Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Advanced

    GitOps

    Deploy a Compose stack straight from a git repository, and keep the two in step.

    A GitOps target points at a repository and a compose file inside it. MangoDock clones it, deploys the stack, and records the commit it deployed.

    Like compose and the scanners, git runs as a real subprocess. MangoDock never parses a byte of git's own wire protocol or object model — it shells out and reads back what git prints.

    Three ways a sync happens

    • On demand, from the UI or POST /api/gitops/:id/sync.
    • On a schedule, as a git_sync job alongside the other scheduled work.
    • From an inbound webhook — POST /api/gitops/webhook/:token, a public endpoint authenticated by the token in the path, so your forge can push to it on every commit.

    A no-op sync is not a failure

    If the resolved commit is already the deployed one and you have not asked it to force, the sync reports that nothing changed and stops. A scheduled sync against a quiet repository is therefore quiet too, rather than redeploying on a timer.

    Drift

    MangoDock can also compare what is running against what the repository says should be running, and report the difference — so a change somebody made by hand on the host is visible rather than silently overwritten on the next sync.

    Air-gapped

    • Point the target at an internal git server. Nothing here requires a forge on the public internet.
    • The webhook endpoint is served by MangoDock itself, so an internal forge can reach it without egress.