Status and devices

Three commands tell you how things stand. juist status shows this device and what needs attention, juist devices lists every device, and juist log shows every change and who approved it.

What it is

Your network is the group of devices that belong together; each of them is a member. Every member keeps its own copy of the network’s log, the signed list of every change (see How juist works). The commands on this page read that log and ask the daemon, juistd, the program that keeps the tunnels up, how things stand right now.

Start with juist status whenever something seems wrong. It names the problem and prints a hint: line with the command that fixes it.

Checking a device

1on laptop

See whether this device is connected, and what needs attention:

juist status
$ juist status
home · connected
  This device   laptop  198.18.36.1  fd4c:8a21:e3f:5b1a:9d02:c4e7:31f8:a6b0
  Devices       3 others, all heard from
  Tunnels       3 of 3 live
  Relays        1 available, via vps
  Names         home.juist
  Freshness     vouched 12m ago, valid 48h
  Ports         udp/41643
  Updated       just now

NAME                  IPV4         IPV6                                    ROLES                   REACHED
laptop (this device)  198.18.36.1  fd4c:8a21:e3f:5b1a:9d02:c4e7:31f8:a6b0  voucher                 -
nas                   198.18.36.2  fd4c:8a21:e3f:77c0:1e4b:a923:6d05:f18e  names mail.example.org  direct
vps                   198.18.36.3  fd4c:8a21:e3f:c2d9:84f1:3b6a:e057:29dc  voucher, relay          direct
phone                 198.18.36.4  fd4c:8a21:e3f:e83:5a7d:f12c:9b46:d371   -                       relayed

The first line names the network and its state. Below come the details, the device table, and then any warnings, each with a hint.

The state on the first line is one of these:

StateMeaning
connectedeverything works
waiting for peersthere are other devices, but none has been heard from yet
no tunnel upother devices are known, but no tunnel to them carries traffic
limitedthis device’s view may be out of date, so it keeps tunnels only to vouchers (see Freshness below)
removedthis device is no longer in the network
juistd not runningthe daemon is not running; start it (see Troubleshooting)

What each line means

  • This device: its name and its addresses in the network, IPv4 first, then IPv6.
  • Devices: how many other devices there are, and how many of them have been heard from.
  • Tunnels: how many tunnels carried traffic at the last check. juistd checks every 30 seconds.
  • Relays: how many devices may relay, and which one this device uses. A relay passes traffic between two devices that cannot reach each other directly.
  • Exit node: which device carries this device’s internet traffic, if any. See Exit nodes.
  • Names: the domain under which this device finds the others, such as home.juist, or why it cannot. See Names.
  • Freshness: when a voucher last confirmed that this device’s view of the network is current, and how long that stays valid. A voucher is a device the network trusts to confirm this, every hour. After 48 hours without one, the line reads expired; vouchers only. See Removing a device.
  • Ports: the ports juistd listens on. udp/41643 is the one for the tunnels.
  • Updated: when juistd last applied the network’s state.

Lines such as Subnets, Published or Renumbering appear only while those features are in use.

Listing the devices

juist devices prints the same table on its own:

juist devices

ROLES shows what the network allows each device to do, such as voucher, relay or exit, and - for none. REACHED says how juistd reached the device at its last check:

REACHEDMeaning
directa direct tunnel works
relayedthe tunnel goes through a relay
no answerthe device did not answer: it is offline, or a firewall blocks it
offline, offline, heard 3h agothe device is most likely offline, and has said nothing since
not heard fromthe device has not announced where to reach it yet
not checked yetjuistd has not checked yet
not connectedthe device was heard from, but has no tunnel, for example while this device’s view is out of date
-this device itself

juist devices --keys adds each device’s identity key, which juist remove also accepts.

Seeing every change

$ juist log
   0  network creation                             K2JS2DNGYZWZ
      approved by alice
   1  device admission: nas                        EU7V5XCUUOSO
      approved by alice
   2  device admission: vps                        QH4T7MWD2LXA
      approved by alice
   3  change of a device's roles or subnets: vps   MMOPGHJRKJ7D
      approved by alice
4 changes

Each entry is one change, with the admins whose keys approved it. An admin is a person whose key may approve changes (see Admins). juist log verify checks the whole log again.

The daemon’s own log

journalctl -u juistd

This shows what juistd itself reports. A second network on the same device has its own daemon, juistd@juist1, with its own log.

Good to know

  • Any local user may run juist status. A user who is not root or the device’s operator sees it without the device table, followed by a read-only hint.
  • juist devices, juist log and every other command are for root and the operator.
  • On a device in several networks, juist status and juist devices show each network in turn. juist devices work shows one.

If something goes wrong

juist status puts warnings below the table, each followed by a hint: line. Troubleshooting lists the common ones and what to do.