
Pangolin
Self-hosted tunneled reverse proxy with identity-aware access control.
About Pangolin
Pangolin is a self-hosted tunneled reverse proxy server with identity and access control, designed to securely expose private resources on distributed networks. It acts as a central hub connecting isolated networks even those behind restrictive firewalls through encrypted WireGuard tunnels.
Built on Traefik for routing and WireGuard for tunneling, Pangolin provides SSO (OIDC/SAML), role-based access control, per-resource IP and path rules, TOTP 2FA, load balancing, and automatic SSL certificates. It's a self-hosted alternative to Cloudflare Tunnels with full data sovereignty.
Key Features
- Self-hosted reverse proxy with WireGuard-based tunnels
- Encrypted connector architecture for exposing internal services
- Centralized access control with SSO integration
- Built-in CrowdSec threat intelligence
Self-Hosting Notes
Find another tool
More in Network & Firewall
NetBird
Open-source Zero Trust Networking platform replacing traditional VPNs with WireGuard-based mesh overlay.
OPNsense
FreeBSD-based firewall and routing platform with a modern GUI, intrusion prevention, VPN support, and plugin ecosystem.
WireGuard / Firezone
High-performance, secure VPN infrastructure for remote team networks.
WireGuard Easy
All-in-one WireGuard VPN with web UI for easy client management.