DNS & publishing services
Names on the mesh, and putting one thing on the public internet.
DNS
- Records — A name and an address, for things that are not MangoFly devices.
- Nameservers — Send a domain to a particular DNS server, scoped to groups if only some devices should use it. The most specific domain wins.
Services
A Service publishes something from inside the mesh at a subdomain of your own domain, without opening a port on the network it lives in. It takes two pieces: a Reverse Proxy Host — a device that accepts the traffic and passes it in — and the Service itself, which names a slug, a mode (HTTP, TLS passthrough, raw TCP or raw UDP), the Resource it points at, and the port there.
Who can open it
- Anyone who can reach it — Public.
- A shared password — One password, browser prompt.
- Sign in with a MangoFly account — A real sign-in page scoped to groups you name. Two-factor applies here too.
- IP allow and deny rules — Per Service. Deny always wins.
By default Caddy reaches the Reverse Proxy Host over the public internet in plain HTTP. Setting MANGOFLY_SERVICES_VIA_MESH=1 sends that hop through the mesh instead — encrypted, and worth doing.
Certificates are issued per hostname on first use, and the apex domain is the server's own so it cannot be a Service. Custom Domains is not built: the sidebar says Soon and means it.