Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Monitoring & Audit

    Know whether a host is up, what it is doing, and what happened afterwards.

    • Connection Dashboard — Reachability across every saved host, right now.
    • Monitor — Live CPU, memory, disk and network graphs on a connected host.
    • Cross-Host Compare — Configuration drift between servers that should match.
    • Audit Log — A local record of connect attempts and disconnects — host, port, username, auth method, outcome and duration. Never passwords, passphrases or keys.
    • Key Lifecycle — Certificate and key expiry across your fleet, so nothing lapses unnoticed.

    Connection Health

    Polls every saved host on an interval and keeps a per-host trend: uptime, latency, how many of its connection attempts authenticated, and how long it has been down. Alerts are off until you turn them on, and can go to a desktop notification or a Slack or Teams webhook — with a per-minute cap so one flapping host cannot become forty messages.

    Up or down per host, with uptime, latency, auth success rate and a trend bar. The webhook URL is treated as a credential — kept in the OS keychain and never shown again after saving.

    Tamper evidence

    Each audit line is hash-chained to the one before it, so any insertion, deletion or edit is detectable. Verify Integrity re-walks the chain; a reported break is worth investigating rather than dismissing.

    A failed connection records why, in full — here a private-network peer that timed out after 15s. Export, Copy and Verify Integrity sit above; the filter narrows to connection events, server events or alerts.

    Step-by-step guides

    How to set each of these up, one task per page.

    Full detail

    Step-by-step instructions, how to check each one worked, and what to do when it did not.