Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Access control

    Who sees whom, which ports are open, and who may sign in.

    Visibility is the first control

    Access policies are group-to-group rules that decide who appears in whose peer list. A device that is not in your peer list is not something you have to be firewalled from — you were never told it exists.

    Controls

    • Access policies — Group-to-group visibility rules.
    • Port rules — Per-peer inbound filtering, enforced on the receiving client rather than centrally.
    • Users and roles — Admin and non-admin accounts, argon2-hashed.
    • Audit log — Enrollments, logins, policy and route changes, with source addresses.
    • API tokens and service accounts — For automation that should not carry a person's credentials.
    • Two-step sign-in — Available for accounts.

    Pro features

    • Device approval — An admin admits each new device before it joins. Opt-in per setup key.
    • Directory login — LDAP or Active Directory credentials, with the role taken from a nominated group.

    Hosted identity providers are not supported. OIDC exists only as a preview; directory login is the supported path.