Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Running it

    Install and first run

    One container, one process, nothing to configure first. If Docker is already on the machine, MangoDock is up in about thirty seconds.

    MangoDock needs Docker Engine 20.10 or newer with the Compose plugin — docker compose, not the standalone docker-compose. Docker Desktop and most Linux distribution packages already include it.

    There is no database to stand up and no config file to write first. The container creates its own SQLite database and its encryption key inside the data volume on first boot.

    Quick start

    bash
    docker run -d --name mangodock \
      -p 3100:3100 \
      -v mangodock_data:/app/data \
      -v /var/run/docker.sock:/var/run/docker.sock \
      ghcr.io/mangossh/mangodock:latest

    Then open http://localhost:3100. You land on a one-time setup screen to create the admin account, and you are in.

    What each flag is for

    FlagWhy it is there
    -p 3100:3100The web UI and API. This is the only port you need, including for managing remote hosts over SSH or TCP.
    -v mangodock_data:/app/dataWhere the database and the encryption key for stored credentials live. Keep this volume.
    -v /var/run/docker.sockOnly so MangoDock can manage this same machine's daemon. Managing other hosts over SSH or TCP needs no socket mount at all — leave it off if you only plan to add remote hosts.

    Recommended: compose

    yaml
    services:
      mangodock:
        image: ghcr.io/mangossh/mangodock:latest
        container_name: mangodock
        restart: unless-stopped
        ports:
          - "3100:3100"
        volumes:
          - mangodock_data:/app/data
          - /var/run/docker.sock:/var/run/docker.sock
    
    volumes:
      mangodock_data:

    The same result as the one-liner, but the configuration lives in a file you can version and re-apply rather than in a shell history entry.

    First login

    The first person to open the UI sets an admin username and password there and then. There is no default password to look up and change, and no skip-auth mode: every install requires an account from the very first request.

    Afterwards, Settings ▸ Users adds more people, each with one of three roles — admin, operator or viewer — enforced on the server rather than hidden in the interface. SSO (OIDC), LDAP and per-user two-factor can be set up whenever you want them.

    Air-gapped

    • Nothing on this page reaches the internet except the image pull itself. For a network that cannot do even that, see the air-gapped install.