Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Networks, Resources & routing

    Exposing what sits behind a device, and failing over between routers.

    Networks group resources so you expose a host or a subnet rather than a whole LAN.

    A Network is a place — an office, a home, a cloud VPC — and a folder for the things in it. A Resource is one thing there: an address for a NAS, a CIDR for a whole subnet, or a host name.

    Resources named after a host

    Use a name when the address is not yours to pin, because DHCP moves it or the service changes address on its own. The routing peers resolve the name — not the server and not the consumer — because they are the machines that have to reach it, and an internal name usually only resolves on their own network.

    • Nothing routes until one resolves it — The Networks page shows "not resolved yet". Failing visibly beats sending traffic somewhere wrong.
    • An address that stops being returned keeps working for ten minutes — So a name whose answers rotate does not cut live connections.
    • At most eight addresses per name — And a failed lookup changes nothing — the addresses already known stay.
    • No health check on a named Resource — A check probes an address inside the Resource, and a name has none until it resolves.

    Routing peers and failover

    A routing peer is the device that passes traffic through to a Resource. Attach more than one and the role moves when it has to.

    • Offline for 20 seconds — Loses the role.
    • Lower priority numbers win — And Pinned keeps the role with one device unless it goes away.
    • A failing health check hands over — Even while the router itself is perfectly reachable — the case the control channel cannot see: the router is up, its own link to the subnet is down.

    The machine doing the routing needs Enable Server Routes on, which is its default. It turns on IP forwarding and NAT for itself when it has something to route.

    Exit nodes

    An exit node carries a device's whole internet connection: add a route and tick exit node, which fixes the CIDR at 0.0.0.0/0. Users choose whether to use one. The exit node's own LAN is not exposed by the default route alone — a route you advertised on purpose still works.