Letting devices in
Setup keys, approval, and removing a device.
A setup key is what someone needs to join. Create one from Peers › Create Setup Key, or from the CLI.
What a key decides
- Group — Which group the device lands in. Access is decided by group, so this is the field that matters.
- Principal type — Human, service or agent — labelling, and what the zero-trust features key off.
- Max uses and expiry — One key per person is tidier than one key for everyone.
- Disposable devices — The device is deleted once it has been offline ten minutes. For CI runners and short-lived containers.
- Require sign-in — The person must authenticate, not merely hold the key. Pro.
- Require approval — You approve each device before it works. Pro.
docker compose exec mangofly mangofly-server --approve-device DEVICE_IDThat approval command works with no licence at all — deliberately, so an expired licence can never lock you out of your own mesh.
Removing one
Disconnect revokes a device immediately and keeps the row so you can undo it. Delete Peer removes it entirely. A revoked device is off the mesh in seconds.