Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Guides · Automation

    Importing hosts

    Bring your existing SSH hosts into MangoSSH instead of retyping them. Import from another SSH client, from the inventory your automation already uses, or from a network scan.

    • SSH hosts
    • Source files are only read
    • About 5 minutes

    Supported sources

    SourceWhere MangoSSH reads itGroupsTag
    OpenSSH~/.ssh/config, found automatically, following Include linesNoimported:ssh-config
    PuTTYWindows: saved sessions in the registry, found automatically. macOS and Linux: ~/.putty/sessionsNoimported:putty
    MobaXtermMobaXterm.ini, found automatically or by path. An exported .mxtsessions file also works.Noimported:mobaxterm
    AnsibleAn INI inventory file you choose (hosts.ini, inventory)Yes: inventory groupsimported:ansible
    TerraformA state file you choose (terraform.tfstate, format v4 or v3)Yes: resource and module namesimported:terraform
    IP ScanLive hosts answering on SSH in a range you scanOne group you nameimported:ipscan

    Every import creates SSH hosts. Sessions of other types in a source, such as RDP, VNC or Telnet entries in PuTTY or MobaXterm, are listed as skipped rather than imported. MangoSSH never writes to the source files.

    Import from a file or another client

    1. In the Dashboard's sidebar, click Import SSH sessions.

    2. Choose the source under Import from. OpenSSH, PuTTY and MobaXterm scan straight away, looking in their usual places.

    3. For Ansible and Terraform, click Browse… to pick the file, or type its path and click Scan. MobaXterm shows the same path box: fill it in only if its config was not found.

    4. Review the list. Each row shows the name, user@host:port, the key file if any, its groups, and which file it came from. Notes about skipped entries appear in yellow above the list.

    5. Untick anything you don't want, or use Select all. Rows whose name matches a host you already have are marked already imported and start unticked, so running an import twice does not create duplicates.

    6. Click Import Selected. When it finishes, the footer shows how many were imported and any that failed. Click Done — Close.

    The new hosts appear in the sidebar and on the Dashboard at once. Each import is recorded in the audit log with the source and the number of hosts.

    What each source brings

    OpenSSH config

    Each Host block becomes a host named after its first non-wildcard pattern. MangoSSH reads HostName, Port, User, IdentityFile, CertificateFile, ServerAliveInterval, Compression, ForwardAgent, ProxyCommand and ProxyJump.

    • Wildcard-only blocks (Host *) and Match blocks are skipped.
    • Include is followed, up to eight levels deep. An Include with a wildcard pattern is skipped and reported.
    • ProxyCommand is copied as written. Check its %h, %p and %r placeholders after importing.
    • ProxyJump is shown on the row but not connected up, because the jump host may not exist in MangoSSH yet. Set the jump host on the host afterwards. See SSH hosts.

    PuTTY and MobaXterm

    From each SSH session: the session name, host, port, username and private key file. PuTTY's Default Settings entry is ignored. From MobaXterm, only sessions in bookmark sections are read. A MobaXterm SSH gateway comes across as a jump host shown on the row, to set up afterwards the same way as a ProxyJump.

    Ansible inventory

    Only the INI inventory format is read. A YAML inventory is not supported yet, and scanning one reports no hosts. What is understood:

    • [group] sections, [group:children] for nested groups, and [group:vars] for shared variables.
    • Ranges such as web[01:03].example.com and db-[a:c].
    • ansible_host, ansible_port, ansible_user and ansible_ssh_private_key_file, plus the older ansible_ssh_host, ansible_ssh_port and ansible_ssh_user spellings. A port written on the name (db1:2222) also works.
    • Ansible's precedence: a host's own variable beats its group's.

    A host in several groups is imported once, with all of them. Membership includes parent groups from :children. For example:

    [web]
    web[01:02].example.com
    
    [db]
    db1 ansible_host=10.0.1.5 ansible_user=postgres
    
    [prod:children]
    web
    db
    
    [prod:vars]
    ansible_user=deploy

    This inventory gives three hosts. web01.example.com and web02.example.com are in groups web and prod, with user deploy. db1 is in db and prod, with its own user postgres.

