Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • People & posture

    Accounts, tokens, directories, and conditions on the device itself.

    Users, roles and two-factor state, with directory-group mapping and API tokens underneath.

    Accounts

    • Local accounts — Two roles: Admin changes things, User reads. That is the whole model.
    • API tokens — Sent as a bearer token, acting as you with your role until they expire or you delete them. Shown once.
    • Service accounts — For machines. One owns tokens and cannot sign in, so its access does not end when the person who set it up leaves. Creating one needs a signed-in admin — an API token cannot do it, so a leaked token cannot manufacture more of itself.

    Directory login

    Pro. People sign in with their LDAP or Active Directory credentials, and directory groups map to mesh groups so membership follows the directory rather than being maintained twice.

    An expired licence still authenticates people through the directory. Expiry must never lock everyone out.

    Single sign-on and provisioning

    • OIDC is a preview — Free while it is one, and honestly labelled: it has had less real-world exposure than the rest of this list.
    • SCIM — Creating, renaming, groups, and deactivation that ends sessions, deletes tokens and revokes devices. Only three attributes are kept — MangoFly is not trying to be your directory. No real tenant has been pointed at it yet.

    Posture checks

    Pro. A policy can require the device to satisfy conditions rather than merely belong to a group: a minimum MangoFly version, network ranges it must or must not be inside, per-OS version rules, or required programs. The Failing Now column shows how many devices currently do not satisfy a check — the number to look at before attaching it to anything important.

    Enforcing checks that already exist is never licence-gated, and neither is deleting them. An expired licence freezes changes; it does not quietly stop enforcing what you asked for.