora or FreeBSD, check the download, or build the package from the source.
Your first network
Create a network on one device, invite a second one, and check that the two reach each other.
Inviting devices
Add a device to the network with a code or a link, compare the four words, and give it a role as it joins.
Android
Install juist's Android app, join a network with a phone by its QR code or code, and see from the phone how each device is reached.

Everyday use

Status and devices
See whether a device is connected, which devices are in the network, and every change made to it.
Managing without sudo
Name the local user who manages a device, so that juist commands run without sudo.
Names
Reach devices by name instead of address, and have public names lead to a member through the tunnel.
Removing a device
Take a device out of the network on every device, and know how soon each one drops it.

Admins and networks

Several admins
Add admins and admin keys, set how many must approve a change, and approve the changes that wait for you.
Several networks
Put one device in several networks at once, and tell juist which one a command is about.
Renaming and renumbering
Give the network or a device another name, move its devices' IPv4 addresses, or end the network, on every device at once.
Access policy
Say which device may open what on which, which exit nodes and subnets each may use, and keep the rest of the network apart.
Keys
Give a device new keys, start a device over, deal with a lost device, back up admin keys, and know what cannot be undone.

Routing traffic

Exit nodes
Send a device's internet traffic through another member of the network, and let a member carry it for the others.
Subnet routers
Reach the LAN behind one member, such as a printer at home, from every device of the network.
Relays and ports
Give the network a relay for devices that cannot reach each other, open the right ports, and run without public helpers.
HTTPS alone
Reach your network from a hotel's, a company's or a school's network that lets nothing out but HTTPS, through your relays on 443, and through a proxy where there is one.
Publishing services
Make a service on one of your devices, such as a NAS at home, reachable from the internet by name.

Design

Architecture
How juist is built, layer by layer, in what sense it is zero trust, and what it takes from WireGuard and Tailscale.
Compared with others
How juist differs from other mesh VPNs, with a central server and without one, and when one of them fits better.
Security
Whom juist trusts and whom it does not, where the keys live, and what it accepts on purpose.

Help

Troubleshooting
What juist status says when something is wrong, what it means, and the command that fixes it.