CLI tool
EasyTier/EasyTier avatar
EasyTier/EasyTier

EasyTier: a decentralized mesh VPN in Rust, and what its shared-node model costs you

A simple, decentralized mesh VPN with WireGuard support.

13,858 stars1,407 forksRustLGPL-3.0

At a glance

What is it?
EasyTier builds a peer-to-peer mesh from statically linked binaries with no central controller, and falls back to community-run relay nodes when NAT traversal fails. Here is how the mechanism works, how to bring up two nodes, and where the design stops being the right choice.
Who is it for?
Adopt EasyTier if you want a peer-to-peer overlay you can stand up from a single binary and you accept that the free shared nodes are community infrastructure with no documented SLA. Do not adopt it if you need per-user identity, device posture checks or an audit trail, because the README describes network-name and network-secret as symmetric values shared by every node.
Can I use it commercially?
Yes, with conditions. LGPL-3.0 is a weak copyleft licence: you can use it inside commercial and closed-source software, but if you distribute changes to its own files, you must publish those changes under the same licence.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

The problem EasyTier solves, and the people it is aimed at

The README frames EasyTier as "a simple, secure, decentralized virtual private network solution powered by Rust and Tokio". The operative word is decentralized. Nodes are described as equal and independent, with no centralized services required. That matters for a specific audience: people who want a flat overlay network across machines they own, where no vendor account, control plane or login sits between them and their peers.

Typical fits are a homelab spanning a home router, a VPS and a laptop; a small team connecting a few servers that already trust each other; or anyone who wants a stable private address range across machines on unrelated networks. The repository also ships easytier-gui, easytier-web, an Android JNI binding and an iOS target, so the project is not only a headless daemon.

The audience it does not target is the enterprise access broker. There is no mention of single sign-on, per-device certificates, device posture or audit logging. Trust in EasyTier is a shared secret, not an identity system.

How the mesh actually forms: listeners, peers and relay fallback

A node started with sudo easytier-core -i 10.144.144.1 listens on TCP 11010, UDP 11010 and WebSocket 11011 by default, according to the README. Peers are supplied with the -p flag, and each entry is a scheme plus address plus port, for example tcp://<SharedNodeIP>:11010 or udp://<SharedNodeIP2>:11010.

Once two nodes can see each other, the README states that they automatically attempt NAT traversal and establish P2P connections. When that fails, data is relayed through shared nodes. This is the part worth understanding before you deploy: relay is a fallback path, not a separate product tier, and it is what keeps the network usable when both peers sit behind unfriendly NAT.

Routing is described as latency-priority with automatic route selection, and the link layer supports TCP, UDP, WSS and WireGuard protocols. Encryption is AES-GCM or WireGuard, and the README claims this prevents man-in-the-middle attacks. The stated NAT traversal support covers UDP and IPv6 and claims to work with NAT4-NAT4 networks. For lossy links, KCP or QUIC proxying is offered as a way to trade some overhead for better behaviour under packet loss.

The topology is therefore not a star. Any node that can reach any other node can join, and the network is identified by a name and secret pair rather than by a server address. That is the whole design, and it is also where its security properties come from and stop.

Installing EasyTier and bringing up two nodes

The README gives several install paths. On Linux it recommends a shell installer; on Windows a PowerShell one run as administrator; Homebrew covers macOS and Linux through the brewforge/chinese tap; and there is a cargo path for the latest development version. Prebuilt binaries for all supported platforms are linked from the releases page.

Linux install:

bash
curl -fsSL "https://github.com/EasyTier/EasyTier/blob/main/script/install.sh?raw=true" | sudo bash -s install

On macOS or Linux via Homebrew, the README installs the GUI rather than the core CLI:

bash
brew tap brewforge/chinese
brew install --cask easytier-gui

For a first real network without any public IP of your own, use a shared node. Both machines need the same network name and secret, and the README warns to pick something more complex than the example to avoid collisions with other users:

bash
sudo easytier-core -d --network-name abc --network-secret abc -p tcp://<SharedNodeIP>:11010

Run that on both nodes, then inspect the result with easytier-cli. The README shows a table with columns for ipv4, hostname, cost, lat_ms, loss_rate, rx_bytes, tx_bytes, tunnel_proto, nat_type, id and version. The row for the local node shows cost Local; a healthy peer shows cost p2p with a small latency figure, while a peer reached through the public server shows a higher latency and a cost of p2p against the relay entry. That cost column is the first thing to read: if your peers never leave the relay, the mesh is not doing what you installed it for.

To test reachability, ping the assigned addresses directly:

bash
ping 10.126.126.1
ping 10.126.126.2

The README notes that a failed ping is often the host firewall blocking inbound traffic, and suggests disabling it or adding allow rules. If you want redundancy, pass more than one -p flag to connect to several shared nodes at once. To run it in the background on boot, the project documents a one-click service registration guide rather than a unit file in the README itself.

Where EasyTier is the wrong tool

The shared-secret model is the first boundary. Every node that joins needs the same --network-name and --network-secret. Anyone who learns those two values can join the network, and the README offers no per-node credential, no revocation list and no way to distinguish one member from another. Rotating the secret means reconfiguring every node. For a two-person homelab that is fine. For a company where laptops are lost, it is not a workable access control story.

