Pangolin
Identity-aware tunneled reverse proxy with dashboard UI, access control, and WireGuard-based tunnels (alternative to Cloudflare Tunnel, Tailscale).
High commit volume, frequent releases and growing activity.
Commit activity more than 97% of tracked projects; popularity more than 89%. How this is calculated.
Commits, last 11 months
| Stars | 23k |
|---|---|
| Latest release | 1.23.0 · 16 Sept 2026 |
| Repo updated | 24 Sept 2026 |
| Licence | AGPL-3.0 |
| Built with | Docker |
Is Pangolin actively maintained?
Development is ongoing. The repository recorded 5693 commits over the same window, and the last three months alone account for 1296 of them.
The most recent tagged release, 1.23.0, shipped within the last month — a current, installable version exists today.
Among the 19 web servers projects we track, Pangolin currently has the highest health score.
What Pangolin actually does
Pangolin is an identity-aware reverse proxy that routes traffic through WireGuard-based tunnels and provides a centralised dashboard for access control. It operates as a self-hosted alternative to established tools like Cloudflare Tunnel or Tailscale, managing secure external connections to your internal infrastructure.
Best fit: Self-hosters who want to expose private internal services securely without opening inbound firewall ports, while retaining control over identity management and routing.
Worth knowing: It overlaps heavily with well-established alternatives, meaning you should evaluate whether its specific dashboard and WireGuard approach suits your existing network architecture better than simpler solutions.
Deployment notes
As a Docker-based application, you will typically need to configure persistent volumes for state data and ensure proper TLS termination at your network edge.
Links
Pangolin as a replacement for
Alternatives to Pangolin
Projects in the same categories, ordered by health score.
Secure remote access gateway that supports the WireGuard protocol. It offers a Web GUI, 1-line install script, multi-factor auth (MFA), and SSO.
Web-based operating system designed to be feature-rich, exceptionally fast, and highly extensible.
HTTP reverse proxy and load balancer that makes deploying microservices easy.
Fully transparent SSH, HTTPS, Kubernetes, MySQL and Postgres bastion/PAM that doesn't need additional client-side software.
Next-gen Web Application Firewall (WAF) that will protect your web services.
Lightweight, simple, and performant reverse proxy with WebUI, Docker integration, automatic shutdown/startup for container based on traffic.