Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Running it

    Behind a reverse proxy

    MangoDock serves plain HTTP on one port and expects to sit behind whatever already terminates your TLS.

    There is no built-in certificate handling and nothing to configure inside MangoDock. Publish the port to the proxy rather than to the world, and point the proxy at it.

    All three configurations below were tested against a running instance — the UI, the Server-Sent Event streams and the terminal's WebSocket upgrade. Caddy needed nothing beyond what is shown, Traefik nothing beyond the three labels, and nginx the two additions called out under it.

    Caddy

    caddyfile
    docker.example.com {
      reverse_proxy mangodock:3100
    }

    nginx

    nginx
    # in the http block: $connection_upgrade does not exist on its own
    map $http_upgrade $connection_upgrade { default upgrade; '' close; }
    
    location / {
        proxy_pass http://mangodock:3100;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection $connection_upgrade;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_buffering off;        # Server-Sent Events: logs, stats, events
        proxy_read_timeout 3600s;   # these streams are long-lived by design
    }

    Two separate additions, for two different mechanisms. The Upgrade and Connection headers are for the container terminal, which is a WebSocket. proxy_buffering off is for logs, stats and events, which are Server-Sent Events — nginx buffers those by default, so without that line they connect and then sit silent while every ordinary page works.

    Traefik

    yaml
        labels:
          - "traefik.enable=true"
          - "traefik.http.routers.mangodock.rule=Host(`docker.example.com`)"
          - "traefik.http.services.mangodock.loadbalancer.server.port=3100"

    If Traefik answers 404 with those labels in place, check its version before anything else: 3.3 could not read a Docker Engine 29.6 socket at all, so it built no routers and every request missed. 3.7 reads the same labels and the same daemon without complaint.

    Serve it over HTTPS

    The session cookie is HttpOnly and SameSite=Lax but not Secure, because MangoDock cannot know whether it is behind TLS. On plain HTTP over a network, anyone in the middle can read the session. This is the same reason to put a proxy in front of it at all.

    Two things to keep in mind

    • Let long connections live, and do not buffer them. A proxy that cuts idle connections after a minute, or that buffers responses, makes exactly those features look broken while every ordinary page works.
    • Drop the ports: mapping from the compose file once the proxy is on the same Docker network. MangoDock is then reachable only through the proxy, which is the point.

    Air-gapped

    • A reverse proxy works the same inside an enclave. Nothing here needs a public certificate authority — an internal CA is fine.