Pangolin: Identity-Aware Tunneled Reverse Proxy
Pangolin is a self-hosted reverse proxy tool. A self-hosted, identity-aware tunneled reverse proxy built on WireGuard, for securely exposing private services without opening ports.
Why self-host Pangolin
Exposing a home server or homelab service to the internet usually means either opening ports directly (a real attack surface) or relying on a third-party tunnel service you do not control. Pangolin combines a reverse proxy with a WireGuard-based tunnel and its own identity and access control layer, letting you expose specific services to specific authenticated users without ever opening an inbound port on your home network.
What it does
Pangolin falls into the Reverse Proxy / Tunnel category of self-hosted software. It acts as a central hub that connects otherwise isolated networks through encrypted WireGuard tunnels, fronts them with a reverse proxy, and layers identity-aware access control on top, so a specific internal service can be made reachable to specific authenticated users without exposing the underlying network directly. It is commonly positioned as a self-hosted alternative to Cloudflare Tunnels for people who want the same “no open ports” convenience without routing traffic through a third party.
Community traction
The Community Edition has 20.4k+ stars on GitHub. The project is developed by Fossorial, a Y Combinator-backed company, which means it has both an active open-source community and a sustainable funding model behind continued development.
Deployment
Docker Compose is the standard deployment path, with the official setup running the proxy, identity/access control, and WireGuard tunnel components together as a small stack.
Licensing note
Pangolin is dual-licensed: the Community Edition is fully open source under AGPL-3.0, while additional Enterprise features are covered by the Fossorial Commercial License. Enterprise features remain free for personal use and for organizations under $100k in annual revenue.
Alternatives
If Pangolin does not fit your needs, common alternatives include Cloudflare Tunnels (not self-hosted, but similar in concept) and a manual combination of Tailscale or Headscale with a reverse proxy like Traefik or Caddy, which offers more flexibility at the cost of more manual configuration.
Maturity
The project has grown quickly and is under active development, with new features shipping regularly as the Community Edition matures.
License
The Community Edition is licensed under AGPL-3.0, making it freely available for personal and commercial use, with an optional commercial license for Enterprise features.
Links
Pangolin is worth a look if you want to expose homelab services securely without opening ports or trusting a third-party tunnel provider with your traffic.