Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Connections

    SSH, RDP, VNC and every other protocol MangoSSH speaks directly, with no external client to install.

    • SSH — Full terminal sessions, MangoSSH's deepest-featured protocol. Per-connection hardening covers X11 and agent forwarding, algorithm policy and session recording.
    • RDP — A built-in canvas-based client running inside the MangoSSH window — no external mstsc or xfreerdp process. Supports RD Gateway, SSH-tunnelled RDP, shared folders, smartcard and printer redirection and clipboard sharing.
    • VNC — Screen sharing to any VNC server, in the same sidebar and group system as everything else.
    • File transfer — SFTP and FTP, either standalone or as a two-pane browser bound to an already-open SSH session. A TFTP server and client are included for network gear.
    • Telnet and serial — For switches, routers and anything on a console cable.
    • Kubectl and local terminal — Kubernetes exec sessions and a plain local shell, in the same tabbed workspace.

    A session in each

    SSH — the per-session toolbar carries Files, Monitor, History, tunnelling, broadcast, recording and split view.
    RDP — rendered inside MangoSSH's own window, not an external client.
    VNC — the title bar reports the negotiated resolution and encryption. Fit scales the desktop to the pane.

    Reaching hosts you cannot route to

    A target behind a jump host connects through a bastion, and one behind a cloud broker connects through ProxyCommand — with presets for AWS SSM, GCP IAP, Cloudflare Access, Teleport, Tailscale and Azure Bastion.

    Step-by-step guides

    How to set each of these up, one task per page.

    Full detail

    Step-by-step instructions, how to check each one worked, and what to do when it did not.