Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Installation & first run

    From an unseated card to a scored Wi-Fi 8 result.

    Connection — the Console pairs to one Agent by address and token.

    Roughly an hour once the hardware is on the bench. Each step ends in something you can observe, so a failure is located rather than guessed at.

    Standing it up

    1. Seat the card and confirm the driver — Boot the Agent box and check the radio is bound. If iw dev returns no interfaces, the driver has not attached and nothing downstream will work.
    2. Install the tools — iw, wpa_supplicant and iperf3 on the Agent; iperf3 on the LAN receiver.
    3. Set MANGOWIFI_DATA_DIR — The config file location comes from this environment variable and nothing else. There is no CLI flag — this is the single most common way to end up editing a config the app never reads.
    4. Configure the Agent — Role Agent, a listen address and port, and a pair token.
    5. Configure the Console — Role Console, the Agent's address and port, the same pair token, then the target SSID and PSK — plus band, channel and bandwidth if you are pinning them.
    6. Pick a setup mode — Over-the-air is the customer's environment; wired-RF with SMA cabling and attenuators is the repeatable one. Each catalog row records which mode it expects.
    7. Run Baseline — Twenty-four checks that answer whether the rig is ready at all. Fix anything red before reading a performance number.
    8. Run a short Wi-Fi 8 row — Start with the 30-second p95 row before committing to a 30-minute endurance run.
    export MANGOWIFI_DATA_DIR=/opt/mangowifi   # role is read from $MANGOWIFI_DATA_DIR/config.json

    The target PSK is elided from debug output rather than logged. If you are diffing configs by hand, expect it to be absent from traces.