Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Settings

    Settings

    Accounts, hosts, credentials and the rest of the configuration.

    Accounts and access

    • Local accounts and sessions are mandatory on every install. There is no toggle to skip them and no anonymous access.
    • Three roles — admin, operator and viewer — enforced on the server per route, not merely hidden in the interface.
    • Personal API tokens for scripts and CI, self-service per user, inheriting that user's role.
    • Single sign-on over OpenID Connect, and sign-in against a real LDAP or Active Directory with auto-provisioning and account linking.
    • Optional two-factor with recovery codes.
    • A Users screen for administrators, and every audited action recording who did it.

    Hosts

    • Add a host over SSH, over TCP with or without mutual TLS, or on the local socket.
    • How a host is reached cannot be changed after adding — the pinned host key and cached connection describe that machine. Remove and re-add instead.
    • An optional public IP makes the Containers page's port links clickable; MangoDock cannot infer it, because the daemon reports the bind address and an SSH target may be a bastion rather than where the service is served.
    • Per-host tabs for updates, activity, security and notifications.

    The rest

    • Registry mirrors and stored credentials.
    • Git links and whether each is writable.
    • Notification channels: email over real SMTP, plus webhook, Slack and Discord. The test button shares the real send path, so a passing test proves the real thing works.
    • Menu mode, choosing whether the advanced half of the rail is open or one click away.

    Air-gapped

    • This is where an enclave is configured: registry mirrors under Credentials, and vulnerability databases under Hosts ▸ Edit ▸ Security.
    • Single sign-on and directory sign-in both work against internal providers — an on-premises identity server or your own directory.
    • Notification channels reach an internal SMTP relay or an internal webhook endpoint just as well as an external one.