Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Reference

    Troubleshooting

    The errors MangoDock actually emits, and what each one is telling you.

    Starting up

    • Port 3100 already in use — change the left side of the -p mapping, for example -p 8080:3100, and open that port instead. MANGODOCK_PORT only changes the port inside the container.
    • “Cannot connect to the Docker daemon” when adding This machine — the socket mount was left off. Add -v /var/run/docker.sock:/var/run/docker.sock and recreate the container, or manage this host over SSH instead.

    MangoDock did not deploy this stack

    The stack uses a path relative to the compose file, like ./data:/data, or a file: secret or config. Those paths resolve on the machine running MangoDock, which the Docker host cannot see. Deployed anyway, Docker would mount an empty directory — so MangoDock stops before deploying and lists each path.

    Fixing that one

    • Bind mounts: use an absolute path that exists on the Docker host, or a named volume.
    • Secrets: use environment: MANGODOCK_SECRET_<name>, with the value coming from the Secrets tab.
    • Configs: use content:.
    • If the host really does see MangoDock's data directory at the same path, set MANGODOCK_DAEMON_SHARES_FILESYSTEM=1.

    Connections MangoDock refuses

    • “Refusing an unencrypted Docker connection … that is a public address” — a plain tcp://…:2375 endpoint on a public IP. Connect with mutual TLS or SSH, or set MANGODOCK_ALLOW_PUBLIC_PLAINTEXT=1 if the host is genuinely reachable only through a VPN or a firewall rule.
    • “did not send it, because this Docker host is reached over an unencrypted connection”, on a pull — MangoDock has a credential for that registry but will not put it on a plaintext wire. Connect the host with mutual TLS or SSH.

    Air-gapped

    • Update checks against an unreachable registry give up after 15 seconds and skip that registry's remaining images, so a check never stalls on the air gap.