Relay dependency is the second boundary. The README describes the shared nodes as free nodes provided by the EasyTier community. It does not describe an uptime guarantee, a capacity limit or a privacy policy for relayed traffic. If your P2P path never establishes, your payloads traverse infrastructure you do not operate, and the documentation does not tell you who runs it or what they can see. You can avoid this by operating your own reachable node, but the README does not present that as a required step; it presents shared nodes as the quick path.

The third boundary is operational. The README does not document rollback, version pinning or an upgrade procedure for an existing mesh. Three releases landed between 2026-04-26 and 2026-05-12, which suggests a fast-moving project, and the cargo install path explicitly pulls the latest development version rather than a tagged release. If you need a frozen version with a documented compatibility matrix, this is not that kind of project yet.

Finally, the project targets an unusual toolchain baseline: the workspace declares edition 2024 and rust-version 1.95. Building from source on a distribution-provided Rust toolchain will likely fail, which is why the prebuilt binaries are the recommended path.

EasyTier compared with Tailscale and ZeroTier

Tailscale and ZeroTier both appear in the repository topics, and the comparison is the obvious one. The difference is where coordination lives. Tailscale and ZeroTier route membership through a hosted coordination service: you authenticate an account, the control plane distributes keys and tells peers how to reach each other, and access rules are evaluated centrally. EasyTier removes that layer. There is no account, and the network is defined by a name and secret rather than by an identity provider.

That trade is symmetrical. You gain the ability to run a mesh with no third-party account and no dependency on someone else's control plane being up. You lose the things a control plane provides: per-user identity, device approval, ACLs, and an audit trail of who joined when. EasyTier's answer to reachability is the shared node pool and NAT traversal rather than a coordination server, which is a different mechanism with different failure modes.

Against WireGuard alone, the difference is scope. WireGuard is a tunnel between configured endpoints; you supply the peer addresses and keys, and it does nothing about discovery or traversal. EasyTier builds the overlay on top, offering WireGuard as one of its supported link protocols and handling peer discovery and NAT traversal itself. If your peers all have stable public endpoints, plain WireGuard is simpler and has fewer moving parts. EasyTier earns its complexity when peers move or sit behind NAT.

There is also easytier-web in the workspace, which suggests a web management surface, and the README links a hosted web console at easytier.cn/web. The repository does not document in the README whether that console is required for any part of the mesh, so treat the CLI path as the one the README actually walks you through.

Licence and the cost of keeping up

EasyTier is licensed under LGPL-3.0. For most users running easytier-core as a separate process on their own machines, this is unremarkable. The obligation becomes relevant if you redistribute the binaries or link the Rust crates into your own product, because LGPL-3.0 carries requirements about source availability and relinking that differ from permissive licences. The repository ships easytier-ffi and easytier-android-jni crates, so embedding is clearly an intended use, which makes the licence worth reading before you build it into something you ship. This is not legal advice; check with someone qualified if you plan to redistribute.

Upgrade cost is the other ongoing expense. The workspace pins a Rust 1.95 baseline with edition 2024, and the release cadence shown by the published versions is three releases in roughly two weeks. The last push to the repository was on 2026-09-19. There is no documented migration guide, no stated support window for older releases, and no rollback procedure in the README. In practice that means pinning a specific release and reading its release notes before moving, rather than tracking main. Running the cargo install command in the README will give you the development version, which is the opposite of what you want on a production mesh.

Editorial conclusion

Adopt EasyTier if you want a peer-to-peer overlay you can stand up from a single binary and you accept that the free shared nodes are community infrastructure with no documented SLA. Do not adopt it if you need per-user identity, device posture checks or an audit trail, because the README describes network-name and network-secret as symmetric values shared by every node. Before rolling it out, verify three things: that your firewall permits inbound traffic on TCP and UDP 11010 and WebSocket 11011, that your peers actually reach p2p in the easytier-cli table rather than sitting on relay, and that LGPL-3.0 obligations are acceptable to whoever distributes the binaries.

Frequently asked questions

What is EasyTier used for?

It builds a decentralized virtual private network across machines, with no centralized service required. Nodes are equal, and each one joins by using the same network name and secret, then attempts NAT traversal to establish P2P connections.

How does EasyTier compare with ZeroTier?

Both create an overlay network, but EasyTier's README describes nodes as equal and independent with no centralized services required, while ZeroTier relies on a coordination layer. EasyTier identifies a network by a shared name and secret rather than by an account.

How does EasyTier compare with WireGuard?

WireGuard is a tunnel between endpoints you configure yourself, with no discovery or NAT traversal. EasyTier supports WireGuard as one of its link protocols and adds automatic NAT traversal, latency-priority routing and subnet proxy on top of it.

Official sources

  1. EasyTier/EasyTier on GitHub
  2. License: LGPL-3.0
  3. Project website
  4. README
  5. Releases
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/easytier-easytier.svg)](https://hysenlabs.com/projects/easytier-easytier)
Community notes

Community notes