Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Running it

    SQLite and PostgreSQL

    SQLite by default, Postgres if you would rather. One thing stays on disk either way.

    SQLite is the default and the right answer for most installs: it is a file in the data volume, it needs no second container, and it is what the backup instructions assume.

    Point MANGODOCK_DATABASE_URL at a postgres:// URL and MangoDock uses Postgres instead. Every migration is written dialect-neutral for exactly this, so nothing else changes.

    Postgres

    yaml
    services:
      mangodock:
        image: ghcr.io/mangossh/mangodock:latest
        environment:
          MANGODOCK_DATABASE_URL: postgres://mangodock:CHANGEME@db:5432/mangodock
        depends_on: [db]
        ports: ["3100:3100"]
        volumes:
          - mangodock_data:/app/data
          - /var/run/docker.sock:/var/run/docker.sock
        restart: unless-stopped
    
      db:
        image: postgres:16-alpine
        environment:
          POSTGRES_USER: mangodock
          POSTGRES_PASSWORD: CHANGEME
          POSTGRES_DB: mangodock
        volumes:
          - mangodock_pg:/var/lib/postgresql/data
        restart: unless-stopped
    
    volumes:
      mangodock_data:
      mangodock_pg:

    Keep the data volume even on Postgres

    The database moves, but the install key — secret.key, which decrypts every stored credential — stays on disk. A Postgres dump alone restores a database full of credentials that nothing can read. Separating the two is deliberate rather than an omission: a database backup, a replica or a support dump never carries the key that unlocks it.

    Switching is a fresh start, not a migration. There is no SQLite-to-Postgres importer, so choose before you have data worth keeping.

    Air-gapped

    • Both options are local. Postgres is one more container on your own network, not a hosted service.