Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • The mesh's address range

    Why 100.64/10, and the one case where it bites.

    Addresses come from 100.64.0.0/10 by default — the range reserved for carrier-grade NAT, chosen because it almost never appears on a LAN.

    The hole in that reasoning

    An ISP hands its own customers addresses from 100.64.0.0/10 behind carrier NAT. A device on such a line has a real address inside the mesh range and no way to tell mesh traffic from the rest. Mobile networks do this often, which is why the range is configurable.

    docker compose exec mangofly mangofly-server --mesh-range
    docker compose exec mangofly mangofly-server --mesh-range 10.80.0.0/12

    Rules

    • Must sit inside 10/8, 172.16/12, 192.168/16 or 100.64/10, and be between /8 and /28.
    • Changing it is refused if any device already has an address outside the new range — And the message names one. Set the range before devices enrol, or pick one that still contains them.
    • Devices already enrolled keep the address they have; only new enrolments draw from the new range.
    • Pick something that does not collide with LANs you intend to reach through routes and Resources.

    MTU is a per-device client setting, not a server one, because the path that needs it belongs to that device.