Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Install & join

    Getting onto a mesh somebody else runs.

    MangoFly runs on Windows, macOS and Linux. The desktop app creates a network adapter, which needs administrator rights on Windows and root elsewhere — it asks when it needs them. A machine with no screen runs the daemon instead.

    Joining

    You need two things from whoever runs the mesh: the server address and a setup key.

    1. Open MangoFly and choose Join Tunnel on the Overview page.
    2. Fill in the details — The server URL, the setup key, and a name for this device. The name is what everyone else sees, so make it recognisable — design-laptop beats DESKTOP-4F8A2.
    3. Enroll. Some meshes also ask you to sign in at this point; if the form shows those fields, the administrator has required it.

    What happens next

    • You are connected — The Overview shows your address and your peers.
    • Or you are waiting for approval — An administrator has to let you in before anything works. That is deliberate on meshes that use it.

    You only enrol once. After that the device remembers who it is, and Connect on the Overview is all you need.

    Reading the Overview

    • The connect switch — On or off for this device.
    • Your address — Under Settings › Network › Tunnel Address. Other devices reach you at it.
    • Connected Peers — Every device you are allowed to see, and what you can do with each.

    Two cards appear only when something is wrong, and both are worth reading rather than dismissing: "Can't reach the server" means existing connections keep working but nothing new arrives, and "Your sign-in has expired" means the mesh asks people to sign in periodically and yours has lapsed.