MangoFly
MangoFly documentation
A self-hosted WireGuard mesh. These pages cover how the mesh is shaped, what the server needs, how to stand one up, how access is controlled, and what to do when it misbehaves.
- Peers talk directly. The coordination server holds no private keys and carries no traffic.
- The server is one binary and a SQLite file, using a few megabytes — a 512 MB VM is enough, most of that for Docker.
- It runs fully disconnected, with operator-supplied TLS and no public STUN.
- The project publishes its own limitations; the status page here repeats them rather than summarising them away.
Using a mesh · 4
Running a mesh · 10
Install the server
One small VM, and the first admin.
Letting devices in
Setup keys, approval, and removing a device.
Groups & access policies
Who may reach whom, and two things that surprise people.
Networks, Resources & routing
Exposing what sits behind a device, and failing over between routers.
DNS & publishing services
Names on the mesh, and putting one thing on the public internet.
People & posture
Accounts, tokens, directories, and conditions on the device itself.
The mesh's address range
Why 100.64/10, and the one case where it bites.
Operating it
Configuration as a file, metrics, backups, and headless machines.
Free & Pro
What is free permanently, what Pro gates, and what expiry does.
Install & first run
Set up a MangoFly server on a fresh Linux VM, one step at a time. About fifteen minutes, most of it waiting for DNS. Every command below is exactly what to type.
Reference · 8
What is not built
Named plainly, so nothing surprises you later.
Overview
How a mesh is shaped, and why the server is not in the path.
Requirements
The VM, the domain and the five ports.
Access control
Who sees whom, which ports are open, and who may sign in.
Routing & publishing
Subnet routes, exit nodes, mesh DNS and the Reverse Proxy.
Air-gapped deployment
Running with no internet anywhere in the loop.
Operations
Backups, metrics, upgrades and the failure people hit.
Status & limitations
What has been proven on real hardware, and what has not.