Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Reference

    The HTTP API

    Everything the interface does, it does over this API. Scripts use the same routes with a token instead of a cookie.

    The web UI is a client of this API and has no privileged back channel. Anything you can do in the interface, you can do from a script, with the same role check applied.

    Authenticating a script

    bash
    curl -H 'Authorization: Bearer mgdk_…' \
         https://docker.example.com/api/environments

    API tokens are created under Settings and travel as a bearer header rather than a cookie — nothing about a scripted client should need cookie handling. Each token records when it was last used, so a token nothing uses any more is visible as such.

    Why tokens start with mgdk_

    Partly so a person can tell what kind of secret they are looking at in a list of environment variables, and partly because a recognisable prefix is exactly what automated secret scanners — GitHub's included — key off to flag a token that has leaked into a public repository. A bare 64 hex characters would be invisible to them. Tokens are stored as a SHA-256 lookup hash, not in the clear.

    Route families

    PrefixWhat lives there
    /api/auth/*Sign-in, sign-out, password change, TOTP enrol/confirm/disable, recovery codes, and the SSO and LDAP configuration and test endpoints.
    /api/environmentsThe hosts themselves — add, edit, test, discover, reconnect, and per-host info and status.
    /api/environments/:id/containersList, inspect, act, top, update, and the in-container file operations.
    /api/environments/:id/composeStack up and down, plus stack definitions, drift, expiry and limits.
    /api/environments/:id/swarm/*Swarm init, join, leave, nodes, services, scale, image update, configs and secrets.
    /api/environments/:id/backup/*Init, check, snapshots, restore, restore-service, swap, forget, and volume and stack backup.
    /api/scans, /api/scanner-dbImage scans and their findings, SARIF export, and the vulnerability databases.
    /api/gitopsGit targets, their files, manual sync, and the public webhook endpoint.
    /api/schedules, /api/notificationsScheduled jobs including on-demand runs, and notification channels with a test endpoint.
    /api/users, /api/tokensAccounts, roles, password resets, per-user TOTP disable, and API tokens.
    /api/health, /api/metrics, /api/featuresLiveness, Prometheus-style metrics, and which optional features this install has on.

    Streams

    Logs, stats, events and scan progress are Server-Sent Events rather than polled endpoints; the container terminal is a WebSocket. A proxy in front of MangoDock has to leave both alone — see Behind a reverse proxy.

    One transport cannot do all of this

    A host connected over SSH-with-exec drives the docker CLI rather than the Engine API. Deploying a stack needs the API, and MangoDock says so rather than half-working: “deploying a stack needs the Engine API; this host is on the docker-CLI transport. Allow socket forwarding on it, or use a TCP endpoint.”

    Air-gapped

    • The API is served by the same container as the UI. Nothing about it reaches outside your network.