Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Reaching things

    Devices by name, networks behind them, and exit nodes.

    Peers — every device, its platform, its tunnel address and whether it is actually connected right now. Example network.

    Another device

    Every device has an address, and most meshes also give it a name — the device's name plus .mesh. Use either exactly as you would any other address: ssh you@laptop.mesh, \\nas.mesh\share, or http://buildbox.mesh:3000 in a browser.

    What the Peers page adds

    • Ping — Is it reachable right now.
    • Open Address… — Opens a web interface in your browser, offering the common ports as one-click choices and remembering what you picked per device.
    • Remote Access — SSH, RDP or VNC, when MangoSSH is installed alongside.
    • Run Traceroute — The hops in between — how you tell "the mesh is slow" from "your internet is slow".

    How you are reaching a peer

    Expanding a peer row shows latency, estimated loss, throughput, and a Connection field that names the path: Direct LAN (same network), NAT-traversed (a direct path across the internet — the good case), Connecting, No direct path (going through the relay, which works but detours every packet), or Unreachable.

    Something that is not a MangoFly device

    You do not need MangoFly on a printer, a NAS, a switch or a whole office subnet. Somebody runs it on one machine there, and that machine passes traffic through. From your side there is nothing to configure: if your group has access, the address simply works.

    • Access to a Resource is not access to its router — Reaching a customer's database does not mean reaching the server that fronts it. That is deliberate.
    • Enable Client Routes must be on — It is by default. Off means your device ignores these routes entirely.

    Sending everything through another device

    An exit node carries your whole internet connection, not just mesh traffic. Settings › Network › Exit Node offers Automatic, Off, or one specific device. Changing it reconnects the tunnel, so expect a brief interruption.

    While an exit node is active, IPv6 to the internet is blocked outright. That is not a bug — it is what stops IPv6 traffic leaking around the tunnel while you believe everything is going through it. Block LAN Access, on by default, keeps your own printer and router out of reach of the mesh at the same time.

    More than one mesh

    A profile is one coordination server with its own identity, key, address and peers. Add one under Settings › Account and switch with the picker at the top of the sidebar. Only one connects at a time, deliberately: two meshes hand out addresses from the same range, so being on both at once would need a second adapter and a way to tell them apart.