Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Status & limitations

    What has been proven on real hardware, and what has not.

    The project's README ends with a section headed "Honest about where this actually is". It is reproduced here rather than summarised, because the difference between "implemented" and "exercised on hardware" is the whole point of publishing it.

    Built, not yet proven

    • Linux routing — Verified on Windows and macOS on real hardware. The Linux code paths are complete and compile, but subnet routing and exit nodes have not been exercised on a real Linux host.
    • ICE nomination — Hole punching is covered by simulation tests including symmetric-NAT scenarios, but nomination has not been confirmed between two machines on separate networks.
    • Reverse Proxy — Complete and unit-tested on both ends, never run end to end against a live public domain.

    Deliberate boundaries

    • Single tenant — One deployment serves one network. There is no organisation identifier anywhere in the schema.
    • No web dashboard — The admin UI is the desktop client.
    • No cloud SSO — Directory login via LDAP or Active Directory is the supported path; OIDC is a preview.
    • Licensing — Not yet licensed for redistribution.