Your devices, one private network.你的设备,连成一张私有网络。
Skein Mesh connects your devices directly, encrypted end to end, and coordinated by a control server you run yourself. It is cross-platform and keeps working behind NAT, strict firewalls and networks that throttle UDP. Skein Mesh 让你的设备之间端到端加密直连,由你自己运行的控制服务器统一协调。跨平台,在 NAT、严格的防火墙和限制 UDP 的网络里照样可用。
Everything a private network needs, on hardware you own.私有网络需要的一切,跑在你自己的机器上。
Direct, encrypted links端到端加密直连
Each pair of devices talks over its own Noise IK session. Identity comes from short-lived certificates signed by your own CA.每对设备之间都是独立的 Noise IK 会话,身份来自你自己 CA 签发的短期证书。
Through NAT, with a relay behind it穿透 NAT,有中继兜底
Devices connect through a relay right away, then switch to a direct path as soon as hole punching succeeds.设备先经中继立即连通,打洞成功后自动切到直连。
Works over port 443走 443 端口也能用
When UDP is blocked or throttled, traffic moves to TLS on port 443 and the connection stays up.UDP 被封或被限速时,流量自动改走 443 端口的 TLS,连接不中断。
Exit nodes with split routing出口节点与分流
Send traffic for chosen domains or address ranges through an exit node. Everything else stays on its usual path.只把指定域名或地址段的流量交给出口节点,其余流量照常走。
Web dashboardWeb 管理面板
Approve devices, revoke certificates, review routes, follow traffic and read the audit log in one place.审批设备、吊销证书、审核路由、查看流量和审计日志,都在一个地方。
Join with a link or QR code链接或二维码加入
Open a join link or scan a code on the new device, check the verification code, approve it, and it is on the network.在新设备上打开加入链接或扫码,核对验证码并审批,设备就上线了。
From a fresh server to a working network in three steps.从一台新服务器到可用的网络,只要三步。
-
Set up your control server部署控制服务器
skein-server initasks a few questions, creates your CA and prints the first join link.skein-server init问几个问题,生成你的 CA,并打印第一个加入链接。 -
Add your devices加入设备
Run
skein up --joinwith the link, or scan the QR code in the app.用链接运行skein up --join,或在 app 里扫二维码。 -
Approve and connect审批并连通
Approve the device in the dashboard. It receives a certificate and finds its peers on its own.在管理面板里审批,设备拿到证书后自动找到其他节点。
# control server $ sudo skein-server init … Join link: skein://join?… $ sudo systemctl enable --now skein-server # every other device $ sudo skein up --join 'skein://join?…' node up
In active development.正在积极开发中。
Downloads and documentation will be published on this site.下载与文档将在本站发布。