Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Requirements

    The VM, the domain and the five ports.

    The machine

    • A Linux VM with a public address — One vCPU and 512 MB of RAM. The server itself uses a few megabytes and peer traffic never passes through it — the RAM is for Docker, which needs around 150 MB on its own.
    • A domain pointing at it — Clients connect over TLS, a certificate is required, and a certificate requires a name.

    Ports reachable from the internet

    • 80 / TCP — ACME certificate challenge, and the HTTP to HTTPS redirect.
    • 443 / TCP — Enrollment, the peer-list WebSocket, ICE signalling and the admin API.
    • 8788 / UDP — The NAT reflector.
    • 8443 / TCP — Reverse Proxy in HTTP mode. Only needed if you use that feature.
    • 8444 / TCP — Reverse Proxy in TLS-passthrough mode. Same.

    The UDP port cannot go behind a reverse proxy

    The reflector's only job is to report the source address a packet arrived from — which is exactly what a proxy replaces. It has to reach clients directly. Everything else is ordinary HTTP and belongs behind TLS.

    Open UDP 8788 at your cloud provider, not just on the VM. Cloud firewalls default to deny and are configured separately from the instance, and every provider's convenient "allow HTTP/HTTPS" option covers only TCP 80 and 443. Nothing prompts you for the UDP rule, and its absence is invisible: TLS works, health checks return 200, devices enroll successfully — and peers then never connect to each other.

    gcloud compute firewall-rules create mangofly-reflector \
      --allow udp:8788 --source-ranges 0.0.0.0/0