Several admins
An admin is a person whose key approves changes to the network. With several admins, you decide how many of them must agree before a device joins, leaves or gets a role.
What it is
Every change to the network, such as admitting a device, removing one or giving it a role, is a record in the membership log. The log is the signed list of every change, and every device checks it for itself (How juist works). A change counts once enough admins have signed it.
An admin is a person. An admin key is the key that person signs with.
It lives in their keystore, ~/.config/juist, as a file such as
admins/alice@home.key. An admin holds one key on each device they approve
from. Never copy a key to another device; create a new one there instead.
The quorum is how many votes a change needs. Each admin key has a vote, and a person’s keys cast that person’s votes once, whichever of them signs. Say alice, bob and carol are admins with one vote each, and the quorum is 2. Then any two of them can approve a change, and one of them can be on holiday. One of them alone can change nothing.
An admin is not the same as a voucher. A voucher is a device with the role
voucher that confirms every hour that the network’s state is current. A
voucher holds no admin key.
Approving from both of your laptops
Your admin name is what juist create printed on the line Admin, and what
juist admins lists. It is your login name, unless you gave --admin-name.
Use that name for the second laptop’s key; under any other name the key
becomes a second admin.
Create a key under your admin name:
juist admins new aliceIt prints the command that adds the key, with the key itself in it.
Run the command as printed:
juist admins add alice nid:… --on laptop2It prints added a key of alice's; 2 keys, 1 signing.
juist admins then lists which machine each key is on. A change that waits
for approval says where the keys are that can give it.
One key per network
Each network gets an admin key of its own, such as admins/alice@home.key.
A lost or stolen key then costs one network, and two networks’ logs share no
key.
- A key from
juist admins newis filed under the first network whose log names it.juist admins new alice --network homenames the network at once. - To govern a new network with a key you already have, say so:
juist create lab --admin-key alice@home. juist adminslists the keys on this machine and the networks each one governs.- On a machine in no network,
juist approve --key alice@home FILEsays which key signs.
Two admins, and neither decides alone
Say alice and bob each have two devices, and every change should need both of them.
Add each of bob’s keys, once for each device of his. Bob creates them with
juist admins new bob, which prints the line to run:
juist admins add bob nid:…Bob now holds two keys, which cast one vote between them.
Require both admins for every change, and two vouchers to confirm that the network’s state is current:
juist admins quorum 2
juist admins vouchers 2juist admins now shows Quorum 2 of 2 votes.
With juist admins vouchers 2, one voucher that lies about the network’s
state cannot fool a device alone. It needs one accomplice. Two vouchers must
then be online.
Alone, with two devices for every change
You can also be the only admin and still want every change to need two of your devices:
juist admins require alice 2Hold three keys for that. With exactly two, losing one device may lock the network.
When a change needs another admin
A change that needs someone else’s vote waits for them on the network’s voucher devices. You see this when you make the change:
$ juist remove phone
remove phone (198.18.36.4 fd77:9359:d9fb:bcb6:5fc:cc5c:f45d:c475) from "home"? [y/N] y
pending remove-phone.rec: needs 1 more vote, from bob on nas; another admin runs, on an admin device or with the file:
juist approve
juist approve remove-phone.rec
On bob’s device, juist status says
1 change waits for your vote: …. Bob approves it there:
$ juist approve
device removal, proposed by alice's key on laptop:
removes the device phone (nid:A7Bu6lgr…)
approve? [y/N] y
signed as bob's key on nas
applied
juist approve asks about each change waiting for your vote. It shows what
the change does from the record and the log, never from the file’s name.
Once the change has its votes, it applies on every device.
For a waiting change to reach an admin’s devices, each admin runs
juist admins receive once. The founder of a new network already has. It is
a change like any other.
Change files
The change is saved as a file too, such as remove-phone.rec, in the
directory you ran the command in. You can send it to an admin, who runs on a
device in the network:
juist approve remove-phone.recIt shows what the change does, asks, signs the file in place, and applies the
change once it is complete. juist apply does the same.
On a machine in no network, an admin can approve the admission of a device. They cannot approve anything that may change who approves or vouches: a removal, a role, an admin key, or the quorum. Only the log says whom such a change touches.
Good to know
juist adminslists every admin, their votes, the machines their keys are on, the quorum and the vouchers needed.juist admins add NAME KEY --votes Ngives a key more than one vote.juist create --admin-votes Ndoes the same for the keyjuist createmakes.juist admins remove NAME|KEYtakes a key’s vote away. It is refused if the rest cannot reach the quorum.juist admins quorumwarns when every change needs every admin, since then losing one admin’s keys locks the network.- Admin keys never leave their machine, and that machine needs no network of
its own.
juist create --no-devicemakes a network from a machine that only signs. - Run admin commands as yourself, without sudo: the keys are in your keystore.
juist logshows every change and who approved it.
Losing every key of the admins a change needs locks the network for good.
The break-glass secrets juist create writes are for a recovery that is not
implemented yet. Keep them offline anyway. Give the network more admins than
the quorum needs, each on devices of their own
(Keys).
If something goes wrong
| You see | What to do |
|---|---|
hint: for changes waiting for your vote to reach you: juist admins receive | run juist admins receive once |
hint: bob cannot read it on an admin device yet; send them the file | send bob the .rec file; he runs juist approve FILE |
juist: no admin key of this network in … | run the command where an admin’s key is |
juist: run as alice, without sudo: … | run it again without sudo |
….rec: outdated by a later change | whoever started the change makes it again |