Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Everyday

    Stacks

    Compose projects, their dependency graph, and deploys from git.

    How stacks are found

    • Compose projects are grouped from labels already carried on every container listing — nothing extra is installed or parsed to discover them.
    • The dependency graph is drawn from those same labels.
    • Start, stop and restart apply to a whole stack at once.

    Deploying

    • Deploy and teardown run the real docker compose CLI, not a reimplementation of it.
    • It runs locally against a proxy onto whatever the target actually is — so a stack can be deployed over SSH to a host with nothing installed on it.
    • The visual editor builds a stack's services and dependencies on that same graph.
    • It saves its own definition and generates deploy YAML from it, rather than ever parsing Compose YAML back in.

    Git-backed stacks

    • A stack linked to a repository opens its compose file from that repository, with the commit it came from named in the banner.
    • When the link is marked writable, the file is editable and Review & commit shows the change line by line — added and removed lines carry a sign as well as a colour.
    • The commit message is yours; the author is the link's, with the signed-in user recorded in a Changed-by trailer.
    • If the branch moved while the file was open, the commit is refused and both commits are shown with a reload — nothing is written, and your edit stays in the editor.
    • A link that is not writable keeps the read-only view and says where to turn writing on.

    Deadlines

    • A stack can be given a deadline from the clock icon in its row: MangoDock takes it down, or stops it, when the time comes.
    • The row shows a countdown chip — slate until the last half hour, amber after that. Clicking it moves or cancels the deadline.
    • Deadlines are absolute moments rather than schedules. If MangoDock is not running when one passes, the stack goes at the next start.
    • Refused up front on the exec rung, which cannot take a stack down at all.

    Air-gapped

    • Deploys pre-pull through whichever registry mirror you configured, so images come from inside the enclave.
    • A git-backed stack needs a git host the network can reach — an internal GitLab, Gitea or bare repository is enough.
    • A private repository's access token is injected per request and never written to disk.