Skip to main content
P

Pangolin

Pangolin provides a secure, self-hosted gateway to expose internal applications and local resources to the internet. It uses WireGuard tunnels and a reverse proxy to simplify secure remote access and sharing of services without complex network configurations.

Founded 2025210+ followers
Updated 4 months ago

Funding

Funding not disclosed

Funding rounds are not available yet.

Founders

Product

Problem

Organizations often struggle to securely expose internal applications and local resources to the internet without complex network configurations or opening unnecessary ports. This limitation hinders remote access for users and limits the ability to test or share internal tools.

Solution

Pangolin provides an open-source, self-hosted solution that acts as a secure gateway to private networks. It enables users to tunnel services to the internet via encrypted WireGuard connections, allowing access to local resources from any location. The platform simplifies the process of exposing internal applications, such as development dashboards or IoT devices, without requiring manual firewall or NAT configuration. Pangolin offers flexible deployment options, including fully managed cloud infrastructure, hybrid setups, and community self-hosted instances, catering to diverse operational needs.

Target Audience

The primary audience includes developers, DevOps professionals, and IT administrators seeking to securely expose internal applications, test environments, or IoT devices to the internet without compromising network security.

Features

  • User-space WireGuard tunnels for secure, encrypted connectivity without privileged processes.
  • Traefik reverse proxy integration for efficient request routing and load balancing.
  • Badger plugin for request authentication and access control, integrated with the Pangolin management server.
  • Gerbil component for WireGuard interface management, facilitating peer creation and tunnel maintenance.
  • Newt CLI tool and Docker container for establishing user-space WireGuard connections and proxying local resources.
  • Clientless access to exposed resources via a web browser, eliminating the need for client software installation.
  • Support for exposing HTTP, TCP, and UDP resources.
  • Flexible deployment models: fully managed cloud, hybrid infrastructure, and community self-hosted options.
  • Access control mechanisms including user/role-based permissions, PIN codes, passwords, email OTP, and temporary share links.
  • Multiple exit node deployment for high availability and low-latency access with seamless failover.
This profile is AI-generated and may contain inaccuracies.