Ross ROSS = Recommend OSS · open-source software intelligence for agents

fosrl/pangolin

Identity-aware VPN and tunneled reverse proxy for remote access based on WireGuard®. observed · 2026-08-28

github.com/fosrl/pangolin · homepage · TypeScript · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 99
  • Release rhythm 83
  • Longevity 50

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0.0
  • age_days: 706
  • days_rel: 35
  • days_push: 7
  • n_releases_24m: 75

Full methodology

Adoption not part of the score

22501 stars · 764 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Pangolin is an open-source, identity-aware remote access platform built on WireGuard that combines VPN and tunneled reverse proxy capabilities. It provides zero-trust, granular access to web applications and private resources like SSH and databases, with NAT traversal so no public IPs or open ports are needed.

Use cases

  • expose self-hosted apps securely without opening ports
  • replace traditional VPN with zero-trust remote access
  • access home lab services behind restrictive firewalls
  • give team members SSO-based access to internal tools
  • tunnel into private networks with NAT traversal
  • secure remote SSH and RDP access to servers
  • self-host a Cloudflare Tunnel alternative with identity controls

When to choose

  • you need identity-based, per-resource access control instead of full-network VPN
  • your servers sit behind NAT or firewalls without public IPs
  • you want a self-hosted alternative to Tailscale, Cloudflare Access, or ZTNA products
  • you want browser-based clientless access plus client-based private resource access in one platform

When to avoid

  • you only need a simple site-to-site VPN without identity management
  • you require a fully permissive open-source license (AGPL-3 core with commercial enterprise tiers)
  • you need lightweight point-to-point tunneling without a management dashboard
  • you cannot run a Docker-based or server deployment for the control plane

Facets

application · maturity active

vpn proxy auth security self-hosted networking security networking self-hosted privacy developer-tools windows self-hosted cross-platform wireguard zero-trust ztna reverse-proxy nat-traversal single-sign-on oidc tunneling remote-access typescript linux macos android ios docker

4 sources

Member repositories

RepositoryRoleHealth v2
fosrl/pangolinmain84

For agents

markdown · JSON · MCP: product_card(name="fosrl/pangolin")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem