Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Running it

    Adding hosts

    One control plane for many Docker hosts, with nothing installed on any of them.

    The container you just started is MangoDock. It does not manage its own host unless you added the socket mount. Either way the next step is the same: Dashboard ▸ Add host.

    Three kinds of connection

    • This machine — only offered if you mounted /var/run/docker.sock.
    • SSH, recommended for anything remote — point it at any host you can already ssh into. Nothing is installed on that host and no port is opened; MangoDock reaches its Docker socket over the SSH session itself.
    • TCP, for a host that already exposes the Engine API directly. Use mutual TLS on 2376.

    Plain 2375 is refused on public addresses

    Port 2375 has no authentication and no encryption — anyone who can reach it has root on that host. MangoDock accepts it only for loopback and private ranges (127.x, 10.x, 172.16–31.x, 192.168.x, link-local, and 100.64/10 where Tailscale lives), and never sends a stored registry credential over it, so private images cannot be pulled through a plaintext connection. If the host really is reachable only through a VPN or a firewall rule, MANGODOCK_ALLOW_PUBLIC_PLAINTEXT=1 overrides it — a server setting rather than a checkbox, on purpose.

    SSH is the one worth knowing about: if you can SSH into a box today, you can manage its containers in MangoDock half a minute later, with nothing added to that host. This is the main reason to run MangoDock rather than docker directly — one UI, every host, no agent anywhere.

    Air-gapped

    • All three connection kinds are local to your network. None involves a broker or a relay outside it.