Tunneled Mesh Reverse Proxy Server with Identity and Access Control and Dashboard UI
Find a file
2026-07-29 21:27:33 -04:00
.cursor/rules basic functionality 2026-06-30 21:03:19 -04:00
.github Bump the github-actions-dependencies group across 1 directory with 5 updates 2026-07-27 01:34:06 +00:00
.vscode Spellcheck 2026-06-24 18:36:01 -04:00
cli support remove server admin 2026-06-10 15:10:58 -07:00
config Update to latest badger 2026-06-01 15:27:34 -07:00
install Bump golang.org/x/term 2026-07-23 01:33:10 +00:00
messages New translations en-us.json (French) 2026-07-29 18:14:07 -04:00
public update readme 2026-07-09 21:32:35 -04:00
server Merge branch 'main' into dev 2026-07-29 17:54:59 -04:00
src fix site status stuck loading sometimes 2026-07-29 17:52:55 -04:00
test Update year 2026-04-15 14:41:13 -07:00
.dockerignore fix migration 2026-06-11 15:02:29 -07:00
.editorconfig add .editorconfig and fix db imports in scripts 2024-09-28 17:42:07 -04:00
.eslintrc.json Format all files 2025-12-09 10:56:14 -05:00
.gitignore Add allowedDevOrigins 2026-05-28 21:23:55 -07:00
.nvmrc Update lock, downgrade to node 24 2025-12-06 15:12:58 -05:00
.prettierignore 🔨Add format script and install prettier 2025-12-08 19:57:08 +01:00
.prettierrc env context and refactor api support different ports 2024-12-12 22:46:58 -05:00
components.json Format all files 2025-12-09 10:56:14 -05:00
compose.drizzle.yaml Rename docker-compose.yml to compose.yaml 2026-06-04 10:01:35 +02:00
compose.example.yaml Upgrade Traefik image to version 3.7 2026-07-03 08:22:13 +02:00
compose.mailpit.yaml Rename docker-compose.yml to compose.yaml 2026-06-04 10:01:35 +02:00
compose.pgr.yaml Rename docker-compose.yml to compose.yaml 2026-06-04 10:01:35 +02:00
compose.yaml Rename docker-compose.yml to compose.yaml 2026-06-04 10:01:35 +02:00
CONTRIBUTING.md change digpangolin.com to pangolin.net 2025-10-18 11:51:09 -07:00
crowdin.yml Add first i18n stuff 2025-05-04 15:11:42 +00:00
Dockerfile Use ecr base to build 2026-02-26 21:43:14 -08:00
Dockerfile.dev update packages and node 2026-02-02 19:17:40 +00:00
drizzle.pg.config.ts Format all files 2025-12-09 10:56:14 -05:00
drizzle.sqlite.config.ts Merge pull request #3085 from marcschaeferger-org/security-updates 2026-05-28 11:54:23 -07:00
esbuild.mjs Merge remote-tracking branch 'origin/dev' into update-packages 2026-02-07 08:14:16 +00:00
eslint.config.js Format all files 2025-12-09 10:56:14 -05:00
LICENSE Chungus 2025-10-04 18:36:44 -07:00
license_header_checker.py Add resource column to hc and remove — 2026-04-16 17:42:30 -07:00
Makefile Merge branch 'main' into dev 2026-01-11 14:19:59 -08:00
next.config.ts Move proxy and client to public and private 2026-05-31 17:30:31 -07:00
package-lock.json Merge pull request #3494 from fosrl/dependabot/npm_and_yarn/next-16.2.11 2026-07-29 17:58:09 -04:00
package.json Merge pull request #3494 from fosrl/dependabot/npm_and_yarn/next-16.2.11 2026-07-29 17:58:09 -04:00
postcss.config.mjs Format all files 2025-12-09 10:56:14 -05:00
README.md update readme 2026-07-09 21:32:35 -04:00
SECURITY.md Update security 2026-03-31 15:26:39 -07:00
tsconfig.enterprise.json Merge pull request #3085 from marcschaeferger-org/security-updates 2026-05-28 11:54:23 -07:00
tsconfig.oss.json Merge pull request #3085 from marcschaeferger-org/security-updates 2026-05-28 11:54:23 -07:00
tsconfig.saas.json Merge pull request #3085 from marcschaeferger-org/security-updates 2026-05-28 11:54:23 -07:00

Discord Slack Docker Stars YouTube

Get started with Pangolin at app.pangolin.net

Pangolin is an open-source, identity-based remote access platform built on WireGuard® that enables secure connectivity to infrastructure anywhere. It combines reverse-proxy and VPN capabilities into one platform, providing browser-based access to web applications and client-based access to private resources with NAT traversal, all with granular access control.

