Pangolin logo

Pangolin

Website

Identity-aware VPN and reverse proxy for secure remote access

22.5k stars 765 forks last commit first released

Actively maintained

Last commit 26 Aug 2026.

Pangolin screenshot

Pangolin is an identity-based remote access platform built on WireGuard that securely routes traffic to private and public resources across multiple networks. It combines VPN-style connectivity with browser-based reverse proxy access to applications, using zero-trust access controls.

Key Features

  • WireGuard-based tunnels to connect remote networks (“sites”) without exposing ports or requiring public IPs
  • Browser-based access to web applications via identity- and context-aware tunneled reverse proxy
  • Client-based access to private resources (for example SSH, databases, RDP, and network ranges)
  • Granular zero-trust access controls so users only reach explicitly allowed resources
  • SSO and OIDC support, plus additional authentication options such as PIN and passwords
  • Centralized dashboard to manage applications across networks, with access logging and policy enforcement
  • Automatic TLS/SSL certificate handling for proxied apps

Use Cases

  • Provide secure access to internal tools (Grafana, Bitwarden, admin panels) across offices, cloud VPCs, and edge locations
  • Replace or complement traditional VPNs with per-application access and stronger identity enforcement
  • Publish self-hosted web apps safely without directly exposing the underlying network

Limitations and Considerations

  • Dual-licensed: Community Edition under AGPL-3, with separate enterprise/commercial licensing terms

Pangolin is well-suited for teams and homelabs that need identity-aware access to distributed networks and apps. It emphasizes minimizing network exposure while still enabling convenient browser and client access to protected resources.

Categories:

Tags:

Tech Stack:

Share:

Similar to Pangolin

GoDoxy

Reverse proxy and container-aware traffic manager with Web UI

4.1k
188
Last commit

High-performance reverse proxy for self-hosted apps with Web UI, Docker/Podman auto-routing, HTTPS via Let's Encrypt, access control, and OIDC/ForwardAuth support.

Actively maintained
Alternative to:
Traefik Cloud logo
Traefik Cloud
+5
NetBird logo

NetBird

WireGuard-based overlay network with SSO/MFA and granular access controls.

28.7k
1.6k
Last commit

Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.

Actively maintained
Alternative to:
Tailscale logo
Tailscale
+17
Firezone logo

Firezone

Zero-trust remote access platform built on WireGuard

9k
450
Last commit

Firezone is a zero-trust VPN replacement built on WireGuard, providing identity-aware access policies, peer-to-peer encrypted tunnels, and lightweight gateways.

Apache-2.0Actively maintained
Alternative to:
Tailscale logo
Tailscale
+11

Pomerium

Identity- and context-aware access proxy for zero trust access

5k
350
Last commit

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Apache-2.0Actively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+12

OAuth2 Proxy

Reverse proxy and middleware for OAuth2/OIDC authentication

14.9k
2.2k
Last commit

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

MITActively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+14
DockFlare logo

DockFlare

Cloudflare Tunnel ingress controller automated with Docker labels

2.4k
107
Last commit

Self-hosted controller that automates Cloudflare Tunnels, DNS records, and Access policies using Docker labels, with a web UI and optional multi-server agents.

Actively maintained
Alternative to:
Cloudflare Tunnel logo
Cloudflare Tunnel