Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Zero Trust & Relay

    Reach machines with no inbound port open, hide credentials from the people using them, and approve access per request.

    Fleet-wide oversight of privileged access in one place.

    One relay sits behind each of these features. It brokers the connection; it is not a place your credentials live.

    • Persistent sessions — Keep an SSH session alive on the relay so it survives your laptop closing.
    • PAM Broker — Someone connects without ever being given the password. Works for SSH, RDP and VNC.
    • One-time browser links — Share access to a host through a link that works once.
    • Connect by ID — TeamViewer-style rendezvous for RDP, with no port forwarding.
    • MangoSSH Direct — Reach a Windows machine that has no RDP server enabled at all.
    • Private Network — A MangoFly overlay network between your machines.

    Oversight

    • PAM Dashboard — Fleet-wide view of privileged sessions, pending requests and credential rotation.
    • Just-in-time access — Access is requested and approved per use, and expires. Policy can require a ticket reference and a one-time code from the approver.
    • Fleet-wide policy — Rules applied by group, by tag or across the fleet rather than per host. A default policy can be overridden on a host; a mandatory one locks the control.

    Step-by-step guides

    How to set each of these up, one task per page.

    Full detail

    Step-by-step instructions, how to check each one worked, and what to do when it did not.