Documentation
How to set up juist and use each of its features, step by step.
Basics
- How juist works
- The ideas the other pages build on, in plain words, from the network and its devices to freshness.
- Install
- Install juist's released package on Debian, Ubuntu, Fedora or FreeBSD, check the download, or build the package from the source.
- Your first network
- Create a network on one device, invite a second one, and check that the two reach each other.
- Inviting devices
- Add a device to the network with a code or a link, compare the four words, and give it a role as it joins.
- Android
- Install juist's Android app, join a network with a phone by its QR code or code, and see from the phone how each device is reached.
Everyday use
- Status and devices
- See whether a device is connected, which devices are in the network, and every change made to it.
- Managing without sudo
- Name the local user who manages a device, so that juist commands run without sudo.
- Names
- Reach devices by name instead of address, and have public names lead to a member through the tunnel.
- Removing a device
- Take a device out of the network on every device, and know how soon each one drops it.
Admins and networks
- Several admins
- Add admins and admin keys, set how many must approve a change, and approve the changes that wait for you.
- Several networks
- Put one device in several networks at once, and tell juist which one a command is about.
- Renaming and renumbering
- Give the network or a device another name, move its devices' IPv4 addresses, or end the network, on every device at once.
- Access policy
- Say which device may open what on which, which exit nodes and subnets each may use, and keep the rest of the network apart.
- Keys
- Give a device new keys, start a device over, deal with a lost device, back up admin keys, and know what cannot be undone.
Routing traffic
- Exit nodes
- Send a device's internet traffic through another member of the network, and let a member carry it for the others.
- Subnet routers
- Reach the LAN behind one member, such as a printer at home, from every device of the network.
- Relays and ports
- Give the network a relay for devices that cannot reach each other, open the right ports, and run without public helpers.
- HTTPS alone
- Reach your network from a hotel's, a company's or a school's network that lets nothing out but HTTPS, through your relays on 443, and through a proxy where there is one.
- Publishing services
- Make a service on one of your devices, such as a NAS at home, reachable from the internet by name.
Design
- Architecture
- How juist is built, layer by layer, in what sense it is zero trust, and what it takes from WireGuard and Tailscale.
- Compared with others
- How juist differs from other mesh VPNs, with a central server and without one, and when one of them fits better.
- Security
- Whom juist trusts and whom it does not, where the keys live, and what it accepts on purpose.
Help
- Troubleshooting
- What juist status says when something is wrong, what it means, and the command that fixes it.