# fosrl/pangolin

Identity-aware VPN and tunneled reverse proxy for remote access based on WireGuard®.

Repository: https://github.com/fosrl/pangolin
Canonical: https://ross.abutalabs.com/products/pangolin
Homepage: https://pangolin.net
Language: TypeScript
License: NOASSERTION
License Family: other
Topics: identity-management, reverse-proxy, wireguard, single-sign-on, self-hosted, iot, oidc, proxy, vpn, zero-trust, zero-trust-network-access, ztna, pam, private-access, remote-access, ssh, tunneling, nat-traversal
Last push: 2026-08-26T22:04:01+00:00

## Health v2 (maintenance only)
Score: 84/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 83, longevity 50
- inputs: {"age_days": 706, "days_push": 7, "days_rel": 35, "gap_med": 0.0, "n_releases_24m": 75}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 22501, forks 764 (observed 2026-08-28T04:11:32.680760+00:00)

## What it is
Pangolin is an open-source, identity-aware remote access platform built on WireGuard that combines VPN and tunneled reverse proxy capabilities. It provides zero-trust, granular access to web applications and private resources like SSH and databases, with NAT traversal so no public IPs or open ports are needed.

## Use cases
- expose self-hosted apps securely without opening ports
- replace traditional VPN with zero-trust remote access
- access home lab services behind restrictive firewalls
- give team members SSO-based access to internal tools
- tunnel into private networks with NAT traversal
- secure remote SSH and RDP access to servers
- self-host a Cloudflare Tunnel alternative with identity controls

## When to choose
- you need identity-based, per-resource access control instead of full-network VPN
- your servers sit behind NAT or firewalls without public IPs
- you want a self-hosted alternative to Tailscale, Cloudflare Access, or ZTNA products
- you want browser-based clientless access plus client-based private resource access in one platform

## When to avoid
- you only need a simple site-to-site VPN without identity management
- you require a fully permissive open-source license (AGPL-3 core with commercial enterprise tiers)
- you need lightweight point-to-point tunneling without a management dashboard
- you cannot run a Docker-based or server deployment for the control plane

## Facets
- artifact type: application
- maturity: active
- function: vpn, proxy, auth, security, self-hosted, networking
- domain: security, networking, self-hosted, privacy, developer-tools
- platform: windows, self-hosted, cross-platform
- tags: wireguard, zero-trust, ztna, reverse-proxy, nat-traversal, single-sign-on, oidc, tunneling, remote-access, typescript, linux, macos, android, ios, docker

## Member repositories
- fosrl/pangolin (main) score 84

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:32.680760+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T16:57:09.238391+00:00, confidence not recorded.
  - readme: https://github.com/fosrl/pangolin (fetched 2026-08-28T04:11:32.680760+00:00, sha becf6ebe4207)
  - homepage: https://pangolin.net (fetched 2026-08-29T07:55:46.444654+00:00, sha fc78ad4dc9c7)
  - site_page: https://docs.pangolin.net/ (fetched 2026-08-29T07:55:46.455789+00:00, sha 6ff1c658e222)
  - site_page: https://pangolin.net/pricing (fetched 2026-08-29T07:55:46.453657+00:00, sha c566dbaf49bc)
- Data as of 2026-08-30T08:39:29.467469+00:00.
