Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Overview

    How a mesh is shaped, and why the server is not in the path.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol

    Every device holds an encrypted WireGuard tunnel to every other device. Separately, each device keeps a thin TLS connection to the coordination server, which tells it who else exists and how to reach them. Those are the only two kinds of connection in the system.

    What the server does

    • Enrollment — Admits a device to the network against a setup key.
    • Address allocation — Hands each device its tunnel address.
    • Peer lists — Tells each device which other devices it may see, filtered by access policy.
    • ICE signalling — Relays sealed candidate payloads between peers so they can find each other through NAT.
    • NAT reflector — Reports back the source address a packet arrived from, which is how a device learns its own public endpoint.

    What it cannot do

    • It holds no private keys — Nothing it stores can decrypt peer traffic.
    • It cannot read signalling — ICE payloads are sealed with X25519 against the peers' own WireGuard keys before they reach it.
    • It carries no data — Bandwidth cost stays near zero however much the mesh moves — except on the relay path, below.

    When peers cannot punch through

    If both ends sit behind symmetric NAT, hole punching fails. Rather than leaving the pair unable to talk, traffic falls back to an authenticated relay. That is the one case where bytes cross infrastructure you run.