mrkeyoor.com_
Sun 04 Oct 07:05 UTC
Self-Hostedevaluationupdated 26 Aug 2026

pangolin review

Pangolin is an identity-aware remote-access system built around WireGuard tunnels and a reverse proxy. It lets administrators publish web applications to browsers or give installed clients access to private hosts and networks without opening each internal service directly to the internet.

+49stars / 7d
Verdict

Our Pangolin checkout pulled 1,637 packages and 1,580 MB, then failed its build after 30 seconds with module-not-found errors. Trial the published containers if its combination of browser access, private routes, and per-resource identity rules matches your network, but do not treat this source snapshot as release-ready without reproducing the build. Budget for gateway operations, client testing, AGPL review, backups, and the 14 advisories found in our installed dependency tree.

We ran it

Lab card: what happened when we ran pangolinScreenshot of pangolin (pangolin.net)
Install✓ · 111s1637 packages · 1580 MB
Build✗ · 30s
Testsn/ano test script
Known vulns140 critical · 1 high · 3 moderate · 10 low (npm audit)
Repo1874 files~313,530 lines of source · 30.2 MB · 5 CI workflows · Dockerfile · tests dir

Answers from our run

Does pangolin build from source?

Dependencies installed in 111 seconds (1637 packages), and the build failed. We cloned commit 7319bf8 into a clean Debian container with 3 CPUs and no project-specific setup.

Does pangolin have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does pangolin have known vulnerabilities in its dependencies?

npm audit flagged 14 known advisories in the dependency tree at the time of our run.

Who should not use pangolin?

Self-hosters without a public Linux server, domain, root access, or the required TCP and UDP firewall ports: the quick-install guide requires all of them.

What are the alternatives to pangolin?

Tailscale, NetBird, Netmaker. Our Pangolin checkout pulled 1,637 packages and 1,580 MB, then failed its build after 30 seconds with module-not-found errors.

Setup2/5Installer is guided, but our source build failed after 30 seconds
Docs5/5Clear gateway, DNS, install, update, and access guidance
Community5/522,493 stars with same-day pushes and active reports
Maturity3/5v1.21.1 is active; build and client reports need attention

Discussed on

  1. hnShow HN: Pangolin – Open source alternative to Cloudflare Tunnels500 points
  2. hnShow HN: Pangolin: Open-source identity-based VPN (Twingate/Zscaler alternative)81 points
  3. hnShow HN: Pangolin – SSO and WireGuard instead of API keys for LLM access3 points

Who it’s for

Self-hosters who want authenticated web access and private-network access in one control plane.
Teams connecting sites behind NAT without assigning every resource a public address.
Organizations that need user and role rules for individual services instead of broad VPN access.
Operators prepared to maintain a public Linux gateway, DNS, certificates, containers, identity, and backups.

Who it’s NOT for

Self-hosters without a public Linux server, domain, root access, or the required TCP and UDP firewall ports: the quick-install guide requires all of them.
Companies that reject AGPL and do not qualify for the Enterprise Edition's free-use terms: the README separates Community and commercial licensing.
Teams that need a clean source build at commit 7319bf8: our build stopped on module-not-found errors, and no test target was available.
Deployments that cannot tolerate client-routing regressions: current reports cover relayed local connections and iOS or macOS disconnections from private HTTP resources.

Setup reality

Our sandbox installed 1,637 npm packages in 111 seconds and used 1,580 MB. The build failed with exit code 1 after 30 seconds. Its log tail showed repeated module-not-found errors from several settings and administration pages, but did not name the missing modules in the supplied lines.

There was no test script or target, so we skipped tests. npm audit reported 14 known vulnerabilities: 1 high, 3 moderate, and 10 low, with none critical. The checkout had a Dockerfile, Compose configuration, 5 CI workflow files, and a tests directory.

Self-hosting needs a public Linux server, root access, DNS, an email address, and open ports 80 and 443 over TCP plus 51820 and 21820 over UDP. The installer pulls Pangolin, Gerbil, and Traefik containers. SMTP and external identity providers are optional.

Pangolin combines a reverse proxy with private network access

Pangolin covers two access patterns that are often operated separately. Browser users can sign in and open published HTTPS applications, remote desktops, or SSH sessions through a reverse proxy. Installed clients can reach private hosts, port ranges, and network ranges through WireGuard-based tunnels. Administrators assign users and roles to specific resources, which avoids handing every VPN user a route to an entire internal network.

Sites run outbound connectors and can traverse NAT without a public address at the protected location. A personalized launcher shows each user the resources they can open. The product also handles certificates, health checks, routing, and audit logs. Our checkout contained 1,874 files and about 313,530 source lines in 30.2 MB, so this is a full access platform with several moving services, not a small WireGuard configuration generator.

Self-hosting starts with a public gateway and four open ports

The quick installer expects a Linux server with root access, a public IP address, a domain pointing at that server, and an email address for certificates and the first administrator. Firewall rules must admit ports 80 and 443 over TCP, plus 51820 and 21820 over UDP. The installer supports AMD64 and ARM64 and places its files in the directory from which it runs.

Pangolin then pulls containers for the application, Gerbil tunneling, and Traefik. Gerbil can be omitted if you only want a reverse proxy. Initial setup uses a token printed in the Pangolin container logs, after which the operator creates the first administrator and organization. Those steps are approachable, but the 1,580 MB dependency result from our source install hints at the software volume behind the friendly installer.

What happened when we ran it

Our fresh Debian sandbox installed commit 7319bf8 with npm in 111 seconds. The operation added 1,637 packages and occupied 1,580 MB. The repository had 5 CI workflow files, a Dockerfile, Compose configuration, and a tests directory. Installation completed without an exit error, but npm audit found 14 known vulnerabilities: 1 high, 3 moderate, 10 low, and none critical.

The build ran for 30 seconds and exited with code 1. The supplied log tail showed repeated module-not-found links from resource-creation, user-access, and administrator pages. Those lines did not include the missing module names, so we cannot say whether generation, workspace state, or an undeclared package caused the failure. No test script or target was available to the harness, and we therefore have no test result for this commit.

Identity narrows access, while the gateway remains sensitive

Pangolin can use built-in identities or an external identity provider, then assign access by user and role. Browser resources can add passcodes, email codes, location rules, and allow lists. Private resources can use friendly DNS names and redundant connectors. These controls are more precise than a flat VPN route, especially when contractors or separate teams should see only named applications.

The public gateway still handles authentication and routes toward private systems. Back up its configuration, protect administrator accounts, review identity synchronization, and inspect audit logs. Release 1.21.1 specifically fixed identity-provider organization ownership when saving a policy and included security updates. The 14 advisories in our dependency audit do not prove an exploitable gateway path, but the 1 high-severity result deserves triage against the shipped package and configuration.

Client and NAT behavior needs testing on real networks

Pangolin advertises direct connections where possible and relayed connections when needed. Open issue 3634 reports a connection shown as local by the client while the server recorded it as relayed. Issue 3625 reports sudden disconnections from private HTTP resources on iOS and macOS clients. Issue 3620 covers a Cloud connection failure on a T-Mobile dual-stack network. Each report names a particular environment rather than a universal defect.

Those cases are exactly why a remote-access trial must leave the office. Test home broadband, mobile data, corporate Wi-Fi, IPv4 and IPv6 paths, sleep and resume, and the client operating systems your users carry. A 30-second source build failure is a release-engineering finding; tunnel behavior requires an end-to-end network exercise that our repository harness did not perform. Keep a relay path available until direct-connect behavior is proven on your networks.

Community and Enterprise editions have different terms

The Community Edition is open source under AGPL-3. The Enterprise Edition uses the Fossorial Commercial License and is free for personal and hobby use, plus businesses below the revenue threshold stated in the README. Organizations should decide which edition they need and have counsel assess the applicable terms before building access policy around enterprise-only behavior. A public GitHub repository does not make every edition AGPL software.

Updates also deserve care. The official guide says to back up configuration before upgrading and recommends moving incrementally between major versions. Its procedure stops the Compose stack, updates several service image versions, pulls them, restarts, and checks sites and tunnels. Release 1.21.1 warns that downgrading is not easy without a backup, which makes a restore test more useful than merely copying the directory.

Same-day development is encouraging, not a substitute for a passing build

GitHub showed 22,493 stars, 116 combined issues and pull requests, and a push on August 26, 2026. The latest release, 1.21.1, was published July 30 with identity, rate-limit, domain-validation, interface, and security fixes. Recent issue discussion covers clients, routing, APIs, and browser behavior. The project is plainly active even though the latest release is several weeks older than the last push.

Pangolin's mix of browser publishing and private routes is genuinely useful for a team that would otherwise combine a proxy, VPN, and identity layer. Our source checkout did not earn a clean recommendation: 1,637 packages led to a failed build, no runnable test target, and 14 dependency advisories. Evaluate the released deployment with a narrow resource set, real client networks, and a tested backup before it becomes the front door to production systems.

Alternatives

ProjectWhat it isPick it when
Tailscale gh↗A WireGuard-based mesh network with managed coordination and identity integrations.pick this instead when easy device networking matters more than a self-hosted reverse-proxy dashboard.
NetBird gh↗An open-source WireGuard overlay with SSO, device management, and network access policies.pick this instead when device-to-device private networking is the center of the deployment.
NetmakerA WireGuard network controller for distributed private networks and gateways.pick this instead when building and routing overlay networks matters more than browser-published applications.

What people are saying

  1. [github-trending] fosrl/pangolin

Sources

  1. Pangolin repository and README
  2. Pangolin quick install guide
  3. Pangolin update guide
  4. Pangolin 1.21.1 release
  5. Relayed local connection report
  6. Apple client disconnection report
  7. Dual-stack mobile connection report

More self-hosted reviews

awesome-cloudflare-selfhosted · life · AgentVerse-OS · incubator-seata · DocsGPT · glances · the whole board →