Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Advanced

    Podman

    MangoDock manages Podman hosts too, with the differences named rather than discovered.

    Podman management is off by default and turned on in Settings ▸ Manage. It is a server-side switch rather than a browser preference, because it decides what the whole install manages.

    On, it adds a Podman entry to the sidebar listing your Podman hosts with their version, whether they run rootful or rootless, the negotiated API version, and what each one cannot do. The engine is detected from the daemon's own version response, in the same call that negotiates the API version, so knowing which engine you are talking to costs no extra round trip.

    What differs

    AreaOn Podman
    CPU limitsExpressed in the form Podman accepts. Sending Docker's form is accepted with an empty warning and then ignored — the ceiling silently does not exist, which is why this is handled explicitly.
    SwarmNot available. The page says so and links here, rather than offering to initialise a cluster whose requests then fail.
    Update checksNot supported by the shipped daemon. MangoDock says that, rather than reporting that your registry no longer has the tag — which was a false claim about your infrastructure. Pulling still works.
    SecretsWork. The breakage reported elsewhere did not reproduce.
    ComposeVerified end to end.

    Short image names depend on the host, not on MangoDock

    image: alpine resolves only if docker.io is in that host's unqualified-search-registries. On a host configured without it, the same compose file fails to pull. Qualify the image name if you cannot rely on every host's configuration.

    Plaintext TCP is worse here than on Docker

    Podman's own service warns, unprompted, against using its API over TCP without TLS. The advice on the Adding hosts page applies with more force: use SSH, or mutual TLS.

    Air-gapped

    • Podman hosts are reached the same ways Docker hosts are, and the same refusal to send credentials over a plaintext connection applies.