Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Groups & access policies

    Who may reach whom, and two things that surprise people.

    Access Control. Each policy names its sources, its destinations, the direction and the ports — and a posture check where one applies.

    Groups are free text. A device is in exactly one, set by the setup key it used or changed later; users can be in several. Policies then decide who may reach whom.

    What a policy says

    • Sources and destinations — Groups the traffic comes from, and groups or specific Resources it goes to.
    • Direction — Both ways, or one way — sources may start connections, destinations may only answer.
    • Protocol and ports — All, or TCP/UDP with port ranges, or ICMP.
    • Posture checks — Extra conditions the device itself must satisfy. Pro.
    • Active — Off keeps the policy without applying it.

    Visibility is mutual, permission is not

    If a policy lets one group reach another, devices on both sides see each other in Peers — a tunnel needs both ends configured. What one-way direction controls is who may start a connection.

    A Resource policy grants the Resource, not the machine

    Letting a group reach a database behind a routing peer does not let them reach the routing peer itself. If you want both, say both.

    docker compose exec mangofly mangofly-server --create-policy "eng to lab" \
      --from eng --to lab --one-way --protocol tcp --ports 22,8000-8080