Installation

Pangolin

Deployment Options

  • Pangolin Cloud - Fully managed service - no infrastructure required.
  • Self-Host: Community Edition - Free, open source, and licensed under AGPL-3.
  • Self-Host: Enterprise Edition - Licensed under Fossorial Commercial License. Free for personal and hobbyist use, and for businesses making less than $100K USD gross annual revenue.

Key Features

Connect remote networks with sites and NAT traversal

Pangolin's site connectors provide gateways into networks so you can access any networked resources. Sites use outbound tunnels and intelligent NAT traversal to make networks behind restrictive firewalls available for authorized access without public IPs or open ports. Easily deploy a site as a binary or container on any platform.

  • Lightweight user-space connector runs anywhere
  • Punches through any firewall
  • Doesn't require open ports or a public IP
  • Strict network segmentation
  • WireGuard-based
  • Get alerts when a device or network resource goes down
Sites

Browser-based reverse proxy access

Expose HTTPS web applications and connect to VNC, RDP, and SSH entirely in the browser through identity and context-aware tunneled reverse proxies. Users access resources with authentication and granular access control without installing a client. Pangolin handles routing, load balancing, health checking, and automatic SSL certificates without exposing your network directly to the internet.

  • Expose a web panel anywhere
  • Access via any web browser
  • Single sign-on across all resources
  • HTTPS resources
  • Remote desktop in the browser with VNC and RDP
  • In-browser SSH terminal with privileged access management (PAM)
  • PIN codes, passcodes, email OTP, geoblocking, allow-lists, and more
Reverse proxy access

Client-based private resource access

Access private resources like SSH servers, databases, RDP, and entire network ranges through Pangolin clients. Intelligent NAT traversal enables connections even through restrictive firewalls, while DNS aliases provide friendly names and fast connections to resources across all your sites. Add redundancy by routing traffic through multiple connectors in your network.

  • Peer-to-peer with intelligent NAT traversal
  • Hosts/IPs and port ranges
  • Network ranges/CIDRs
  • Friendly DNS aliases for network addresses
  • Privileged access management (PAM) with SSH resources
  • Private HTTPS resources only accessible on the private network
Private resources

Give users and roles access to resources

Use Pangolin's built-in users or bring your own identity provider and set up role-based access control (RBAC). Grant users access to specific resources, not entire networks. Unlike traditional VPNs that expose full network access, Pangolin's zero-trust model ensures users can only reach the applications, services, and routes you explicitly define.

  • Bring your existing identity provider (IdP) or use Pangolin identities
  • Sync users and roles from your IdP
  • User- and role-based access control
  • Full network audit and access logs
Users from identity provider with roles

Find and launch resources from a personalized home page

Give users a landing page to quickly find and open the resources they can access. Resources are grouped by site or label, searchable, and filterable, with grid or list views. Saved views capture filters, grouping, and layout as personal or organization-wide defaults.

  • Single place for admins and non-admins to see accessible resources
  • Create reusable views for common access patterns
Resource Launcher

Download Clients

Download the Pangolin client for your platform:

Get Started

Sign up now

Create a free account at app.pangolin.net to get started with Pangolin Cloud.

Check out the docs

We encourage everyone to read the full documentation first, which is available at docs.pangolin.net. This README provides only a very brief subset of the docs to illustrate some basic ideas.

Licensing

Pangolin is dual licensed under the AGPL-3 and the Fossorial Commercial License. For inquiries about commercial licensing, please contact us at contact@pangolin.net.

Contributions

Please see CONTRIBUTING in the repository for guidelines and best practices.