Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Settings that matter

    The handful worth changing, and signing in.

    Settings: auto-connect, route acceptance, inbound blocking and the rest, per profile.

    Most settings can be left alone. These are the ones with a reason to change them.

    Network

    • Reconnect on Network Change — on — Leave it. Off means a peer lost by switching Wi-Fi stays lost until you reconnect by hand.
    • Try IPv6 When IPv4 Can't Connect — on — Leave it. It only acts where IPv4 has already failed, so it never changes a working connection.
    • Tunnel MTU — 1420 — Change it when large transfers stall while small ones work.
    • Enable Client Routes — on — Off means you ignore Resources and exit nodes entirely.
    • Enable Server Routes — on — Off means this machine never acts as a router for others, whatever the administrator configured.

    Security

    • Block Inbound Traffic — off — Turn on when this device should reach out but never be reached. Replies to connections you start still work.
    • Block LAN Access — on — Leave it unless you deliberately want peers reaching your local network.

    Signing in, and two-factor

    Some meshes ask people — not just devices — to sign in, and the administrator sets how long a sign-in lasts. When yours expires the device drops off and the Overview offers Sign In Again; the app warns three days ahead.

    • Two-factor — Set up from Users › 2FA sign-in with any authenticator app. After that a code is needed to sign in, enrol a device, or open a protected Service.
    • Ten recovery codes — Each works once. Keep them somewhere that is not the phone with the authenticator on it — that is the exact situation they exist for.

    If you lose both the authenticator and the recovery codes, an administrator can turn two-factor off for your account.