Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Letting devices in

    Setup keys, approval, and removing a device.

    A setup key is what someone needs to join. Create one from Peers › Create Setup Key, or from the CLI.

    What a key decides

    • Group — Which group the device lands in. Access is decided by group, so this is the field that matters.
    • Principal type — Human, service or agent — labelling, and what the zero-trust features key off.
    • Max uses and expiry — One key per person is tidier than one key for everyone.
    • Disposable devices — The device is deleted once it has been offline ten minutes. For CI runners and short-lived containers.
    • Require sign-in — The person must authenticate, not merely hold the key. Pro.
    • Require approval — You approve each device before it works. Pro.
    docker compose exec mangofly mangofly-server --approve-device DEVICE_ID

    That approval command works with no licence at all — deliberately, so an expired licence can never lock you out of your own mesh.

    Removing one

    Disconnect revokes a device immediately and keeps the row so you can undo it. Delete Peer removes it entirely. A revoked device is off the mesh in seconds.