Air-gapped deployment
Running with no internet anywhere in the loop.
MangoFly runs entirely inside a disconnected network. The differences from a standard install are all in how TLS is obtained and trusted.
TLS without ACME
With no internet there is no ACME challenge, so the server terminates TLS itself from operator-supplied PEM files. Either issue a certificate from your own CA, or have the server mint a self-signed one for the names and addresses clients will actually use.
mangofly-server --generate-selfsigned --san mesh.internal,10.20.0.5Trusting it
- Clients get the certificate or your CA — As a custom trust root, additive to the system store rather than replacing it.
- Names must match — Clients reach the server by a name or address in the certificate's SAN set.
- No escape hatch — Hostname verification always runs. There is deliberately no skip-verification option anywhere in the product.
What already needed no internet
- NAT traversal — Uses only the server's own UDP reflector. There is no public STUN fallback to forget to block.