
Pangolin
Identity-aware VPN and reverse proxy for secure remote access

Pangolin is an identity-based remote access platform built on WireGuard that securely routes traffic to private and public resources across multiple networks. It combines VPN-style connectivity with browser-based reverse proxy access to applications, using zero-trust access controls.
Key Features
- WireGuard-based tunnels to connect remote networks (“sites”) without exposing ports or requiring public IPs
- Browser-based access to web applications via identity- and context-aware tunneled reverse proxy
- Client-based access to private resources (for example SSH, databases, RDP, and network ranges)
- Granular zero-trust access controls so users only reach explicitly allowed resources
- SSO and OIDC support, plus additional authentication options such as PIN and passwords
- Centralized dashboard to manage applications across networks, with access logging and policy enforcement
- Automatic TLS/SSL certificate handling for proxied apps
Use Cases
- Provide secure access to internal tools (Grafana, Bitwarden, admin panels) across offices, cloud VPCs, and edge locations
- Replace or complement traditional VPNs with per-application access and stronger identity enforcement
- Publish self-hosted web apps safely without directly exposing the underlying network
Limitations and Considerations
- Dual-licensed: Community Edition under AGPL-3, with separate enterprise/commercial licensing terms
Pangolin is well-suited for teams and homelabs that need identity-aware access to distributed networks and apps. It emphasizes minimizing network exposure while still enabling convenient browser and client access to protected resources.
Categories:
Tags:
Tech Stack:
Similar Services

Puter
Self-hostable web-based personal cloud and desktop environment
Self-hostable internet OS that provides a web desktop, cloud storage, and an app platform for files, web apps, and remote-work style workflows.


Sunshine
Self-hosted game streaming host compatible with Moonlight
Self-hosted game streaming server for Moonlight with low-latency streaming, hardware/software encoding, and web-based configuration and pairing.

Teleport
Identity-aware access proxy for infrastructure and internal apps
Secure access platform for servers, Kubernetes, databases, desktops, and web apps with SSO/MFA, short-lived certificates, and full session auditing.


n.eko (Neko)
Self-hosted virtual browser and shared desktop via WebRTC
Neko is a self-hosted virtual browser/desktop streamed over WebRTC, enabling low-latency remote access and multi-user collaborative sessions in Docker.

XPipe
Connection hub and remote file manager for managing server infrastructure
Desktop application that centralizes SSH, containers, VMs, Kubernetes and remote file management; integrates local CLI tools and syncs connection data via git.
OpenVPN
Open-source VPN daemon for TLS-based secure tunneling
OpenVPN is a widely used open-source VPN daemon providing TLS/SSL-based secure tunneling, flexible client-server and site-to-site modes, and cross-platform support.




