Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Routing & publishing

    Subnet routes, exit nodes, mesh DNS and the Reverse Proxy.

    Reaching things that are not on the mesh

    • Subnet routes — One device advertises a LAN behind it, and the rest of the mesh reaches that range through it.
    • Exit nodes — Send all internet traffic through a nominated device.
    • Networks and Resources — Expose specific subnets or hosts, with routing peers and policy control, rather than the whole LAN.
    • Mesh DNS — Reach a peer as devicename.mesh instead of remembering a tunnel address.

    Publishing a service outward

    The Reverse Proxy publishes an internal service on a public domain in three modes: HTTP, TLS passthrough, or raw TCP and UDP. Visitors can optionally be made to sign in first.

    Reverse Proxy is complete and unit-tested on both server and client, but the full public-domain path has not been run against a live deployment. Treat it as unproven rather than finished.

    When large transfers stall

    Almost always the MTU. A tunnel adds header overhead, and a path that fragments or silently drops oversized packets shows up as small requests working perfectly and big ones hanging. The self-hosting guide has the specific numbers.