Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • DNS & publishing services

    Names on the mesh, and putting one thing on the public internet.

    Reverse Proxy publishes an internal service on a public domain — HTTP, TLS passthrough or raw TCP.

    DNS

    • Records — A name and an address, for things that are not MangoFly devices.
    • Nameservers — Send a domain to a particular DNS server, scoped to groups if only some devices should use it. The most specific domain wins.

    Services

    A Service publishes something from inside the mesh at a subdomain of your own domain, without opening a port on the network it lives in. It takes two pieces: a Reverse Proxy Host — a device that accepts the traffic and passes it in — and the Service itself, which names a slug, a mode (HTTP, TLS passthrough, raw TCP or raw UDP), the Resource it points at, and the port there.

    Who can open it

    • Anyone who can reach it — Public.
    • A shared password — One password, browser prompt.
    • Sign in with a MangoFly account — A real sign-in page scoped to groups you name. Two-factor applies here too.
    • IP allow and deny rules — Per Service. Deny always wins.

    By default Caddy reaches the Reverse Proxy Host over the public internet in plain HTTP. Setting MANGOFLY_SERVICES_VIA_MESH=1 sends that hop through the mesh instead — encrypted, and worth doing.

    Certificates are issued per hostname on first use, and the apex domain is the server's own so it cannot be a Service. Custom Domains is not built: the sidebar says Soon and means it.