Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • What is not built

    Named plainly, so nothing surprises you later.

    The guide's own closing list, reproduced rather than summarised. Its opening line is that a guide which oversells is worse than no guide, because the first thing that doesn't work takes the rest of it down with it.

    Not implemented

    • Custom Domains — The sidebar says Soon. There is no implementation.
    • IPv6 routes, Resources and exit nodes — Not started.
    • A Terraform provider — Deliberately not started — configuration as a file covers the same ground.
    • A Kubernetes operator — Beyond running the daemon as a pod.

    Partial or unproven

    • Single sign-on is a preview — Less real-world exposure than the rest.
    • IPv6 inside the mesh is half-built — Devices can be given IPv6 addresses, but it is off unless enabled per group, reachable only from the database, and a peer with any port rule still denies IPv6. IPv6 between peers — a direct path where IPv4 cannot connect — is finished and on by default, which is a different thing.
    • SCIM has never been pointed at a real tenant — It is implemented and untested against a live identity provider.
    • The Reverse Proxy Host path — Has never been run against a real carrier-NAT line.