Development docs, for main @ c56b482 - what's coming, not yet released. This page for v2026.10.05-5, the latest release →
User guide
Everything to run Janus: getting an image, booting and provisioning
nodes, the Controller that manages them, HAProxy, the network and the
optional extensions, and keeping a fleet running. A Janus node has no
shell and no SSH: everything here goes through the node’s mTLS API -
from the Controller’s web UI, from janusctl, or from Terraform.
Getting started
Section titled “Getting started”- Quick start - a node in a virtual machine on your workstation, configured through its API, serving HTTP: ten minutes.
- Images and extensions - the images each release publishes, and how to build one with the optional extensions you need (BGP, VRRP, firewall, Consul, Let’s Encrypt…).
- Provisioning a node - four ways to turn a blank machine into a node that registers itself with a Controller. Deploying many, on a hypervisor or bare metal: Janus in a private cloud.
The Controller
Section titled “The Controller”- The Controller - the web UI for a fleet: installing it, accounts and roles, adding nodes, backups, updates.
- Hypervisors - nodes the Controller creates itself, on libvirt/KVM or Proxmox VE.
janusctl
Section titled “janusctl”- Using janusctl - installing it, signing in to a Controller, reaching nodes; shell completion.
- janusctl reference - every command, its arguments and its flags.
- A fleet without a Controller - the
same trust model, driven from
janusctlalone.
HAProxy
Section titled “HAProxy”- Your haproxy.cfg - what to change in an existing configuration to run it on Janus.
- Files, maps and certificates - error pages, maps, ACL files and certificates next to the configuration.
- Let’s Encrypt - certificates obtained and renewed by the node itself.
Network
Section titled “Network”- Network configuration - interfaces, VLANs, routes and DNS, applied on trial and reverted unless confirmed.
- Firewall, VRRP, BGP and Consul - the optional network extensions.
Operate
Section titled “Operate”- Updating nodes - A/B updates with an automatic revert,
from the Controller or
janusctl; going back. - Metrics - the Prometheus exporter every node serves.
- Packet capture - tcpdump-style captures streamed over the API.
- Troubleshooting - where each problem shows, without a shell: registration, access, HAProxy, the network, VRRP and BGP, updates.
- Security policy - supported versions and how to report a vulnerability.