    On macOS and Linux, clicking Scan with the path empty reads Ansible's default /etc/ansible/hosts.

    Terraform state

    MangoSSH reads a local state file, format v4 (current) or v3 (older). For remote state, such as an S3 or Terraform Cloud backend, save a copy first with terraform state pull > terraform.tfstate. Data sources are ignored, and so is any instance without an address yet.

    Resource typeName fromAddress used
    aws_instanceName tagPublic IP, else public DNS, else private IP
    google_compute_instancenameExternal (NAT) IP, else internal IP
    azurerm_linux_virtual_machine, azurerm_windows_virtual_machine, azurerm_virtual_machinenamePublic IP, else private IP. The username comes from admin_username.
    digitalocean_droplet, hcloud_servernamePublic IPv4, else private IPv4
    linode_instancelabelip_address
    vultr_instancelabel, else hostnamemain_ip
    openstack_compute_instance_v2nameaccess_ip_v4
    scaleway_instance_servernamePublic IP, else private IP

    An instance without a name is called after its resource, such as web[0]. The row shows its full Terraform address. Groups are the resource name, plus the module (such as module.db) when the resource lives in one. Every host is imported on port 22. Azure is the only type that brings a username. For the rest, set one afterwards or type it at first connect. Windows VMs are imported as SSH hosts too, so remove any you don't reach over SSH.

    Groups, tags and sign-in

    • Source tag. Every imported host gets a tag naming where it came from, as listed in the table at the top. Search or filter by it to find a batch later.
    • Group tags. Each Ansible or Terraform group becomes a tag group:<name>, such as group:prod. The first group also becomes the host's group in the sidebar. For Ansible that is the first matching group in the order the groups appear in the file.
    • Sign-in. A host with a key file is set to key-only authentication with that key. Any other host is set to password, and MangoSSH asks for the password the first time you connect. No passwords are imported from any source.

    Tags and groups are what policies and multi-host commands select on, so an imported inventory can be put to work straight away.

    Add hosts from an IP scan

    For machines that are on the network but in no file, scan for them.

    1. Open Tools → IP Scan, enter a range and click Scan. Each address is probed on SSH, RDP, VNC, FTP and Telnet ports. No administrator rights are needed.

    2. Click Add all found. One prompt asks for an SSH username for all of them (leave it blank to be asked at first connect) and a group, Scanned by default.

    3. Every host that answered on port 22 and is not already saved (matched by IP) is added as an SSH host with password sign-in, tagged imported:ipscan.

    Hosts found only on RDP or VNC are not part of Add all found. Use the + Add button on their row instead.

    Cloud instances

    To list running instances straight from AWS, Azure, Google Cloud or Kubernetes, use Discover in the Dashboard's sidebar. It uses the provider's own command-line tool (aws, az, gcloud or kubectl) and the sign-in you already have there. Pick instances and click Add Selected. They are tagged imported:aws, imported:azure, imported:gcp or imported:kubernetes. Discover is not in the Secure (air-gapped) edition.

    Troubleshooting

    SymptomLikely cause
    “No PuTTY sessions found in the registry”PuTTY has no saved sessions for this Windows user. Sessions saved by another user or a portable PuTTY are not in this registry location.
    “Couldn't auto-find MobaXterm.ini”MobaXterm keeps its config elsewhere, for example the portable edition. MobaXterm shows the location under Settings → Configuration. Paste that path, or export your sessions to an .mxtsessions file and choose that.
    Ansible: “No hosts found … Only the INI inventory format is read”The file is a YAML inventory, or it only defines groups and variables.
    Terraform: “No compute instances with an address found”The state has no supported resource type, or the instances have not been created yet.
    “not a Terraform state file”The file is not state JSON, for example a .tf file or a plan. Choose terraform.tfstate.
    A host is missing from the OpenSSH listIt is only matched by a wildcard or a Match block, or it sits in a wildcard Include. The yellow notes list what was skipped.
    Every row says “already imported”Hosts with those names already exist, usually from an earlier import. Ticking a row anyway adds a second host with the same name.